> Markdown version of [/jobs/ext/1383665-information-security-analyst](https://www.wearedevelopers.com/jobs/ext/1383665-information-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst - **Company:** Hagadone Media Group - **Location:** Coeur d'Alene, ID, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Data Analysis, Software System Penetration Testing, CompTIA Security+, Cyber Security, Disaster Recovery, Networking Hardware, Windows Servers, PCI Data Security Standards, Runbook, Service Pack, Security Information and Event Management, Software Vulnerability Management, Data Classification, Large Language Models, Cyber Threat Analysis, AI Platforms, Information Technology, Patch Management, Workday HRIS, Vulnerability Analysis - **Published:** July 22, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ea047812299425ce ## About the Role * Bachelor's degree in Cybersecurity or Computer Science. * 3 or more years of relevant IT, Cybersecurity, system administration, infrastructure, or information security experience. * Familiarity with vulnerability scanning, penetration testing concepts, and remediation workflows. * Strong verbal and written communication skills with the ability to effectively collaborate with internal teams, external partners, and stakeholders. * Ability to work effectively both independently and as part of a team, with a strong willingness to learn across diverse cybersecurity and operational areas. * Familiarity with AI and machine learning concepts, including generative AI and Large Language Models (LLMs), with practical experience in assessing security and data privacy risks associated with these technologies. Ability to develop and implement AI-specific security guidelines and policies. * Demonstrated ability to write, edit, and maintain comprehensive technical documentation, including security policies, procedures, incident response plans, and disaster recovery runbooks. * Experience in documenting security assessments, vulnerability findings, and remediation plans. PREFERRED CERTIFICATIONS * CompTIA Security+, CySA+, CISSP, CISM, or similar industry-recognized certifications. ## Description The Information Security Analyst reports directly to the CIO and is responsible for supporting and strengthening the organization's cybersecurity posture. This is done through vulnerability management, security operations, governance, risk management, compliance initiatives, and information security program development. This position works collaboratively with IT, HR, Legal, and business teams to identify and mitigate security risks, maintain security policies and procedures, support incident response activities, and ensure compliance with industry standards and regulatory requirements. The Information Security Analyst also plays a key role in disaster recovery planning, security awareness training, technical documentation, and the secure adoption of emerging technologies, including Artificial Intelligence (AI). This role requires a proactive, analytical professional who can balance technical security requirements with business objectives while helping protect organizational data, systems, and operations. This is a primarily on-site role based in Coeur d'Alene, Idaho. Due to the collaborative nature of this position, regular in-person attendance is required., * Vulnerability & Patch Management: Track missing patches, CVEs, and vulnerability remediation progress. Coordinate security patching and upgrades across Windows servers, network devices, and appliances. Define patching priorities based on business risk, ensuring proper change documentation and post-patch validation. * Security Operations & Incident Response: Monitor EDR and SIEM alerts, escalating potential security incidents as appropriate. Participate in cybersecurity incident response, remediation planning, and follow-up tracking. * Governance, Risk, & Compliance: Support PCI audits, regulatory compliance reviews, and quarterly/annual security scans. Work with internal teams and third parties to remediate findings. * Policy Development & Maintenance: Develop and maintain comprehensive IT security policies, standards, and guidelines, including Acceptable Use, Access Control, Data Classification, and Incident Response. * Technical Documentation: Proficiency in creating and updating technical documentation, such as incident response playbooks, disaster recovery runbooks, and security configuration guides. * Framework Alignment: Ensure policies and procedures align with industry best practices, established cybersecurity frameworks, and regulatory requirements such as PCI-DSS. * Policy Exceptions & Risk: Manage the policy exception process by evaluating business justification, assessing associated security risks, and recommending compensating controls. * Operational Integration: Conduct periodic reviews of documentation to ensure it reflects current operational practices, technology changes, and the evolving threat landscape. * Enforcement & Compliance: Collaborate with internal departments such as HR, Legal, and IT to support policy enforcement, track employee acknowledgments, and integrate security guidelines into standard operating procedures. * Disaster Recovery: Support backup and DR planning by defining recovery objectives, ensuring critical system coverage, reviewing backup statuses, participating in restore testing, and maintaining DR runbooks. * Security Research: Help create and deliver cybersecurity awareness training for employees. Stay current on emerging cybersecurity trends, threat landscapes, and AI-related technologies. * Lead Secure AI Adoption: Champion the organization's AI initiatives by providing strategic security guidance, evaluating AI platforms for data privacy and security risks, and ensuring business adoption aligns with organizational risk tolerance. Additionally, work closely with Hagadone team members to provide and participate in hands-on training opportunities that build practical AI knowledge, strengthen secure adoption practices, and support effective use of AI tools across the organization. * Promote Responsible AI Usage: Develop and enforce AI acceptable use guidelines, proactively educating employees on ethical usage, data protection, and the risks of inputting sensitive company information into public AI models. * IT Communications & Security Awareness: Work directly with the Corporate Administrative Manager to serve as the organization's primary liaison for IT and cybersecurity communications by developing and delivering company-wide updates on technology initiatives, cybersecurity threats, AI developments, system changes, security best practices, and incident-related communications. Partner with HR, IT, and leadership to ensure employees receive timely, consistent, and understandable information regarding HRIS implementations, software updates, security policies, compliance requirements, and emerging technology risks, while fostering a culture of security awareness and responsible technology use. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [IKEA Story: Transforming an Iconic Retail Brand](https://www.wearedevelopers.com/videos/444-ikea-story-transforming-an-iconic-retail-brand) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [What's (new) with Spring Boot and Containers?](https://www.wearedevelopers.com/videos/1514-what-s-new-with-spring-boot-and-containers) - [Bridging AI and Nomad: a Go-based MCP Server for Cluster Control](https://www.wearedevelopers.com/videos/2063-bridging-ai-and-nomad-a-go-based-mcp-server-for-cluster-control) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)