Remote job
Lead Information Security Analyst
Job details
About this role
Role overview Lead governance, risk, and compliance work for an information security program, helping the organization assess risk and meet requirements such as SOC 2 and the NIST Cybersecurity Framework. The role combines audit leadership, security policy development, vendor reviews, technical assessment, and guidance for other analysts.
Responsibilities - Manage compliance monitoring, audits, risk assessments, and preparation for external reviews. - Maintain security policies, procedures, evidence, and audit records; coordinate their review and implementation. - Assess vendor security during onboarding and periodic reviews, and work with teams to integrate controls into business processes. - Monitor security posture, recommend remediation, and conduct vulnerability, penetration, and system or application security assessments. - Participate in incident response and post incident analysis, and keep current with emerging threats and compliance requirements. - Mentor information security analysts and communicate control issues and recommendations to leaders and partners.
Requirements - Bachelor’s degree in computer science, cybersecurity, IT, or a related discipline. - 5–10+ years of experience in audit, compliance, or technical security work. - Strong knowledge of security controls, audit practices, and compliance programs. - Clear written and verbal communication, including the ability to explain complex control issues to different audiences. - Relevant security, audit, or compliance training or certifications. - Able to manage competing priorities, work through ambiguity, and contribute practical improvements.
Benefits and work setup Remote within the United States, limited to residents of specified eligible states. Applicants must already be authorized to work in the U.S. without visa sponsorship or transfer. The listed base salary range is $120,000–$150,000, with eligibility for an annual incentive bonus.