> Markdown version of [/jobs/ext/1283536-security-analyst](https://www.wearedevelopers.com/jobs/ext/1283536-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Analyst - **Company:** Goodwin Procter LLP - **Location:** Santa Monica, CA, United States - **Experience:** Experienced - **Salary:** $103,700.0 - $178,900.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Macintosh Computers, Microsoft Azure, Cyber Security, Linux, Intrusion Detection and Prevention, Intrusion Detection Systems, Python (Programming Language), Node.Js, Windows PowerShell, Security Information and Event Management, Software Vulnerability Management, Microsoft Power Automate, Malware, Firewalls (Computer Science), Information Technology, Palo Alto Networks, Splunk, Cisco, Security Orchestration, Automation & Response - **Published:** July 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ba01e62f9ffde8d3 ## About the Role * Bachelor's Degree or equivalent. * Minimum of 3 years' experience working in the capacity of an Information Security Analyst * CISSP or equivalent preferred * Expert knowledge in IT Security frameworks and solutions. * Active participation in IT Security Forums inside/outside of the Legal Industry. * Excellent technical communication skills with a strong desire to achieve customer satisfaction; must be able to communicate effectively across entire organizations. * Operating knowledge of security configurations with respect to one or more of the following security products * SIEM: Splunk, Sentinel * Firewalls: Cisco, Palo Alto Networks * IDS/IPS: Cisco, Palo Alto Networks * NAC: Cisco, Aruba * Vulnerability Management: Tenable, Rapid7 * Programming Languages: Python, Powershell, Node.js * Security Automation: LogicApps, Power Automate, Splunk * Operating knowledge of security issues associated with one or more of the following cloud platforms: Azure, AWS * Strong security knowledge of O/S (desktop and server) Security - Windows, Mac, Linux. * Strong security knowledge of browser security issues (Edge, Chrome). * Ability to learn new technologies and security features. * Excellent analytical, problem solving and troubleshooting skills. * Excellent organizational, interpersonal, communication and customer service skills. * Knowledge of ITIL Service Management principles. * Travel 1 week per quarter ## Description Here, we're not just supporting a law firm; we're partnering with attorneys and clients to deliver cutting-edge solutions in high-stakes litigation and dispute resolution, world-class regulatory compliance and advisory services, and complex transactions. Our commitment to integrity, ingenuity, agility, and ambition drives us, and we're proud to have been recognised as the "Best Business Team" by The American Lawyer. This is your opportunity to grow professionally in a dynamic, global environment, surrounded by forward-thinking peers. Working with the Director, Information Security, this position is responsible for the operation, implementation, management, auditing and reporting, and engineering support of Goodwin's network and information security systems infrastructure. Assists with security automation, threat detection engineering, risk assessments, vulnerability management, incident response, and disaster recovery testing. Provides internal consulting to project owners and technical resources to ensure the confidentiality, integrity and availability of firm data and systems. Reviews, tests and implements new security technology platforms. Advocates information security practices to all firm members. What You Will Do: * Identify new threats to IT systems and create rules to identify, prevent and remediate. * Expand security auditing and ensuring the proper ongoing operations of security tools * Providing internal information security consulting for other business and IT projects. This includes identifying, documenting and implementing secure configurations and architectures. * Assist with the creation and maintenance of security policies, standards, guidelines and other documentation for IT and business audiences. * Responsible for security metrics on a monthly basis to ensure the proper service levels are maintained. * Support incident response lifecycle including identification, triage, remediation and communications for security breaches and malware infections. * Identify latest security vulnerabilities, malware, breaches, and industry news which could affect the firm * Maintains vulnerability management process including identification, rating, remediation and monitoring. * Provides additional coverage for approvals and notifications to other IT groups for critical time sensitive operations including firewall changes, password reset approvals, and application vetting. * Assist with automation of security processes, integration of security platforms, and creation of tools. * Ongoing reviews of access controls by investigating improper access; revoking access; reporting violations; monitoring requests; recommending improvements * Provides technical leadership for incident response capabilities including malware analysis, breach investigation, and remediation efforts. * Creation of internal training materials and other items to support the advancement of information security within the firm. * Maintains awareness of industry trends and their advantages with the ability to make recommendations for improving technology used by the firm. * Participates in and/or manages cross-functional team projects to implement new or updated technology. * Cross-trains other IT staff in security best practices, the use or maintenance of technology. * Effectively manages small projects. * Displays professionalism, quality service and a "can do" attitude to internal members/departments of the Firm as well as external clients and vendors via electronic and print correspondence, over the telephone and in-person. * Provides information security knowledge transfer to other IT staff and business * Assumes additional responsibilities as assigned. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)