Information Security Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
- Conduct third-party and vendor information security risk assessments to identify, evaluate, and document potential cybersecurity risks.
- Perform security control reviews, control validation activities, and compliance assessments to help strengthen the organization’s overall security posture.
- Analyze risk assessment findings, recommend remediation strategies, and partner with business and technology teams to address identified issues.
- Review vendor security documentation, including audit reports and supporting evidence, to evaluate security practices and compliance with organizational standards.
- Support risk metrics, reporting, and data analysis to provide meaningful insights into cybersecurity risks, trends, and control effectiveness.
- Maintain accurate assessment documentation and risk records using governance and project management tools such as ServiceNow and Jira.
- Collaborate with cross-functional stakeholders to support risk management initiatives, improve assessment processes, and ensure consistent execution of security programs.
- Communicate technical security risks, assessment results, and recommendations to both technical and non-technical audiences in a clear and effective manner.
- Stay informed on evolving cybersecurity threats, industry standards, and best practices to continuously enhance assessment methodologies and risk management processes.
Requirements
Our client is seeking a Senior Information Security Analyst to support enterprise information risk management initiatives by evaluating cybersecurity risks, strengthening security controls, and partnering with stakeholders across the organization. This role is ideal for a collaborative professional with strong analytical skills who can translate complex technical concepts into actionable business insights while helping drive effective risk management practices.
This role is a hybrid model in Beaverton, Oregon. Applicants who can work a hybrid model are preferred but fully remote applicants will be considered., * Minimum of 2-5 years of experience in information security, cybersecurity, technology, risk management, or a related field.
- Hands-on experience performing third-party or vendor risk assessments and evaluating information security controls.
- Experience conducting audits, compliance reviews, or security control assessments within an enterprise environment.
- Proficiency with ServiceNow, Jira, and Microsoft Office Suite, including Excel and PowerPoint.
- Strong analytical, organizational, and problem-solving skills with the ability to interpret complex technical information.
- Excellent written and verbal communication skills, with the ability to explain technical concepts to business stakeholders.
- Experience working collaboratively across multiple teams and managing relationships with diverse stakeholders.
- Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Business, or a related discipline preferred; equivalent professional experience will also be considered.
- Professional certifications such as CRISC, CISSP, or similar information security credentials are preferred but not required.
- Experience in enterprise risk management, retail, supply chain, or related industries is a plus.
- Demonstrated adaptability, intellectual curiosity, a commitment to continuous learning, and the ability to handle sensitive information with professionalism and discretion.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.vanderhouwen.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Fully Remote Software Engineer Jobs
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Is Software Engineering Over-Saturated?
9 Ways to Make Money Hacking