Senior Information Security Analyst
# Senior Information Security Analyst **cobb systems group** · Remote · `Remote` 🕒 **Статус:** *Опубликовано: 5 дней назад* · *Источник: Indeed* --- ### About the Role The Senior Information Security Analyst strengthens enterprise cyber risk management by improving risk visibility, reducing exposure, validating security control effectiveness, and producing clear business-focused reporting for technical, audit, compliance, and executive stakeholders. The role supports a maturing Information Security program across vulnerability management, security controls, cloud operations, data protection, governance, risk, compliance, and cyber defense. Primary Responsibilities This position is responsible for measurable remediation of vulnerabilities and security findings, effective governance of cloud, application, identity, and data protection controls, audit-ready evidence and risk documentation, and concise reporting that enables timely leadership decisions. The successful candidate will use enterprise security and risk management platforms to assess security posture, validate remediation, review security incidents, evaluate control effectiveness, support audit and regulatory requirements, and provide meaningful risk intelligence. Essential Duties and Responsibilities Vulnerability and Findings Management: Lead analysis, prioritization, tracking, and reporting of vulnerability, application security, cloud security, endpoint, and infrastructure findings to drive timely remediation and risk reduction. Risk Governance: Support risk acceptance, exception, deferment, and compensating control processes by ensuring decisions are documented, justified, time-bound, and aligned to organizational risk appetite. Security Control Review: Evaluate security controls across Microsoft 365, Microsoft Defender , Microsoft Sentinel, Microsoft Purview, Microsoft Entra ID, AWS, Azure, ServiceNow (), Qualys, SonarQube, and related enterprise platforms. Architecture and Advisory Support: Participate in security architecture, threat modeling, DevSecOps, identity and access management, privileged access, data protection, and third-party risk reviews to identify control gaps and recommend practical mitigation actions. Audit and Compliance Support: Support internal audits, client audits, regulatory reviews, and due diligence activities through evidence collection, remediation tracking, risk analysis, and clear status reporting. Metrics and Reporting: Develop dashboards, metrics, executive summaries, and recurring reports that communicate security posture, remediation progress, compliance performance, control effectiveness, and emerging risk trends. Required Skills and Qualifications This role will work with enterprise security and risk management platforms including Qualys, Microsoft Defender , Microsoft Sentinel, Microsoft Purview, Microsoft Entra ID, ServiceNow (), SonarQube, Power Automate, Power BI, majorly Azure, AWS to a lesser extent and related security and compliance technologies. Experience and Education Education and Experience: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent work experience, with 7-12 years of progressive information security experience across vulnerability management, security operations, cloud security, risk management, governance, compliance, audit support, or related cybersecurity disciplines. Technical Knowledge: Proven experience with vulnerability management, DLP, Microsoft Purview, Microsoft Defender, Microsoft Sentinel, Microsoft Entra ID, Qualys, Splunk, ServiceNow, Power BI, or comparable security and risk management platforms. Security and Risk Expertise: Strong understanding of Microsoft 365 security services, cloud security concepts, identity controls, application security findings, regulatory obligations, and industry frameworks such as CIS Controls and SOC 2 standard. Communication and Execution: Excellent analytical, written, verbal, and problem-solving skills, with the ability to work independently and collaboratively in a fast-paced environment. Certifications: Relevant certifications such as CCSP, CISSP, SSCP, GCED, or similar are preferred. Performance Expectations Success in this role will be measured by improved risk visibility, stronger remediation performance, audit readiness, effective security control governance, increased cloud and DevSecOps maturity, and measurable reductions in enterprise cybersecurity risk. : Timely and effective vulnerability remediation, Reduction of vulnerability aging and backlog, Positive trending in overall vulnerability reduction, Monitoring and reduction of exposure to vulnerabilities listed in the CISA Known Exploited Vulnerabilities (KEV) Catalog, Consistent tracking and reporting of relevant vulnerability exposure metrics. Work Location: Remote
Наблюдалась 2026-09-15, впервые 2026-09-10, источник — Indeed.