> Markdown version of [/jobs/ext/1916947-information-security-analyst](https://www.wearedevelopers.com/jobs/ext/1916947-information-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst - **Company:** Country Financial - **Location:** Bloomington, IL, United States - **Experience:** Expert - **Salary:** $94,400.0 - $129,800.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, CompTIA Security+, Cyber Security, Computer Forensics, PCI Data Security Standards, Cloud Services, Security Information and Event Management, CIS Benchmarks - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=fa8ad5d39494ae72 ## About the Role * Typically requires 7+ years of relevant experience or a combination of related experience, education and training. * Experience performing information security risk assessments, including documenting risks, evaluating control gaps, and communicating mitigation recommendations to business and technology stakeholders. * Experience supporting third-party risk management activities, such as vendor due diligence, ongoing monitoring, contract/security reviews, and assessment of supplier control environments. * Working knowledge of cybersecurity governance, risk, and compliance practices, including the development or maintenance of security policies, standards, procedures, and control documentation. * Familiarity with common security and regulatory frameworks, such as NIST CSF, NIST 800-53, ISO 27001, CIS Controls, PCI DSS, GLBA, HIPAA, or FFIEC guidance. * Experience using governance, risk, and compliance platforms or risk assessment tools to manage assessment workflows, document evidence, track risks, and report status. * Ability to translate technical security findings into clear business risk language for project teams, leadership, auditors, and non-technical stakeholders. * Experience consulting on technology projects to identify security requirements, assess risk, and recommend practical control improvements. * Experience supporting audit, compliance, or regulatory exam activities, including evidence gathering, control mapping, management responses, and remediation tracking. * Strong written and verbal communication skills, with experience creating risk reports, assessment summaries, policies, standards, or executive-level deliverables. * Professional security, risk, privacy, or audit certifications such as CISSP, CISM, CRISC, CISA, Security+, CEH, or similar. * Experience assessing risks related to artificial intelligence, cloud services, SaaS platforms, data protection, or other emerging technologies. * Demonstrated ability to work independently, manage multiple priorities, and collaborate across technology, business, legal, compliance, and vendor management teams. #LI-CORP ## Description Participates in projects and assessments as a security consultant or advisor on risk. Researches general and industry specific security trends. Analyzes, defines security policies and information security standards. Provides detail to project teams regarding security requirements. Creates and presents risk reports, policies, results and deliverables. Performs penetration and vulnerability testing, including the delivery & explanation of results. Evaluates, documents and communicates vulnerability ratings and mitigation guidelines., Participates in projects and assessments on risk. - Analyzes and defines security policies and standards. - Monitors, alerts and responds to security events. - Performs computer forensic and investigative activities; and penetration and vulnerability testing. - Defines and administers identity & access roles and workflows. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Industries Outside of AI Are Hiring The Most AI Experts?](https://www.wearedevelopers.com/magazine/98-what-industries-outside-of-ai-are-hiring-the-most-ai-experts) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere)