Sr Information Security Analyst

SageNet, LLC.
Tulsa, OK, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$104,000.0 - $124,800.0
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Cyber Security Identity and Access Management Intrusion Detection Systems Virtual Private Networks (VPN) Industry Standard Architecture Network Security Log Analysis Network Segmentation Open Web Application Security PCI Data Security Standards Performance Tuning
+11 more
Security Information and Event Management Software Engineering Software Vulnerability Management Wide Area Networks Data Processing In-Plane Switching (IPS) Software Security Firewalls (Computer Science) Information Technology Static Application Security Testing Dynamic Application Security Testing

Job description

Protect the business. Influence the strategy. Lead the response. This is more than a traditional analyst role. You’ll help drive the day-to-day execution of SageNet’s information security program while partnering closely with our Director of Information Security to strengthen security operations, application security, risk management, and compliance., The Senior Information Security Analyst plays a critical role in executing and maturing SageNet’s information security program. This position supports and extends the Director of Information Security by owning key security operations, governance, risk, and compliance activities while acting as a delegated decision-maker for day-to-day security program execution.

This role balances hands-on operational responsibility with cross-functional leadership, ensuring security controls are effective, risks are managed, and compliance obligations-particularly PCI DSS-are met. The position partners closely with IT, Network Engineering, Operations, and Development teams to embed security into infrastructure, applications, and business processes., Security Operations & Incident Response

  • Oversee SIEM alert tuning, investigation, triage, and escalation in coordination with SOC providers
  • Serve as the primary incident response coordinator during security events, including investigation, documentation, and follow-up
  • Develop and deliver security awareness and training initiatives
  • Maintain operational security metrics and prepare reporting for leadership
  • Partner with IT and system owners to manage IAM controls, access reviews, and privileged access governance

Security Architecture & Application Security

  • Act as a subject matter expert for secure network architecture, including firewalls, VPNs, SD-WAN, wireless, and authentication systems
  • Lead firewall and network security review processes to ensure alignment with internal policies and PCI DSS requirements
  • Serve as the primary security stakeholder for internally developed and customer-facing applications
  • Define and maintain application security requirements aligned with PCI DSS 4.0, OWASP ASVS, and secure SDLC practices
  • Partner with development and engineering teams to integrate security into the software development lifecycle
  • Review application designs and architectures for security risks related to authentication, authorization, data handling, and segmentation
  • Oversee application vulnerability management activities, including SAST, DAST, and software composition analysis (SCA)
  • Coordinate remediation, risk acceptance, and exception tracking for application security findings
  • Support and validate application-layer penetration testing and remediation efforts
  • Act as a security escalation point for application-related incidents

Risk, Compliance, & Governance

  • Own the end-to-end vulnerability management lifecycle across infrastructure and applications
  • Coordinate remediation efforts with Network Engineering, IT Infrastructure, Operations, and Development teams
  • Conduct targeted risk assessments and support enterprise risk management activities
  • Lead coordination of PCI DSS compliance activities, including evidence collection, control validation, and engagement with external QSAs
  • Manage the lifecycle of security policies and procedures, ensuring alignment with regulatory and business requirements
  • Support customer, regulatory, and internal audit activities, This role operates in a hybrid work model within a fast-paced managed services environment supporting large, distributed customer bases. The position requires close collaboration with cross-functional teams and active leadership of security initiatives that improve operational maturity and reduce risk.
  • This position may be performed in office or as a fully remote role, based on business needs and candidate location
  • Standard business hours with occasional after-hours availability required to support incident response or critical security events
  • Professional work environment whether in office or remote, requiring a dedicated and secure workspace
  • Regular collaboration with technical and non-technical teams across multiple time zones
  • Work performed primarily using computers, secure systems, and standard office equipment

Requirements

  • 5+ years of experience in information security, network security, or security governance roles
  • Bachelor’s degree in information security, Computer Science, MIS, or equivalent professional experience
  • At least one security certification is required (e.g., Security+, CySA+, SSCP, GSEC)
  • Strong working knowledge of vulnerability management tools, SIEM platforms, and log analysis
  • Solid understanding of firewall architectures and access control review methodologies
  • Working knowledge of PCI DSS 4.0 and managed service provider shared-responsibility models
  • Strong understanding of application security principles, including common web vulnerabilities (OWASP Top 10)
  • Experience coordinating remediation efforts across technical and non-technical teams
  • Excellent communication, documentation, and analytical skills
  • Ability to independently manage multiple priorities in a fast-paced environment, * Advanced security certifications such as CISSP, CISM, ISA/QSA, or equivalent
  • Familiarity with SD-WAN, WAF, IDS/IPS, VPN, identity management, and network segmentation
  • Experience supporting or reviewing SAST, DAST, and penetration testing activities
  • Comfortable serving as a functional lead and escalation point across security domains, * Ability to sit for extended periods of time while working at a computer and participating in virtual meetings
  • Frequent use of hands and fingers for typing, navigating systems, and using standard office equipment
  • Ability to visually review and analyze information on computer screens for prolonged periods, including logs, dashboards, and technical documentation
  • Ability to communicate effectively verbally and in writing, including participating in meetings, training sessions, and incident response activities
  • Occasional ability to move within an office environment to attend meetings or collaborate with team members

Benefits & conditions

$100.00 per hour

About the company

Empowering Connections, Inspiring Possibility

SageNet is the single, accountable partner unifying connectivity and digital experiences for widely distributed enterprises. We design, deploy, manage, and monitor critical infrastructure across thousands of locations. Our U.S.-based Network Operations Centers operate 24/7, and our national field force delivers consistent outcomes from pilot to scale.

Trusted connections guide how we work and what we build. On the networking and digital side, it means reliable, secure, and visible systems that keep every store, every screen, and every customer connected. On the human side, it means transparent communication, collaborative problem solving, and long-term partnerships with our customers, teammates, and communities.

With a three-decade track record in managed services, SageNet boasts a long-term customer base that includes some of the nation’s largest retail, restaurant, c-store, and financial brands. Headquartered in Tulsa, SageNet has regional offices in Atlanta, Toronto, and Washington, D.C., As a managed services provider, SageNet maintains a high level of information Security. SageNet has a published Information Security Policy and provides mandatory Security Awareness Training for all employees. SageNet requires that all employees adhere to published SageNet security policy, failure to do so may result in termination of employment. The SageNet security program is only as strong as our people and as such it is the responsibility of all employees to protect corporate and customer data following best practices and policies

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jofdav.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

11:18 min

Addressing audience questions on security and microservice architectures

Reinhard Kugler ¡ LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman ¡ WWC 2022

2:10 min

Defining stream data processing versus standard event processing

Soroosh Khodami Soroosh Khodami ¡ WWC 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira ¡ Coffee With Developers

3:48 min

Leveraging multi-agent systems for autonomous software testing

Ondřej Gróf Ondřej Gróf · WWC Europe 2026

1:45 min

Transitioning from software development to security roles

Stefania Chaplin ¡ WWC 2022

Videos

See all

Related articles

See all