> Markdown version of [/jobs/ext/2539290-lead-security-analyst](https://www.wearedevelopers.com/jobs/ext/2539290-lead-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Analyst - **Company:** Lennar Corporation - **Location:** Miami, FL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Factor Analysis, Software Vulnerability Management, Computer Equipment, Information Technology, ISO/IEC 27002 - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=64c6222379c4ef42 ## About the Role * Bachelor's degree in Computer Science, Information Security, or a related field; a Master's degree is preferred. * 7+ years of experience in cybersecurity, with a focus on leadership, vulnerability management, GRC, and incident response. * Ideally familiar with one or more regulatory requirements and laws such as, but not limited to, PCI, FFIEC, Sarbanes-Oxley Act (SOX), HIPAA, GDPR, and GLBA. Additionally, experience in one or more: ISO 17799, ITIL and NIST. General understanding of the Factor Analysis of Information Risk (FAIR) methodology. * Strong leadership and management skills, with a proven track record of building and leading effective cybersecurity teams. * Excellent communication and presentation skills, with the ability to influence and engage stakeholders at all levels. * Advanced certifications (e.g., CISSP, CISM, CRISC) are required. * Preferable, but not required, one or more of the following: CRISC, CISSP, CISA, CGEIT, GCCC, GSEC and GISP. Physical & Office/Site Presence Requirements: Regular, in-person attendance at the Lennar office during regular work hours is an essential function of this job. This is primarily a sedentary office position which requires the incumbent to have the ability to operate computer equipment, speak, hear, bend, stoop, reach, lift, and move and carry up to 25 lbs. Finger dexterity is necessary. ## Description The Lead Security Analyst is a senior leadership position responsible for overseeing all cybersecurity activities of GRC. The Lead Analyst will drive the strategic direction of the cybersecurity program, ensuring the organization is well-protected against current and emerging threats., * Lead and manage the cybersecurity team from a technical perspective, having input on/leading strategic direction and ensuring the successful execution of all cybersecurity initiatives. * Develop and maintain the GRC framework, ensuring alignment with business objectives and industry standards. * Serve as a subject matter expert on cybersecurity issues, advising leadership on security risks and mitigation strategies. * Foster a culture of security awareness across the organization through training and education initiatives. * Mentor and coach junior cybersecurity team members, providing technical guidance and leadership. * Create and present risk posture discovery and recommendation reports to risk management leadership. * Review technical reports from vulnerability and penetration testing assessments, and results from tabletop exercises. * Monitor plans of action and milestones for risk remediation requirements from internal and external security assessments, vulnerability reports, audit findings and security gaps. * Liaison with technical and business teams related to business continuity and disaster recovery requirements. * Provide strong oversight of third parties, vendors, and business partners to safeguard against undue risk presented by external entities. * Frequently interact with business units to understand their plans, risk posture and tolerance, and how to support their vision and business obligations with security and risk in mind. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Repository as Network: Visualizing Collaboration in git](https://www.wearedevelopers.com/videos/100189-repository-as-network-visualizing-collaboration-in-git) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [WWC24 - Chris Wysopal, Helmut Reisinger and Johannes Steger - Fighting Digital Threats in the Age of AI](https://www.wearedevelopers.com/videos/926-wwc24-chris-wysopal-helmut-reisinger-and-johannes-steger-fighting-digital-threats-in-the-age-of-ai) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)