Sr. Information Security Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+8 more
Job description
As a Sr. Information Security Analyst within STAAR Surgical’s Information Technology team, this individual plays a critical role working closely with the business and across the Information Technology organization defining, delivering and supporting information security solutions and supporting roadmaps. In summary this position: works on information security problems that are diverse and highly complex; selects methods and techniques for identifying and advocating effective security solutions; develops approaches to address critical information security issues; and develops and administers schedules and performance requirements.
- Defines and implements information security strategies and procedures.
- Works with engineering teams to define and refine information security and systems management policies and settings.
- Monitors and assesses vendor and 3rd party information security reports/lists.
- Evaluates new and emerging products, technologies and makes recommendations to leadership concerning introduction of new technologies.
- Coordinates, administers, manages and monitors the use of access control systems security tools and intrusion detection systems to identify anomalous events and security infractions that exploit system vulnerabilities.
- Integrates information security controls into an environment to identify risks and reduce their impact.
- Provides analysis of potential risk to information security and recommends solutions.
- Creates and maintains information security documentation.
- Communicates information security procedures to users.
- Reviews and recommends changes to information security policies, including STAAR Surgical IT use policies, Data Sensitivity and Personally Identifiable Information Security Policies and procedures.
- Understands and applies principles, concepts, theories, technologies and standards of professional field.
- Develops and applies specialized knowledge within own discipline.
- Deepens knowledge through exposure to new assignments and continuous learning.
- Knowledge of related industry considerations.
- Good working knowledge and demonstrated ability utilizing systems, tools and procedures to accomplish a job.
- Builds a deeper understanding of processes, procedures, customers and organization.
- Assists program or process development and implementation.
- Coordinates activities and processes.
- Leads or provides direction for information security projects.
- Provides complex analysis of potential risk to information security and recommends innovative solutions.
- Recommends and implements changes to procedures and systems to enhance information systems security.
- Mentor junior information security personnel.
- Works on assignments where considerable judgment and initiative are required in resolving problems and making choices, recommendations, or decisions.
- Regularly exercises discretion and independent judgment on business matters.
- Performs other duties as assigned.
Requirements
- Preferred: Undergraduate degree and 2-6 years relevant experience or Graduate degree and 0-4 years relevant experience.
- Highly desirable: Security certifications such as CISSP, CySA+, GCIH, GSEC, Security+, * Preferred: 6-8 years of relevant experience or equivalent combination of education and work experience., * Applies research, information gathering and analytical and interpretation skills to problems of diverse scope.
- Develops solutions to a variety of problems of moderate complexity.
- Screens, categorizes, evaluates, reconciles, reports and resolves data integrity issues.
- Interprets generally defined practices and methods.
- Recognizes and acts on inconsistencies in data or results and escalates unusual problems.
- Identifies issues beyond the stated situation.
- Works on assignments where considerable judgment and initiative are required in resolving problems and making choices, recommendations, or decisions.
- Regularly exercises discretion and independent judgment on business matters.
- Involved with local or business specific engagement initiatives in support of broader programs.
- Competent in security best practices and defense in depth strategies for multiple platforms (i.e., Linux/Unix, Windows, Mac).
- Competent in staying up to date on common cybersecurity threats, attacks, and TTPs.
- Competent in intrusion detection and investigations.
- Competent in incident handling and reporting.
- Competent in analyzing host-based and network logs.
- Competent in analyzing firewalls rules and configuration.
- Competent in public cloud computing platforms.
- Competent in standard cybersecurity frameworks and implementing security controls.
- Competent in managing privileged account management (PAM) solutions.
- Competent in managing vulnerability scanning solutions.
- Competent in methods of data protection, encryption, and data loss prevention (DLP) solutions.
- Competent in identity and access management methodology.
- Competent in automation scripting languages (i.e., PowerShell, Python, Bash).
- Proficient in developing and managing a security awareness training program.
- Proficient in managing endpoint protection solutions (EDR/XDR).
- Proficient in multifactor authentication (MFA) technologies.
- Proficient in managing email security gateway solutions.
- Ability to analyze more complex security issues, determine its cause and impact to the business and identify the corrective action needed to eliminate and prevent the event for the future.
- Familiar with database technology and query analysis.
- Ability to recommend security standards and procedures.
- Must possess strong verbal and written communication skills and be able to adapt to the level and nature of their audience.
Benefits & conditions
Pay range is $125k - $160k - Final compensation/salary will depend on experience.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
9 Ways to Make Money Hacking
Best Paying Jobs in Technology