Information Security Analyst managing critical governance, risk, and compliance topics. Leading incident responses and security policy development in a hybrid work model.
Responsibilities
• Will be a point of reference for critical governance, risk, and compliance topics, working across the Plan, Attack and Defend pillars;
• Will handle sensitive projects, critical data, and demanding audits.
**Strategic and analytical:**
• Conduct risk analyses for new projects and systems;
• Develop and review security policies and procedures;
• Coordinate responses to critical incidents (technical and strategic perspective);
• Apply threat intelligence and propose countermeasures;
• Participate in implementing security within DevSecOps pipelines.
**Operational:**
• Tune and improve tools such as SIEM, DLP, and XDR;
• Perform security testing and forensic analysis;
• Track critical vulnerabilities from identification to remediation;
• Serve as the technical point of contact during audits and internal threat investigations.
**Leadership and development:**
• Mentor junior professionals in technical and strategic competencies;
• Contribute to continuous improvement projects within the security area;
• Deliver training and security awareness initiatives;
• Represent the security team in forums, committees, and technical meetings.
Requirements
• Bachelor's degree in Technology fields such as Information Security, Computer Science, Information Systems, or related areas;
• 3–5 years of experience in Information Security;
• Strong communication and interpersonal skills, with the ability to integrate teams and present results;
• Technical writing skills for creating advanced documents and corporate policies;
• Autonomy to make technical decisions and lead projects;
• Analytical profile with mentoring ability, strategic collaboration, and business awareness;
• Focus on continuous improvement and innovation.
***Hard skills:***
• Experience in On-premises environments and in AWS, Azure, or GCP;
• Experience with Docker, Kubernetes, and securing CI/CD (GitLab, Jenkins, SonarQube);
• Scripting/automation experience with Python, PowerShell, or Bash;
• Security best practices for REST/GraphQL APIs and Infrastructure as Code.
***Monitoring and Incident Response***
• Use of SIEM tools (e.g., Splunk, QRadar), SOAR (e.g., Cortex, Splunk SOAR), and XDR (e.g., CrowdStrike, Microsoft Defender);
• Experience with forensic analysis tools (e.g., FTK, Volatility) and vulnerability management (e.g., Nessus, Qualys);
• Familiarity with DLP, UEBA, NGFW firewalls, email security, CASB, and SSPM solutions.
***Threats and Testing***
• Knowledge of Threat Intelligence (e.g., MITRE ATT&CK, Mandiant);
• Execution or support of penetration tests (pentests) and Red Team simulations;
• Basic knowledge of reverse engineering and malware analysis (differential).
Cyber Threat Intelligence Analyst supporting IT Security team in identifying and mitigating cyber threats. Ensuring network security and protecting company secrets in high - tech environment.
Risk Analyst supporting cyber risk management activities for PokerStars and other brands. Ensuring accurate risk documentation, reporting, and stakeholder engagement in Cluj - Napoca, Romania.
Cyber Security Analyst responsible for governance, risk management, and compliance projects for clients and internally at Cyberlogic. Engaging with clients on project - based work while developing policies and standards.
Analista de segurança de informação supporting the maintenance of data privacy and protection programs at Minsait. Involves audit support, training, and compliance with legislation.
IT Security Analyst assisting in managing technology environments ensuring security compliance. Supporting Brasilseg's platforms with adherence to best practices in software and hardware.
Senior Cybersecurity Analyst applying RMF concepts to enhance cybersecurity for defense program. Conducting risk assessments and developing reports, based in Colorado Springs, CO.
Junior Information Security Analyst assisting federal clients at OCT Consulting with NIST security assessments and risk analyses. Responsible for executing hands - on security control assessments and recommending process improvements.
Journeyman Information Security Analyst providing expertise to federal clients in Security Controls Assessments and Risk Analyses. Responsibilities include technical assessments and recommendations for security improvements.
Information Security Analyst supporting security practices at Silimed, the leading silicone implant manufacturer in Latin America. Ensuring compliance and resilience in critical OT & IT environments.
Security Analyst defending enterprise systems against cyber threats. Supporting threat intelligence and incident response activities in a global biotechnology organization.