> Markdown version of [/jobs/ext/2565308-information-security-analyst-iii](https://www.wearedevelopers.com/jobs/ext/2565308-information-security-analyst-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst III - **Company:** SONABLATE CORP. - **Location:** Indianapolis, IN, United States - **Experience:** Expert - **Salary:** $100,000.0 - $115,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Cyber Threat Analysis, Information Technology - **Published:** August 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=45f645201dcccf9d ## About the Role * Bachelor's degree or higher in Information Technology, Cybersecurity, Computer Science, or a related field. * 7+ years of corporate IT cybersecurity experience. * 5+ years of experience supporting medical device cybersecurity. * Strong knowledge of cybersecurity principles, vulnerability management, risk assessment, and security operations. * Experience working with cybersecurity requirements in a regulated medical device environment. * Strong understanding of EU MDR/CE Mark cybersecurity requirements. * Familiarity with: * NIST cybersecurity standards and frameworks * FDA medical device cybersecurity requirements and guidance * HIPAA * GDPR * Experience with SIEM platforms, endpoint security tools, vulnerability monitoring, and cybersecurity incident response. * Experience creating and maintaining cybersecurity policies, procedures, and technical documentation. * Ability to work effectively with technical and non-technical stakeholders across IT, Engineering, Quality, and Regulatory functions. * Ability and willingness to provide Tier 1 and Tier 2 IT support as part of the position. Preferred Qualifications * Security+, CISSP, or other recognized cybersecurity certification. * Experience maintaining or reviewing Software Bills of Materials (SBOMs). * Experience supporting cybersecurity activities throughout the medical device product lifecycle. * Experience working directly with FDA-regulated medical devices. * Experience supporting regulatory submissions, audits, or cybersecurity documentation for medical devices. * Strong analytical, troubleshooting, communication, and documentation skills. ## Description Sonablate is seeking an experienced Information Security Analyst III to join our Indianapolis-based IT team. This senior-level position plays a key role in protecting both our corporate technology environment and the cybersecurity of our medical device systems. The Information Security Analyst III will work cross-functionally with Information Technology, Software Development, Quality, Regulatory, and other teams to support cybersecurity compliance, risk management, security operations, and documentation. This position combines medical device cybersecurity, corporate information security, regulatory compliance, and hands-on IT support. The successful candidate should be comfortable moving between cybersecurity initiatives and day-to-day technical support responsibilities. Key ResponsibilitiesCybersecurity & Compliance * Develop, review, maintain, and update cybersecurity policies, procedures, standards, and supporting documentation for both corporate IT systems and the Sonablate medical device. * Perform internal cybersecurity assessments against applicable standards and regulatory requirements, including: * EU Medical Device Regulation (EU MDR) * FDA cybersecurity requirements and guidance * NIST cybersecurity frameworks and standards * Partner with Quality, Regulatory, Software Development, and IT teams to identify cybersecurity risks and support appropriate remediation activities. * Support cybersecurity testing and documentation associated with the Sonablate medical device. * Help ensure cybersecurity policies and procedures are appropriate, current, and consistently followed. Security Operations * Monitor, investigate, and respond to alerts generated by the Security Information and Event Management (SIEM) platform. * Review and respond to antivirus and endpoint security alerts. * Identify, investigate, document, and escalate potential cybersecurity threats and vulnerabilities. * Maintain the Software Bill of Materials (SBOM). * Monitor newly identified vulnerabilities and coordinate appropriate evaluation, documentation, and response activities. Security Awareness & Training * Own and administer the company's cybersecurity awareness training platform. * Review training content to ensure it remains current and relevant. * Monitor employee completion of required cybersecurity training. * Escalate overdue or incomplete training to management when appropriate. * Help promote cybersecurity awareness and good security practices throughout the organization. IT Support * Provide Tier 1 and Tier 2 technical support to Sonablate employees. * Troubleshoot hardware, software, account access, networking, and other general IT issues. * Document and resolve support requests in accordance with established IT procedures. * Assist with other IT projects and responsibilities as needed. Approximately 50% of this position may be dedicated to IT helpdesk and technical support activities., The successful Information Security Analyst III will be able to balance strategic cybersecurity responsibilities with hands-on technical work. This individual will help Sonablate maintain a strong cybersecurity posture while supporting regulatory compliance, medical device security, corporate IT security, and the day-to-day technology needs of our employees. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [The Avengers Initiative (Practical Ethics for Software Engineers)](https://www.wearedevelopers.com/videos/2070-the-avengers-initiative-practical-ethics-for-software-engineers) ## Related Articles - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)