> Markdown version of [/jobs/ext/157561-senior-information-security-analyst](https://www.wearedevelopers.com/jobs/ext/157561-senior-information-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Security Analyst - **Company:** Vesync Co. - **Location:** Tustin, CA, United States - **Experience:** Expert - **Salary:** $125,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cyber Security, Identity and Access Management, Intrusion Detection and Prevention, Intrusion Detection Systems, Information Systems Security Architecture Professional, Network Security, Security Information and Event Management, Software Vulnerability Management, Enterprise Data Management, Google Cloud, Multi-Cloud, QRadar, Information Technology, Splunk, Blue Team (Cyber Security) - **Published:** May 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=cee58d190c7b2348 ## About the Role Do you have experience in Regulatory Frameworks (Architecture security)?, Do you have a Bachelor's degree?, We are seeking a highly skilled and strategic Senior Information Security Analyst to spearhead the protection of our enterprise data, systems, and hybrid infrastructure (On-Premise and Multi-Cloud). In this role, you will balance technical execution with strategic planning-developing comprehensive security plans, establishing robust compliance frameworks, and engineering real-time monitoring solutions. As a senior member of the team, you will act as a defender, a strategist, and a mentor, utilizing advanced technologies to mitigate risk, drive security awareness, and foster a culture of continuous improvement. Candidates must be bilingual in Mandarin (read, write, speak)., * Bachelor's degree in Information Security, Computer Science, or a related field. * 8+ years of experience in information security, with a strong background in security event analysis, incident response, vulnerability management, and risk assessment. * Must be bilingual in Mandarin (read, write, speak). * Hands-on experience with public cloud security (e.g., AWS, Azure, GCP), including cloud-native security tools and best practices. * Familiarity with security regulatory compliance standards and frameworks such as NIST CSF, ISO 27001, and CIS. * Familiar with AWS security suites * Familiar with security scorecards, SIEM tools and dashboards (Splunk, QRadar, Rapid7, Wazhu) * Experience with OneTrust, Drata or similiar tools * Knowledge of network security principles, intrusion detection/prevention systems (IDS/IPS), firewalls, and endpoint protection. * Understanding these aspects is essential for ensuring the company's security compliance and building a robust security defense system. * Strong analytical and problem - solving skills, with the ability to quickly identify and mitigate security threats. * Relevant security certifications such as CISSP, CISM, CEH are a plus. ## Description * Develop and implement comprehensive information security plans to safeguard the security of company data and assets, including on-premise and cloud environments. * Thoroughly analyze the company's business processes and data characteristics, and combine industry best practices and frameworks such as NIST Cybersecurity Framework (CSF)to create customized security plans, ensuring the confidentiality, integrity, and availability of information assets in various scenarios. Policy Development and Compliance * Create security policies and ensure that the company's operations are in strict compliance with industry standards (e.g., ISO 27001, NIST, GDPR) and regulatory requirements. * Continuously monitor industry trends and regulatory changes, and adjust security policies in a timely manner to provide a solid security and compliance framework for the company's business operations. System, Network and Cloud Security * Maintain and enhance security measures for systems, networks , and public cloud platforms (e.g., AWS, Azure, GCP) to prevent potential threats. * Utilize advanced technical means and tools to conduct real - time monitoring and risk early warning of systems, networks, and cloud environments, promptly detect and block various attack behaviors, and ensure the stable and secure operation of IT infrastructure. Security Monitoring and Incident Response * Monitor security events in real - time, respond promptly to emergencies, and effectively mitigate risks. * Build an efficient security monitoring platform, use intelligent analysis technology to promptly capture abnormal behaviors, activate emergency response plans, and minimize the impact of security incidents. * Conduct red/blue team exercise . Security Awareness and Training * Develop and deliver security training programs to enhance employees' security awareness and encourage their adherence to best practices. * Design targeted training courses according to the needs of different positions and use diverse training methods to ensure that employees have a deep understanding of and implement security requirements. Access Control and Identity Management * Oversee user access controls, regularly review permissions, and ensure secure identity management. * Implement a strict access control mechanism, Conduct regular audits of user permissions, and use reliable identity management systems to prevent unauthorized access and ensure the security of company resources. Risk Assessment and Management * Conduct comprehensive risk assessments, identify vulnerabilities, and implement effective mitigation strategies. * Use scientific risk assessment methods and frameworks such as NIST CSF to evaluate potential threats and vulnerabilities, formulate corresponding mitigation measures based on the assessment results, and continuously improve the company's security defense capabilities. * Develop risk KPIs and metrics . Documentation and Mentorship * Document Cyber Security controls, detection rules and playbooks. * Mentor team members . ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [The Open-source Java SDK for Multi-Cloud Development - Sandeep Pal](https://www.wearedevelopers.com/videos/2113-the-open-source-java-sdk-for-multi-cloud-development-sandeep-pal) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [Winning the Hybrid Cloud](https://www.wearedevelopers.com/videos/432-winning-the-hybrid-cloud) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)