> Markdown version of [/jobs/ext/2865914-senior-information-security-analyst](https://www.wearedevelopers.com/jobs/ext/2865914-senior-information-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Security Analyst - **Company:** Teamware Solutions - **Location:** Woburn, MA, United States - **Experience:** Expert - **Salary:** $93,954.0 - $136,739.0 - **Contract:** Temporary to permanent - **Skills:** Artificial Intelligence, Cloud Computing Security, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Data Governance, Information Leak Prevention, Intrusion Detection and Prevention, PCI Data Security Standards, Security Information and Event Management, Software Vulnerability Management, Information Technology, RSA Archer Platform, Servicenow - **Published:** September 12, 2026 - **Apply:** https://www.careerjet.com/jobad/us4bc11bb25f76591cee028e285c4c487d ## About the Role Seeking a Senior Information Security Analyst with 6 9 years of experience in information security, cybersecurity risk management, security engineering, or IT risk management, preferably within a regulated industry. The ideal candidate will have strong expertise in cybersecurity risk, governance, security frameworks, architecture reviews, and risk assessments, along with hands-on experience with Microsoft Purview and Microsoft Defender. This role is ideal for someone who is naturally curious, hands-on, proactive, and comfortable identifying security gaps, evaluating new technologies, and solving evolving cybersecurity challenges., * 6 9 years of experience in information security, cybersecurity risk, security engineering, IT risk, or a related discipline. * Strong experience with Microsoft Purview. * Strong experience with Microsoft Defender. * Strong understanding of cybersecurity risk management and governance. * Experience with security assessments, risk analysis, threat modeling, and/or architecture reviews. * Experience working with GRC platforms or GRC environments. * Strong knowledge of cybersecurity standards and frameworks. * Excellent communication and stakeholder-management skills. * Ability to identify gaps independently and provide practical security recommendations. * Strong curiosity and willingness to learn new technologies. Security Frameworks Strong understanding of one or more of the following: * NIST Cybersecurity Framework (CSF) * ISO 27001 * COBIT * FFIEC * PCI DSS Preferred Technical Experience * Microsoft Purview * Microsoft Defender * SIEM platforms * Vulnerability management tools * Data Loss Prevention (DLP) * Cloud security * Endpoint protection * GRC platforms such as: * Archer * ServiceNow IRM * RiskConnect * Other enterprise GRC platforms GRC Experience The client is open to candidates with experience in any enterprise GRC platform. Specific experience with Archer, ServiceNow IRM, or RiskConnect is preferred but not mandatory. The candidate should be able to work from the IT/security side of GRC, including enhancing existing modules, workflows, controls, and processes within an in-house GRC environment. AI & Emerging Technology * Familiarity with AI tools and their cybersecurity implications. * Understanding of AI-related data protection and privacy risks. * Awareness of AI-enabled threat detection and security automation. * Understanding of third-party and vendor risks associated with AI technologies. * Ability to evaluate emerging technologies and identify potential security gaps. Education & Certifications * Bachelor's degree in Information Security, Computer Science, Cybersecurity, or a related field preferred. * Master's degree is a plus. * Relevant certifications are strongly preferred, such as: * CISSP * CISM * CRISC * CISA ## Description * Perform cybersecurity risk assessments, risk analysis, and control evaluations. * Act as a Subject Matter Expert (SME) for cybersecurity standards, frameworks, policies, and controls. * Conduct security architecture reviews when onboarding new applications, technologies, and systems. * Perform threat modeling and evaluate security risks associated with new applications and technologies. * Identify security gaps and provide practical, risk-based recommendations for remediation. * Partner with IT, security, business, and leadership teams to improve the organization's security posture. * Support the adoption and implementation of Microsoft Purview for data governance, protection, compliance, and security. * Work with Microsoft Defender and related security capabilities. * Support cloud security, endpoint protection, and Data Loss Prevention (DLP) initiatives. * Work with SIEM solutions, vulnerability management platforms, and incident response processes. * Support and enhance the organization's in-house GRC platform, particularly from the IT/security perspective. * Help enhance existing GRC modules, workflows, controls, and processes. * Work with GRC platforms such as Archer, ServiceNow IRM, RiskConnect, or similar solutions. * Evaluate the cybersecurity implications of Artificial Intelligence (AI) tools and technologies, including data protection, threat detection, automation, and third-party risks. * Stay current with emerging technologies and evolving cybersecurity threats. * Collaborate with technical teams and business stakeholders to implement effective security controls and governance practices. ## Related Videos - [Data Governance in the Era of AI](https://www.wearedevelopers.com/videos/1622-data-governance-in-the-era-of-ai) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [How to Stop Your Agents From Going Rogue - Arnav Gupta](https://www.wearedevelopers.com/videos/2152-how-to-stop-your-agents-from-going-rogue-arnav-gupta) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)