Sr Information Security Analyst
Akaasa Technologies
Philadelphia, PA, United States
about 1 month ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$107,300.0 - $185,840.0
Working hours
Regular working hours
Job source
Tech stack
Kubernetes Security
Microsoft Windows
Amazon Web Services
Apple Mac Systems
Software System Penetration Testing
Audit Trail
Microsoft Azure
Cloud Computing
Cloud Computing Security
Cyber Security
Linux
Domain Name System (DNS)
+29 more
Monitoring of Systems
Identity and Access Management
Key Management
Log Analysis
Microsoft Data Access Components
Windows Servers
Open Web Application Security
Azure Active Directory
Zero Trust Network Access
Microsoft SharePoint
Security Information and Event Management
Windows Desktop
EndPointSecurity
Symantec
Data Logging
Scripting
Google Cloud
Okta
Software Security
Mitre Att&ck
Firewalls (Computer Science)
Amazon Virtual Private Cloud (VPC)
Cybercrime
Microsoft Sentinel
CIS Benchmarks
Cloudwatch
Qualys
Key Vault
Vulnerability Analysis
Job description
Cloud & Enterprise Security (SME)
- Serve as SME on security fundamentals, techniques, and technologies across Azure, AWS, GCP, and on prem environments.
- Guide cloud security architecture: IAM, encryption/key management, network controls, data protection, workload hardening.
- Implement process improvements aligned to security frameworks (NIST CSF/800 53, ISO 27001) and business needs; optimize technology to improve customer experience.
Security Operations & Incident Response
- Implement and monitor controls for unusual and suspicious activity across endpoints, networks, and cloud platforms.
- Perform advanced monitoring, data/log analysis, threat hunting, and forensic investigations; contribute to SOC/IR workflows.
- Plan, contribute to, and participate in incident plan exercises and tabletop scenarios.
Governance, Risk & Compliance (GRC)
- Draft or revise local policies, standards, guidelines, and procedures to supplement enterprise frameworks; identify and remediate gaps based upon NIST standards.
- Interface with internal/external auditors and examiners; maintain vendor management standards, questionnaires, and regulatory documentation (HITRUST, PCI, NIST, HIPAA, SOC2).
- Review contracts and provide security guidance; support project scoping, costing, and cost benefit analyses.
Stakeholder Engagement & Communication
- Act as a liaison for the security team; clearly communicate business risk as it relates to information security.
- Create technical documentation (reports, white papers, technical notes, implementation/configuration guides).
- Use visual aids to convey complex topics to large, diverse audiences; communicate clearly in high pressure, high visibility situations.
Continuous Improvement
- Recommend new security solutions and improvements that do not impede innovation.
- Stay current with the evolving threat landscape; consistently learn and grow to remain a step ahead of attackers.
Technical Expertise Cloud Security (Azure, AWS, GCP)
- GCP: IAM, Security Command Center, Cloud Audit Logs, VPC Service Controls, CMEK/KMS, Cloud Armor, Workload Identity; container security (GKE).
- Azure: Defender for Cloud, Microsoft Sentinel, Entra ID (Azure AD), Conditional Access, Key Vault, NSGs/Azure Firewall, storage encryption, Defender for Endpoint integration.
- AWS: IAM roles/policies, Security Hub, GuardDuty, KMS, CloudTrail/CloudWatch, VPC security controls, AWS WAF, Secrets Manager. (experience with AWS is not required)
Additional Technologies
- Operating Systems: Linux, Windows Server, Windows Desktop; hardening, patching, CIS Benchmarks.
- Forensics & eDiscovery: Symantec, Purview, Proofpoint; email/file discovery; incident response.
- Network & Perimeter: Palo Alto firewalls, URL filtering, DNS blackhole/geo filtering, WildFire; F5 AWAF.
- SIEM & Logging: MS Sentinel, MDE, Elastic; Endpoint management/log forwarding. Microsoft Data Lake, CRIBL
- Vulnerability & AppSec: Qualys, NexusIQ; OWASP aligned testing and remediation.
- Endpoint: Microsoft Defender, Microsoft ATP/Defender for Endpoint.
- Identity & MFA: Okta, Microsoft (Entra ID MFA).
- Core Services: DNS zone management; network micro segmentation; zero trust aligned controls.
- Secure Productivity: Securing Microsoft 365 (Exchange Online, SharePoint/OneDrive, Teams, Purview).
Requirements
- 5+ years of relevant information security experience (or 3+ years in IT systems administration with 2 years security responsibilities).
- Cloud security experience with GCP or Azure and sound knowledge of Cloud Security framework.
- Expertise in incident response, system monitoring/analysis, and risk assessments aligned with compliance and privacy laws.
- Experience with compliance requirements: HITRUST, PCI, NIST, HIPAA, SOC2.
- Experience across multiple platforms: Windows, Linux/Unix, macOS; networks and endpoints.
- Experience with vulnerability assessment and penetration testing engagements.
- Experience with change management and project management.
- Excellent technical writing and presentation skills; ability to translate technical risk to business impact.
Preferred
- CCSP preferred; other certs: AZ 500, AWS Security Specialty, GCP Professional Cloud Security Engineer.
- Experience securing Azure, AWS, GCP in enterprise/hybrid environments.
- Familiarity with NIST CSF, ISO 27001, CIS Benchmarks, MITRE ATT&CK.
- Automation, scripting experience a plus.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.careerjet.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
about 2 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
6 months ago
AJ
Austin Joy
What Are The Top Skills Required For Azure Developers?
over 4 years ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
KD
Krissy Davis
Best Paying Jobs in Technology
about 3 years ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago