Information Security Analyst

Kforce Inc.
Woburn, MA, United States
15 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Working hours
Regular working hours
Job source

Tech stack

Control Objectives for Information and Related Technology (COBIT) Cyber Security PCI Data Security Standards Cloud Services Security Information and Event Management Software Vulnerability Management RSA Archer Platform Servicenow

Job description

Kforce’s client in Woburn, MA is seeking a Senior Information Security Analyst to join a growing cybersecurity and risk management team within a highly regulated environment. This individual will serve as a trusted advisor on information security risk, governance, and compliance initiatives while helping strengthen the organization’s overall security posture. The ideal candidate will combine strong technical security knowledge with risk management expertise and the ability to influence stakeholders across the organization. This role will support enterprise risk assessments, security architecture reviews, governance initiatives, and the continued evolution of security technologies and processes., * Lead and execute enterprise-wide risk assessments across applications, infrastructure, cloud services, and business processes

  • Evaluate and challenge the effectiveness of security controls and recommend risk-based improvements
  • Serve as a subject matter expert on cybersecurity frameworks, standards, and regulatory requirements
  • Conduct security and architecture reviews for new applications, technologies, and third-party solutions
  • Support the adoption, optimization, and governance of Microsoft Purview and Microsoft Defender capabilities
  • Analyze security events, threat intelligence, and risk indicators to identify emerging security concerns
  • Assist with incident response, vulnerability management, and remediation tracking activities
  • Support the development and enhancement of security policies, standards, procedures, and governance processes
  • Collaborate with IT, Legal, Compliance, Audit, and business teams to assess and manage cybersecurity risk
  • Contribute to ongoing improvements within Governance, Risk, and Compliance (GRC) programs and supporting platforms
  • Research emerging threats, technologies, and industry trends to proactively identify and address security gaps

Requirements

  • CISSP, CISM, CRISC, or CISA preferred
  • 6-9 years of experience in Information Security, IT Risk Management, or Security Engineering
  • Hands-on experience with Microsoft Purview and Microsoft Defender
  • Experience conducting risk assessments, security reviews, and control evaluations
  • Knowledge of NIST CSF, FFIEC, PCI DSS, ISO 27001, COBIT, or similar frameworks
  • Experience with SIEM and GRC platforms (Archer, ServiceNow IRM, RiskConnect, etc.)

Benefits & conditions

The pay range is the lowest to highest compensation we reasonably in good faith believe we would pay at posting for this role. We may ultimately pay more or less than this range. Employee pay is based on factors like relevant education, qualifications, certifications, experience, skills, seniority, location, performance, union contract and business needs. This range may be modified in the future.

We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.

Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce’s sole discretion unless and until paid and may be modified in its discretion consistent with the law.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:41 min

Transitioning artificial intelligence infrastructure into scalable commodity cloud services

juarezjunior juarezjunior · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · World Congress 2025

47 sec

Advantages of edge inference over cloud API services

Sasha Denisov Sasha Denisov · World Congress 2026 Europe

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all