> Markdown version of [/jobs/ext/502819-information-security-analyst](https://www.wearedevelopers.com/jobs/ext/502819-information-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst - **Company:** Fitness International, LLC - **Location:** Irvine, CA, United States - **Experience:** Experienced - **Salary:** $74,880.0 - $89,440.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing, CompTIA Security+, Cyber Security, Data Centers, Multi-Factor Authentication, Identity and Access Management, Phishing, User Provisioning Software, Software Vulnerability Management, Data Logging, Vulnerability Analysis - **Published:** June 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=303071a6a26bc8ae ## About the Role Do you have experience in Vulnerability management?, This position supports a large, distributed enterprise environment with thousands of employees and endpoints across hundreds of locations, requiring strong analytical skills, operational discipline, and effective cross-team collaboration., * 3-5 years of experience in Information Security, Security Operations, or a security-focused IT role * Hands-on experience with vulnerability management and remediation tracking in a mid-to-large enterprise environment * Experience supporting email security controls and phishing response workflows * Working knowledge of endpoint security, identity and access management, and incident response processes * Strong analytical, documentation, and communication skills, * Experience working in regulated or compliance-driven environments * Familiarity with common security frameworks and audit requirements * Experience supporting cloud-based productivity, email, and identity platforms Certifications * SSCP and/or CompTIA Security+ (preferred) * Additional vulnerability management or infrastructure security certifications are a plus Work Environment & Physical Requirements * 100% onsite role based in Irvine, California * Work performed in office and data center environments * Ability to lift and carry up to 50 pounds for equipment handling or installation * Ability to sit, stand, and work at a computer for extended periods, * Employment is contingent upon successful completion of background checks and other pre-employment requirements ## Description The Information Security Analyst is responsible for supporting and enhancing the organization's security posture through hands-on vulnerability management, email security operations, and compliance-focused security activities. This role operates and monitors core security controls, assists with incident response, and partners closely with IT and compliance teams to reduce risk, maintain audit readiness, and protect enterprise users, systems, and data., Vulnerability Management & Risk Reduction * Conduct vulnerability scanning, validation, and risk-based prioritization across enterprise endpoints, servers, and infrastructure * Track and report remediation efforts for critical and high-risk vulnerabilities in coordination with IT and infrastructure teams * Maintain vulnerability metrics, remediation evidence, and audit artifacts to support compliance and leadership reporting * Assist with system hardening standards and continuous improvement of patch and vulnerability management processes Email Security & User Protection * Monitor, administer, and tune email security controls to defend against phishing, malware, and business email compromise * Investigate user-reported phishing messages and automated detections, assessing impact and recommending response actions * Support enterprise phishing simulations and security awareness initiatives * Analyze email threat trends to identify control gaps and improvement opportunities Security Operations & Incident Support * Monitor and triage security alerts from endpoint, email, and centralized logging platforms * Perform initial investigation and containment support for security incidents impacting users or systems * Escalate confirmed incidents and assist with root cause analysis and post-incident documentation * Identify recurring attack techniques and contribute to improvements in detection and response processes Identity, Access & Endpoint Security * Support identity and access management processes, including user provisioning, deprovisioning, and access reviews * Assist with enforcement and monitoring of MFA, conditional access, and least-privilege access controls * Manage endpoint and mobile device compliance baselines across thousands of managed devices * Maintain accurate asset and endpoint inventory to support security and compliance objectives Compliance, Reporting & Collaboration * Support regulatory and audit activities through evidence collection, access reviews, and control validation * Prepare security, vulnerability, and compliance reports for technical, business, and leadership stakeholders * Collaborate with IT, compliance, and business teams across multiple locations to align security controls with organizational risk * Assist with evaluation and implementation of security tools and process improvements ## Related Videos - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [The Sustainability Race: AI's Promises, Pitfalls and Potential](https://www.wearedevelopers.com/videos/100155-the-sustainability-race-ai-s-promises-pitfalls-and-potential) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [MFA? Game over! Watch your protection collapse – live](https://www.wearedevelopers.com/videos/100322-mfa-game-over-watch-your-protection-collapse-live) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)