> Markdown version of [/jobs/ext/2836013-information-security-analyst](https://www.wearedevelopers.com/jobs/ext/2836013-information-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst - **Company:** Kforce Inc. - **Location:** Woburn, MA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, PCI Data Security Standards, Cloud Services, Security Information and Event Management, Software Vulnerability Management, RSA Archer Platform, Servicenow - **Published:** September 10, 2026 - **Apply:** https://www.dice.com/job-detail/57dd36bc-86d5-4298-9a41-124ade486491 ## About the Role * CISSP, CISM, CRISC, or CISA preferred * 6-9 years of experience in Information Security, IT Risk Management, or Security Engineering * Hands-on experience with Microsoft Purview and Microsoft Defender * Experience conducting risk assessments, security reviews, and control evaluations * Knowledge of NIST CSF, FFIEC, PCI DSS, ISO 27001, COBIT, or similar frameworks * Experience with SIEM and GRC platforms (Archer, ServiceNow IRM, RiskConnect, etc.) ## Description Kforce's client in Woburn, MA is seeking a Senior Information Security Analyst to join a growing cybersecurity and risk management team within a highly regulated environment. This individual will serve as a trusted advisor on information security risk, governance, and compliance initiatives while helping strengthen the organization's overall security posture. The ideal candidate will combine strong technical security knowledge with risk management expertise and the ability to influence stakeholders across the organization. This role will support enterprise risk assessments, security architecture reviews, governance initiatives, and the continued evolution of security technologies and processes., * Lead and execute enterprise-wide risk assessments across applications, infrastructure, cloud services, and business processes * Evaluate and challenge the effectiveness of security controls and recommend risk-based improvements * Serve as a subject matter expert on cybersecurity frameworks, standards, and regulatory requirements * Conduct security and architecture reviews for new applications, technologies, and third-party solutions * Support the adoption, optimization, and governance of Microsoft Purview and Microsoft Defender capabilities * Analyze security events, threat intelligence, and risk indicators to identify emerging security concerns * Assist with incident response, vulnerability management, and remediation tracking activities * Support the development and enhancement of security policies, standards, procedures, and governance processes * Collaborate with IT, Legal, Compliance, Audit, and business teams to assess and manage cybersecurity risk * Contribute to ongoing improvements within Governance, Risk, and Compliance (GRC) programs and supporting platforms * Research emerging threats, technologies, and industry trends to proactively identify and address security gaps ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [ZEISS & Microsoft - Building the Next Generation Medical Ecosystem in the Cloud](https://www.wearedevelopers.com/videos/424-zeiss-microsoft-building-the-next-generation-medical-ecosystem-in-the-cloud) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)