Information Security Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+8 more
Job description
Lead vulnerability management, prioritization, remediation tracking, and reporting Reduce vulnerability aging, backlog, and overall security exposure Monitor and report exposure to CISA Known Exploited Vulnerabilities (KEV) Support security risk governance, exceptions, risk acceptance, and compensating controls Evaluate security controls across cloud, identity, endpoint, data, and application environments Support security architecture, threat modeling, DevSecOps, IAM/PAM, and third-party risk reviews Provide audit, compliance, regulatory, and due diligence support Build security dashboards, metrics, executive summaries, and risk reports
Must-Have / Preferred Technical Skills Microsoft Defender: Endpoint, Identity, Office 365, Cloud Microsoft Sentinel & Microsoft Purview Microsoft Entra ID Qualys ServiceNow: ITSM, CMDB, IRM, Vulnerability Response Azure strong experience AWS working knowledge Splunk SonarQube Power BI & Power Automate Vulnerability Management / DLP / Cloud Security CIS Controls & SOC 2, Timely vulnerability remediation | Reduction of vulnerability aging & backlog | Overall vulnerability reduction | CISA KEV exposure monitoring | Security risk metrics & reporting | Audit readiness | Control effectiveness
Requirements
7 12 years of progressive Information Security experience Strong background in vulnerability management, security operations, cloud security, GRC, compliance, and audit support Bachelor s degree in Cybersecurity, IT, Computer Science, or related field preferred CISSP, CCSP, SSCP, GCED or similar certifications are a plus
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Understanding and Mitigating Common Web Vulnerabilities
Walking Into The Era of Supply Chain Risks
9 Ways to Make Money Hacking