Who Our Client Is:
Our client is a purpose-driven organization certified as a B Corporation, committed to using business as a force for good. Their Information Security team is small, skilled, and nimble, empowered to secure and defend the organization and its subsidiaries.
What Our Client Needs:
Our client is seeking a Senior Security Analyst to support Network and Endpoint Protection, Security Architecture, and the organization's Governance, Risk, and Compliance (GRC) program. This is a remote role reporting directly to the Director of Information Security & Data Privacy. The analyst will help maintain and improve technical safeguards, evaluate security risks in systems and business initiatives, and contribute to audit readiness and security assurance, while also supporting incident response, security awareness, and the Privacy Program.
What You'll Do:
- Maintain and improve network, endpoint, and related security controls
- Monitor security tools and investigate alerts or suspicious activity, coordinating escalation and response as appropriate
- Help assess and prioritize weaknesses in network and endpoint configurations
- Partner with IT and other technical teams to implement and maintain effective protections
- Participate in security reviews of systems, integrations, cloud services, and significant technology changes
- Identify security risks and recommend practical mitigations that account for business needs
- Review designs involving authentication, authorization, access control, encryption, and secure data handling
- Support audit and assurance activities, including ISO 27001, SOC 2, customer security assessments, and related reviews
- Help prepare evidence, maintain security documentation, and track findings and remediation actions
- Assist with incident response, security awareness efforts, and the Privacy Program in partnership with Legal, Product, Engineering, and other stakeholders
What You'll Need:
- Bachelor's degree in Information Security, Computer Science, Information Technology, or equivalent professional experience
- 3+ years of progressive experience in Information Security, Cybersecurity, Security Engineering, or related discipline
- Experience supporting security and compliance programs involving ISO 27001, SOC 2, NIST CSF, or similar standards and frameworks
- Experience performing security risk assessments and vulnerability management
- Working knowledge of cloud security principles and technologies in environments such as AWS, Azure, or Google Cloud
- Strong understanding of networking, authentication, encryption, access control, and security architecture principles
- Strong written and verbal communication skills, including the ability to communicate security risks and recommendations to technical and non-technical stakeholders
- Intellectual curiosity and a desire to understand the "what and why"
What They Offer:
- Compensation range of $77,000 to $82,000 per year, with $4,000 bonus potential
- Paid time off including vacation, sick time, company holidays, and floating holidays
- Work-from-home flexibility ‒ the convenience of remote work
- Company contribution toward the cost of individual health care premiums
- Opportunity to participate in a company-sponsored 401(k)
- Access to training, education, and ongoing professional development
- Access to a third-party professional coach for every employee
- Tuition reimbursement opportunities to support continued learning
- Be part of a purpose-driven organization committed to using business as a force for good as a Certified B Corporation
Our client believes that diversity fuels innovation, strengthens teams, and drives success. They are committed to fostering a workplace where every individual, regardless of background, feels valued, respected, and empowered to thrive. Discrimination or harassment of any kind is strictly prohibited. Our client does not discriminate based on race, color, religion, sex, sexual orientation, gender identity or expression, national origin, ethnicity, age, disability, veteran status, marital status, or any other characteristic protected by applicable laws.