Remote job
Sr IT Security Analyst - G&A and Business Applications
Job details
About this role
Role overview A senior IT Security Analyst position focused on protecting enterprise business applications and general-and-administrative (G&A) platforms. The role combines hands-on security engineering with risk and compliance work across SaaS and ERP environments, supporting the integrity of systems that run finance, HR, and other core business operations.
Responsibilities - Assess and strengthen security controls for enterprise applications such as NetSuite (ERP) and SAP SuccessFactors (HRIS), including review of configurations, access models, and integrations - Analyze data flows between business systems and internal platforms, evaluating API and middleware integrations (e.g., Boomi) for authentication, authorization, data exposure, and logging gaps - Perform security reviews and risk assessments for new and existing G&A applications, defining compensating controls where platform limits exist and supporting threat modeling - Align application security with regulatory and audit frameworks including FedRAMP, ISO 27001, SOC 2, and SOX, supporting evidence collection, control validation, and remediation tracking - Contribute to securing SaaS and cloud-hosted applications within AWS environments, reviewing IAM configurations, network exposure, and platform-level risks in partnership with cloud teams
Requirements - 2+ years of experience in IT security, application security, or enterprise systems security - Hands-on experience securing or administering enterprise platforms such as NetSuite or SAP SuccessFactors - Strong understanding of identity and access management (IAM), role-based access control (RBAC), and segregation of duties (SoD) - Familiarity with secure system integration and API security patterns - Working knowledge of compliance frameworks including FedRAMP, ISO 27001, SOC 2, and SOX
Nice to have - Experience with SaaS and cloud-hosted application security in AWS environments - Background collaborating across cloud, platform, and application teams on consistent control implementation
Benefits and work setup - Remote-eligible position with hybrid expectations (2 days per week onsite) for candidates within a 45-mile radius of Boston, MA; Detroit, MI; or Denver, CO - EST working hours required - Compensation range of $110K–$150K plus health, dental, life, STD/LTD, 401K, PTO, and stock purchase options (varies by experience, education, and location)