Security Analyst Hybrid

LexisNexis
Horsham, PA, United States
1 day ago
Apply on find.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Shift work
Job source

Tech stack

Computer-Aided Design Microsoft Windows Active Directory Amazon Web Services Microsoft Azure Big Data Cloud Computing Cloud Computing Security Cloud Engineering Configuration Management Cyber Security Linux
+21 more
DevOps Identity and Access Management Information Systems Security Architecture Professional Network Security Windows Servers Azure Active Directory Cloud Services Microsoft Copilot Zero Trust Network Access Virtualization Technology Software Vulnerability Management Policy as Code SSL Certificate Management Enterprise Software Applications Cloud Platform System Microsoft InTune Tanium Platform Expertise Infrastructure Automation Frameworks Information Technology Claude Qualys

Job description

The Infrastructure Compliance Analyst III - Infrastructure Security serves as a security advisor to Infrastructure Engineering, partnering with Cloud Engineering, Platform Engineering, Site Reliability Engineering (SRE), and Systems Engineering teams to design, implement, and continuously improve secure infrastructure services. This role bridges the gap between Security, Governance Risk & Compliance (GRC), and Infrastructure by translating security requirements into practical engineering solutions that enable the business while reducing organizational risk, * Partner with engineering teams throughout the design, implementation, and operational lifecycle to ensure infrastructure solutions are secure, scalable, resilient, and compliant.

  • Interpret and translate security frameworks, regulatory requirements, and organizational security policies into actionable technical guidance for infrastructure engineers.
  • Provide subject matter expertise on secure architecture, operating system hardening, identity management, cloud security, network security, encryption, certificate management, and infrastructure best practices.
  • Work closely with Governance, Risk & Compliance (GRC) and Information Security teams to understand compliance objectives, security findings, audit requirements, and risk management priorities while communicating those requirements effectively to infrastructure teams.
  • Guide infrastructure teams through vulnerability remediation efforts by helping prioritize findings, identifying practical remediation strategies, evaluating operational impacts, and validating successful remediation.
  • Develop secure configuration standards using industry best practices including DISA STIGs, vendor hardening guidance, and organizational security baselines.
  • Assist engineering teams in implementing and maintaining compliant configurations across Windows, Linux, virtualization platforms, cloud services, identity platforms, storage systems, and enterprise infrastructure.
  • Aggregate, analyze, and interpret vulnerability, compliance, operational, and infrastructure data to identify trends, measure organizational risk, and recommend strategic improvements to the company’s security posture.
  • Develop executive dashboards, metrics, and reporting that communicate infrastructure security health, remediation progress, compliance status, risk trends, and operational maturity.
  • Collaborate with engineering leadership to prioritize security initiatives based on business risk, operational impact, and strategic objectives.
  • Identify opportunities to automate security validation, compliance reporting, configuration management, vulnerability remediation, and infrastructure governance using modern engineering practices.
  • Evaluate emerging technologies, security controls, and infrastructure practices to continuously modernize the organization’s security capabilities.
  • Promote a “Security by Design” culture by embedding security considerations into infrastructure planning, engineering standards, operational processes, and technology roadmaps.
  • Provide technical leadership during infrastructure modernization initiatives including cloud migrations, platform upgrades, operating system lifecycle management, and enterprise technology transformations.
  • Participate in security architecture reviews, infrastructure design discussions, change management activities, and technical governance boards.
  • Develop technical documentation, security standards, implementation guides, engineering playbooks, and operational procedures that improve consistency across infrastructure teams.
  • Advise engineers on security best practices, secure engineering principles, and modern infrastructure security techniques.
  • Continuously evaluate Reed Tech’s infrastructure security posture and recommend long-term improvements.
  • Advocate for modern security practices including Zero Trust, Infrastructure as Code, Policy as Code, Continuous Compliance, and Secure Configuration Management.
  • Champion automation-first security practices that reduce manual effort while improving consistency and compliance.

Requirements

  • Comfortable using AI tools (e.g., Copilot, Claude) to accelerate compliance documentation and evidence review, with sound judgment on appropriate use given data sensitivity and regulatory requirements
  • Bachelor’s degree in Information Security, Computer Science, Information Technology, Engineering, or equivalent professional experience.
  • 7+ years of experience in infrastructure engineering, cybersecurity, cloud engineering, or enterprise systems administration.
  • Strong knowledge of Windows Server, Linux, Active Directory, Microsoft Entra ID, networking, virtualization, cloud infrastructure, and enterprise platforms.
  • Experience interpreting and implementing security frameworks such as NIST SP 800-53, NIST Cybersecurity Framework (CSF), DISA STIGs, ISO/IEC 27001, and FedRAMP.
  • Experience with vulnerability management platforms such as Qualys, Tenable, or Rapid7 and enterprise endpoint management platforms such as Tanium or Microsoft Intune.
  • Experience supporting cloud environments including Microsoft Azure and AWS.
  • Strong analytical skills with the ability to interpret large datasets and transform technical information into meaningful recommendations.
  • Excellent communication skills with the ability to explain complex security concepts to technical and non-technical audiences.

Benefits & conditions

We promote a healthy work/life balance across the organisation. We offer an appealing working prospect for our people. With numerous wellbeing initiatives, shared parental leave, study assistance and sabbaticals, we will help you meet your immediate responsibilities and your long-term goals.

Working Pattern

Working flexible hours - flexing the times when you work in the day to help you fit everything in and work when you are the most productive.

About the Business

About the company

hackajob is collaborating with LexisNexis to connect them with exceptional professionals for this role.

About the Business

LexisNexis Reed Tech brings clarity to innovation for businesses worldwide. We enable innovators to accomplish more by helping them make informed decisions, be more productive, comply with regulations, and ultimately achieve a competitive advantage for their business. Our Reed Tech suite of SingleSource for Medical Devices, SingleSource for Drug Products, and Navigator for Drug Labels enables life sciences companies to create product data management strategies and meet compliance deadlines on time. We are proud to directly support and serve these innovators in their endeavors to better humankind. For more information, please visit ., LexisNexis Legal & Professional provides legal, regulatory, and business information and analytics that help customers increase their productivity, improve decision-making, achieve better outcomes, and advance the rule of law around the world. As a digital pioneer, the company was the first to bring legal and business information online with its Lexis and Nexis services.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on find.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:40 min

Choosing Claude Sonnet 3.7 to balance signal and noise

Merrill Lutsky Merrill Lutsky · World Congress 2025

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:16 min

Containing Claude Code within a secure sandbox environment

Luke Hinds · Coffee With Developers

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all