Information Security Analyst

Hagadone Media Group

Coeur d'Alene, ID

JOB DETAILS
SKILLS
Access Control, Administrative Management, Analysis Skills, Artificial Intelligence (AI), Artificial Intelligence (AI) Programming Languages, Best Practices, Business Operations, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Communication Skills, Communications Security (COMSEC), CompTIA Security+, Computer Science, Computer Security, Data Analysis, Data Recovery, Disaster Recovery, Documentation, Documentation Review, Emerging Technology, HRIS/HRMS, Incident Response, Industry Standards, Information/Data Security (InfoSec), Internet Security, Legal, Machine Learning, Maintain Compliance, Microsoft Windows Server, Microsoft Windows System Administration, Modeling Languages, PCI, Penetration Testing, Photography, Policy Development, Presentation/Verbal Skills, Privacy Controls, Regulatory Compliance, Regulatory Requirements, Risk, Risk Analysis, Risk Management, Security Analysis, Security Compliance, Security Information and Event Management (SIEM), Security Patches, Software Administration, Software Patches, Staff Training, Standard Operating Procedures (SOP), System Operations, Systems Administration/Management, Team Player, Technical Leadership, Technical Support, Technical Writing, Time Management, Training/Teaching, Trend Analysis, Vulnerability Scanners, Writing Skills
LOCATION
Coeur d'Alene, ID
POSTED
2 days ago

POSITION SUMMARY

The Information Security Analyst reports directly to the CIO and is responsible for supporting and strengthening the organization's cybersecurity posture. This is done through vulnerability management, security operations, governance, risk management, compliance initiatives, and information security program development. This position works collaboratively with IT, HR, Legal, and business teams to identify and mitigate security risks, maintain security policies and procedures, support incident response activities, and ensure compliance with industry standards and regulatory requirements. The Information Security Analyst also plays a key role in disaster recovery planning, security awareness training, technical documentation, and the secure adoption of emerging technologies, including Artificial Intelligence (AI). This role requires a proactive, analytical professional who can balance technical security requirements with business objectives while helping protect organizational data, systems, and operations. This is a primarily on-site role based in Coeur d'Alene, Idaho. Due to the collaborative nature of this position, regular in-person attendance is required.

ESSENTIAL DUTIES AND RESPONSIBILITIES

  • Vulnerability & Patch Management: Track missing patches, CVEs, and vulnerability remediation progress. Coordinate security patching and upgrades across Windows servers, network devices, and appliances. Define patching priorities based on business risk, ensuring proper change documentation and post-patch validation.
  • Security Operations & Incident Response: Monitor EDR and SIEM alerts, escalating potential security incidents as appropriate. Participate in cybersecurity incident response, remediation planning, and follow-up tracking.
  • Governance, Risk, & Compliance: Support PCI audits, regulatory compliance reviews, and quarterly/annual security scans. Work with internal teams and third parties to remediate findings.
  • Policy Development & Maintenance: Develop and maintain comprehensive IT security policies, standards, and guidelines, including Acceptable Use, Access Control, Data Classification, and Incident Response.
  • Technical Documentation: Proficiency in creating and updating technical documentation, such as incident response playbooks, disaster recovery runbooks, and security configuration guides.
  • Framework Alignment: Ensure policies and procedures align with industry best practices, established cybersecurity frameworks, and regulatory requirements such as PCI-DSS.
  • Policy Exceptions & Risk: Manage the policy exception process by evaluating business justification, assessing associated security risks, and recommending compensating controls.
  • Operational Integration: Conduct periodic reviews of documentation to ensure it reflects current operational practices, technology changes, and the evolving threat landscape.
  • Enforcement & Compliance: Collaborate with internal departments such as HR, Legal, and IT to support policy enforcement, track employee acknowledgments, and integrate security guidelines into standard operating procedures.
  • Disaster Recovery: Support backup and DR planning by defining recovery objectives, ensuring critical system coverage, reviewing backup statuses, participating in restore testing, and maintaining DR runbooks.
  • Security Research: Help create and deliver cybersecurity awareness training for employees. Stay current on emerging cybersecurity trends, threat landscapes, and AI-related technologies.
  • Lead Secure AI Adoption: Champion the organization's AI initiatives by providing strategic security guidance, evaluating AI platforms for data privacy and security risks, and ensuring business adoption aligns with organizational risk tolerance. Additionally, work closely with Hagadone team members to provide and participate in hands-on training opportunities that build practical AI knowledge, strengthen secure adoption practices, and support effective use of AI tools across the organization.
  • Promote Responsible AI Usage: Develop and enforce AI acceptable use guidelines, proactively educating employees on ethical usage, data protection, and the risks of inputting sensitive company information into public AI models.
  • IT Communications & Security Awareness: Work directly with the Corporate Administrative Manager to serve as the organization's primary liaison for IT and cybersecurity communications by developing and delivering company-wide updates on technology initiatives, cybersecurity threats, AI developments, system changes, security best practices, and incident-related communications. Partner with HR, IT, and leadership to ensure employees receive timely, consistent, and understandable information regarding HRIS implementations, software updates, security policies, compliance requirements, and emerging technology risks, while fostering a culture of security awareness and responsible technology use.

QUALIFICATIONS AND REQUIREMENTS

  • Bachelor's degree in Cybersecurity or Computer Science.
  • 3 or more years of relevant IT, Cybersecurity, system administration, infrastructure, or information security experience.
  • Familiarity with vulnerability scanning, penetration testing concepts, and remediation workflows.
  • Strong verbal and written communication skills with the ability to effectively collaborate with internal teams, external partners, and stakeholders.
  • Ability to work effectively both independently and as part of a team, with a strong willingness to learn across diverse cybersecurity and operational areas.
  • Familiarity with AI and machine learning concepts, including generative AI and Large Language Models (LLMs), with practical experience in assessing security and data privacy risks associated with these technologies. Ability to develop and implement AI-specific security guidelines and policies.
  • Demonstrated ability to write, edit, and maintain comprehensive technical documentation, including security policies, procedures, incident response plans, and disaster recovery runbooks.
  • Experience in documenting security assessments, vulnerability findings, and remediation plans.

PREFERRED CERTIFICATIONS

  • CompTIA Security+, CySA+, CISSP, CISM, or similar industry-recognized certifications.

COMPENSATION AND BENEFITS

  • Competitive compensation package based on experience, skills, and qualifications.

Medical Benefits

  • Full-time employees are offered medical benefits at the first of the month following 60 days of employment.
  • Coverages offered: medical, dental, vision, life insurance, flexible reimbursement plans, hospital indemnity, critical care, accident, and short-term disability.
  • All team members and covered dependents have access to The Hagadone Medical Clinic. This medical clinic offers no co-pay, no deductibles, free prescriptions, and is located on-site.

401(k) Plan

  • Team members are eligible to participate at the age of 21 years or greater, with no hour requirements.
  • Team members qualify at the first of the month following 60 days of employment.
  • The Hagadone Corporation offers a 401(k) Plan with a Company Match.

PTO

  • After 6 months of employment, the team member is awarded 7 days PTO.
  • After 1 year, the team member is awarded 10 days PTO.
  • After 2 years, the team member is awarded 15 days PTO.
  • After 5 years, the team member is awarded 20 days PTO.


Employee Discounts

  • Multiple employee discounts offered such as 25% off the CDA Resort Spa, 20% off at any Hagadone Restaurant, free daily cruises, special room rates, 20% off at Quicksilver Photography, and much more!

About the Company

H

Hagadone Media Group