Information Security Analyst
Posted 56mins ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Information Security Analyst defending Satellite Office’s global brand portfolio from cyber threats. Hunting threats, responding to major incidents, and strengthening protection across 2,000+ IT assets.
Responsibilities:
- Prevent, mitigate, and respond to major information and cybersecurity events, incidents, and breaches
- Research, recommend, implement, and operate security technologies, controls, and processes
- Protect information systems across a global portfolio of brands and more than 2,000 IT assets
- Secure more than 400 applications and IT systems
- Educate and interface with approximately 5,000 employees globally
- Participate in global IT projects involving applications, infrastructure, security, and business initiatives
- Consult on security for ERP implementations, SIEM use cases, secure network and zero-trust redesigns, filtering technologies, patching, and vulnerability management
- Research threats, security patches, and alerts and implement remedial actions
- Design, test, evaluate, and implement information security technologies and business cases
- Review and maintain security policies, principles, and standards
- Respond to major incidents as a CSIRT member, including ransomware, data exfiltration, detections, and privacy breaches
- Provide occasional out-of-hours response for high-priority or urgent incidents
- Conduct proactive threat hunting and reactive incident response using EDR/XDR, SSE, SIEM, vulnerability management, email and web filters, and other tools
- Investigate and report incidents and provide security awareness training
- Monitor alerts, reports, and logs for potential threats and anomalous events
- Interface with senior management and IT departments to develop and implement risk-based security programs and projects
- Create high-level security metrics reports and deliverables
- Assess current and future threat landscapes and brief the CISO on enterprise risks and threats
- Provide organization-wide information security expertise and training
- Conduct cybersecurity, control, vulnerability, and risk assessments
- Maintain system, infrastructure, and application inventories and ensure appropriate SIEM logging
- Classify data and systems with stakeholders and assess third-party vendor security
- Analyze audits, penetration tests, and security logs to recommend risk mitigation strategies
- Manage internal and external audit and penetration-testing relationships and remediation tracking
- Support ongoing PCI compliance and identify regulatory changes
- Implement and maintain global security policies, procedures, processes, and SLAs
- Monitor and report compliance with security policies
- Explore sustainable IT practices and perform other aligned duties
Requirements:
- Degree in IT, Computer Science, or a related field is strongly preferred but not required
- Knowledge of network and system infrastructures gained in a business environment
- Understanding of, experience in, and/or desire to learn modern software development practices and lifecycle, infrastructure projects, vendor management, and IT service/help desk functions
- Background in help desk, network administration, systems administration, DFIR analysis, or testing strongly preferred
- Ability to discuss IT-related projects and tools deployed or managed, including related security components
- Participation in digital forensic investigations, incident response, and/or root cause analyses strongly preferred
- At least one technical certification strongly preferred, such as CEH, CISSP, OSCP, GCIH, CCSP, CCNP, NSE-4, PCNSE, GCFE, GCFA, CCSA, or equivalent
- Understanding of information risk concepts and principles, or desire to learn them
- Familiarity with cloud technologies, especially AWS and Azure
- Strong documentation skills, including workflows, diagrams, and internal security documentation
- Technical understanding and practical experience with authentication mechanisms, password management tools, EMM/MDM platforms, patch and vulnerability management, firewalls, network capture tools, security models, and other security technologies strongly preferred
- Experience or knowledge of risk, business impact, control, and vulnerability assessments
- Experience developing and documenting strategic, tactical, and project security plans
- Experience with information security management frameworks such as CIS, ISO2700x, and NIST CSF
- Strong understanding of business applications, including ERP and financial systems
- High-level technical knowledge of operating systems and security technologies including SIEM, log aggregation, network security appliances, email filters, IAM, EDR, cryptography, SSE, vulnerability scanners, anti-malware solutions, security awareness training platforms, automated policy compliance tools, and desktop security tools
- Experience developing, documenting, and maintaining security policies, processes, procedures, and standards, or strong desire to learn
- Knowledge of network infrastructure, including routers, switches, firewalls, network protocols, and concepts, or strong desire to learn
- Ability to work with minimal supervision and stay current on security trends, emerging threats, and controls
- Excellent written and verbal communication skills
- Strong analytical and problem-solving skills
- Ability to manage multiple projects with overlapping deadlines
Benefits:
- Learning opportunities, mentoring, and support
- Team-building experiences and company-wide celebrations
- Wellness programs
- World-class offices in premium business hubs
- Opportunities to work with global brands and international clients
- Continuous learning and development
- Engaging employee programs
- Modern, comfortable office spaces
- Flexible and collaborative work environment




















