Sr. Information Security Analyst

STAAR
Lake Forest, CA, United States
26 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
0 years minimum
Compensation
$125,000.0 - $160,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Macintosh Computers Computing Platforms Bash Shell CompTIA Security+ Cyber Security Databases Data Integrity Information Leak Prevention Linux Multi-Factor Authentication Identity and Access Management
+8 more
Intrusion Detection and Prevention Intrusion Detection Systems Python (Programming Language) Windows PowerShell Scripting Cyber Threat Analysis Information Technology Vulnerability Analysis

Job description

As a Sr. Information Security Analyst within STAAR Surgical’s Information Technology team, this individual plays a critical role working closely with the business and across the Information Technology organization defining, delivering and supporting information security solutions and supporting roadmaps. In summary this position: works on information security problems that are diverse and highly complex; selects methods and techniques for identifying and advocating effective security solutions; develops approaches to address critical information security issues; and develops and administers schedules and performance requirements.

  • Defines and implements information security strategies and procedures.
  • Works with engineering teams to define and refine information security and systems management policies and settings.
  • Monitors and assesses vendor and 3rd party information security reports/lists.
  • Evaluates new and emerging products, technologies and makes recommendations to leadership concerning introduction of new technologies.
  • Coordinates, administers, manages and monitors the use of access control systems security tools and intrusion detection systems to identify anomalous events and security infractions that exploit system vulnerabilities.
  • Integrates information security controls into an environment to identify risks and reduce their impact.
  • Provides analysis of potential risk to information security and recommends solutions.
  • Creates and maintains information security documentation.
  • Communicates information security procedures to users.
  • Reviews and recommends changes to information security policies, including STAAR Surgical IT use policies, Data Sensitivity and Personally Identifiable Information Security Policies and procedures.
  • Understands and applies principles, concepts, theories, technologies and standards of professional field.
  • Develops and applies specialized knowledge within own discipline.
  • Deepens knowledge through exposure to new assignments and continuous learning.
  • Knowledge of related industry considerations.
  • Good working knowledge and demonstrated ability utilizing systems, tools and procedures to accomplish a job.
  • Builds a deeper understanding of processes, procedures, customers and organization.
  • Assists program or process development and implementation.
  • Coordinates activities and processes.
  • Leads or provides direction for information security projects.
  • Provides complex analysis of potential risk to information security and recommends innovative solutions.
  • Recommends and implements changes to procedures and systems to enhance information systems security.
  • Mentor junior information security personnel.
  • Works on assignments where considerable judgment and initiative are required in resolving problems and making choices, recommendations, or decisions.
  • Regularly exercises discretion and independent judgment on business matters.
  • Performs other duties as assigned.

Requirements

  • Preferred: Undergraduate degree and 2-6 years relevant experience or Graduate degree and 0-4 years relevant experience.
  • Highly desirable: Security certifications such as CISSP, CySA+, GCIH, GSEC, Security+, * Preferred: 6-8 years of relevant experience or equivalent combination of education and work experience., * Applies research, information gathering and analytical and interpretation skills to problems of diverse scope.
  • Develops solutions to a variety of problems of moderate complexity.
  • Screens, categorizes, evaluates, reconciles, reports and resolves data integrity issues.
  • Interprets generally defined practices and methods.
  • Recognizes and acts on inconsistencies in data or results and escalates unusual problems.
  • Identifies issues beyond the stated situation.
  • Works on assignments where considerable judgment and initiative are required in resolving problems and making choices, recommendations, or decisions.
  • Regularly exercises discretion and independent judgment on business matters.
  • Involved with local or business specific engagement initiatives in support of broader programs.
  • Competent in security best practices and defense in depth strategies for multiple platforms (i.e., Linux/Unix, Windows, Mac).
  • Competent in staying up to date on common cybersecurity threats, attacks, and TTPs.
  • Competent in intrusion detection and investigations.
  • Competent in incident handling and reporting.
  • Competent in analyzing host-based and network logs.
  • Competent in analyzing firewalls rules and configuration.
  • Competent in public cloud computing platforms.
  • Competent in standard cybersecurity frameworks and implementing security controls.
  • Competent in managing privileged account management (PAM) solutions.
  • Competent in managing vulnerability scanning solutions.
  • Competent in methods of data protection, encryption, and data loss prevention (DLP) solutions.
  • Competent in identity and access management methodology.
  • Competent in automation scripting languages (i.e., PowerShell, Python, Bash).
  • Proficient in developing and managing a security awareness training program.
  • Proficient in managing endpoint protection solutions (EDR/XDR).
  • Proficient in multifactor authentication (MFA) technologies.
  • Proficient in managing email security gateway solutions.
  • Ability to analyze more complex security issues, determine its cause and impact to the business and identify the corrective action needed to eliminate and prevent the event for the future.
  • Familiar with database technology and query analysis.
  • Ability to recommend security standards and procedures.
  • Must possess strong verbal and written communication skills and be able to adapt to the level and nature of their audience.

Benefits & conditions

Pay range is $125k - $160k - Final compensation/salary will depend on experience.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca · World Congress 2021

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all