> Markdown version of [/jobs/ext/538758-security-analyst](https://www.wearedevelopers.com/jobs/ext/538758-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Analyst - **Company:** IBA InfoTech Inc. - **Location:** San Jose, CA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Configuration Management, Cyber Security, Rapid Application Development, Information Technology - **Published:** June 14, 2026 - **Apply:** https://ibainfotech.com/security-analyst-jobs-san-jose ## About the Role * Information Technology Experience - Required - 6 Years * IT Security and/or Audit Experience - Required - 6 Years * PCI, NIST, FISMA, HIPPA, CJIS, or related experience - Required - 5 Years * Experience working in large, complex business and/or IT environments - Required - 6 Years * Bachelors or Masters Degree in Computer Science, MIS, Business, Accounting, or Engineering (or related) - Required - 4 Years * Technical skills: knowledge and experience in IT security statutes, regulations, and standards, experience in GRC tool(s). - Required - 5 Years * CISSP/CISM/CISA certifications - Preferred * AWS Cloud experience and certifications - Preferred * Practical experience with commercial and/or Federal Government Governance, Risk & Compliance platforms - Required - 3 Years * Practical experience working with business and IT/LOB stakeholders to complete Risk Assessments - Required - 3 Years * 8-10 total years related experience, ideally in a fast-paced startup environment. * Experience building solid configuration management for rapid application deployment and pipeline environments. * Results-oriented, collaborative professional with ability to work successfully in a highly matrixed organization. * Clear communicator who is very conductive to working in a team environment and helps lift team spirit. * Grit, drive and a strong feeling of ownership. ## Description 6 or more years with IT security and audit experience with extensive knowledge of national/international security and risk management standards including NIST, PCI, CJIS, CMS, ISO, SOX, HIPAA, HITECH and other regulatory requirements . Knowledge of GRC systems, security standards and progressive experience documenting and performing security assessments, and reviews. 1. Assist the CJIS Program Manager/Administrator with the administration of the CJIS Security, Governance, Risk and Compliance (GRC) enterprise risk management processes. 2. Engage and assist specific stakeholders/agencies with risk assessment processes, and identify gaps in security control environment and CJIS compliance requirements. 3. Perform gap analysis of security requirements implemented within the business unit/agency application(s) and operations according to Corporate processes, statute, regulation, standards and CJIS policies. 4. Provide guidance to staff with standard interpretation of CJIS/NIST/FedRAMP controls and other security statutory and regulatory requirements. 5. Assist with policy/process/procedure development and documentation along with entering information into GRC systems to complete risk assessment, analysis and processes. 6. Assist with GRC volume of work for business units/agencies. 7. Assist with establishing Cyber Security/Risk Management Frameworks. 8. Work with team in improving process. 9. Other risk management/cyber security related tasks as assigned. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Containers in the cloud - State of the Art in 2022](https://www.wearedevelopers.com/videos/410-containers-in-the-cloud-state-of-the-art-in-2022) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [It's not easy being green](https://www.wearedevelopers.com/videos/558-it-s-not-easy-being-green) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)