Senior Information Security Analyst

ARIZONA FOUNDATION REPAIR, LLC
Tucson, AZ, United States
20 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$100,000.0
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Cyber Security Phishing Security Software Cloud Platform System IT Architecture

Job description

As a Senior Information Security Analyst, you’ll have the opportunity to make a meaningful impact by fostering a security first mindset across the organization. If you’re passionate about cybersecurity, we’d love to hear from you! We are seeking a dedicated and engaging Senior Information Security Analyst to monitor, analyze, and respond to security threats and vulnerabilities within the organization. This role involves conducting risk assessments, investigating security incidents, ensuring compliance with industry standards and best practices, and leading employee security awareness initiatives and training programs. This role will play a crucial part in onboarding new employees, developing phishing awareness campaigns, facilitating one-on-one training, and collaborating with internal teams to promote a security-conscious culture. The ideal candidate will have a strong background in cybersecurity, excellent communication skills, and the ability to translate complex security topics into engaging and understandable content.

Supervisory Responsibility:

This position is not supervisory in nature.

Essential Functions/ Major Responsibilities:

  • Monitor security alerts and logs using organization’s cybersecurity tools.
  • Investigate and respond to security incidents, breaches, and vulnerabilities.
  • Perform root cause analysis and recommend corrective actions.
  • Conduct vendor security risk assessments and prepare formal reports.
  • Analyze security risks and provide recommendations for mitigation.
  • Lead security audits, compliance audits, risk assessments, and penetration testing efforts.
  • Assist with third-party risk assessments and vendor due diligence.
  • Support the development and maintenance of security policies, standards, and procedures.
  • Ensure compliance with regulatory requirements and security frameworks.

Knowledge, Skills, and Abilities:

  • Conduct information cybersecurity training sessions for new employees as part of the onboarding process.
  • Develop engaging and informative cybersecurity training materials tailored to different employee roles.
  • Provide ongoing cybersecurity awareness education through various training methods (e-learning, webinars, in-person sessions).
  • Facilitate personalized training sessions for employees who require additional cybersecurity training.
  • Act as a cybersecurity awareness resource, addressing employee inquiries and concerns related to cybersecurity.
  • Create and manage phishing simulation campaigns to assess employee awareness and response.
  • Track, analyze, and report on phishing campaign results to identify trends and areas for improvement.
  • Ensure compliance with security policies by monitoring and reporting on repeated phishing failures.
  • Review reported phish emails and follow up with submitter.
  • Support compliance audits by ensuring complete and accurate documentation.
  • Coordinate with key stakeholders to update and maintain the business continuity and disaster recovery plan.
  • Update and maintain the incident response plan.
  • Serve as the primary liaison with the University of Arizona’s Information Security Office, ensuring compliance with its cybersecurity policies

Requirements

  • Bachelor’s degree in computer, cybersecurity, or a related field (or equivalent experience).
  • 3+ years of experience in cybersecurity work experience required.
  • Strong understanding of information security principles, phishing threats, and social engineering tactics.
  • Experience with phishing simulation tools and security awareness platforms.
  • Excellent communication, presentation, and superb customer service.
  • Excellent problem-solving, analytical, and organizational skills.
  • High attention to detail and commitment to confidentiality and integrity.
  • Ability to work collaboratively with teams across the organization.
  • Knowledge of security compliance frameworks (e.g., NIST, ISO 27001, SOC 2) is a plus.

Preferred Qualifications:

  • Security + certificate.
  • Experience with threat protection, detection, and response tools for endpoints, email, identity, and cloud environments.
  • Ability to communicate effectively with technical IT staff.
  • Knowledge of IT architecture and operations.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:28 min

Documenting microservice architectures with the architecture canvas

Benjamin Wolf Benjamin Wolf +1 · WWC 2025

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · WWC Europe 2026

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all