SonicJobs Logo
Left arrow iconBack to search

Senior Security Analyst

Energage
Posted a day ago, valid for 19 days
Location

Exton, PA, US

Salary

Competitive

Contract type

Full Time

By applying, a Energage account will be created for you. Energage's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The Senior Security Analyst at Energage is tasked with enhancing the company's information security, privacy, and compliance programs through the implementation of technical controls and risk management practices.
  • This role requires a minimum of 3 years of progressive experience in Information Security or a related field, along with a bachelor's degree in a relevant discipline.
  • The position offers a competitive salary, which is not specified in the job description, and involves close collaboration with various departments to ensure compliance with regulatory standards.
  • Key responsibilities include performing application security reviews, managing vulnerabilities, and supporting security audits while maintaining a focus on business needs.
  • Candidates should possess strong communication skills and a solid understanding of security principles, with preferred certifications such as CISSP or CISM being advantageous.

Senior Security Analyst 

Your Mission as Senior Security Analyst

The Senior Security Analyst is responsible for advancing Energage's information security, privacy, and compliance programs by implementing and continuously improving technical controls, governance processes, and risk management practices. This role serves as a senior technical and operational resource responsible for protecting company systems, customer data, and business operations while enabling the organization's continued growth. 

The position partners closely with Engineering, Product, IT, Legal, HR, and business leaders to embed security and privacy into company operations, ensuring compliance with regulatory requirements and industry best practices while maintaining a practical, business-focused approach to risk management. 

The position reports to the Director of Information Security & Data Privacy. 

Accountability & Impact:
In this role, you’ll...

  • Support the integration of security throughout the Secure Software Development Lifecycle (SSDLC). 
  • Partner with Engineering teams to implement secure coding standards, code scanning, dependency management, and application security testing. 
  • Perform application security reviews, threat modeling, and architecture assessments. 
  • Evaluate new technologies and software solutions for security risks before implementation. 
  • Support vulnerability remediation efforts within internally developed applications. 
  • Network, Infrastructure & Cloud Security 
  • Continuously monitor the organization's security posture using security monitoring platforms, endpoint protection, cloud security tools, SIEM, and vulnerability management solutions. 
  • Investigate security alerts, suspicious activity, and potential incidents and escalate or coordinate response activities as appropriate. 
  • Implement and maintain cloud security controls across SaaS and cloud infrastructure. 
  • Manage encryption, key management, secure storage, identity management, and Data Loss Prevention (DLP) technologies. 
  • Evaluate and recommend improvements to network, endpoint, identity, and cloud security architecture. 

Governance, Risk & Compliance (GRC) 

  • Execute and coordinate external security audits and assurance activities, including ISO 27001 certification and surveillance audits, SOC 2 examinations, customer security assessments, and other applicable compliance reviews. 
  • Support organizational alignment with security frameworks and standards, including the NIST Cybersecurity Framework (NIST CSF) and other applicable industry frameworks. 
  • Serve as the primary Information Security point of contact for external auditors and customer security questionnaires. 
  • Own evidence collection, audit preparation, remediation tracking, and continuous compliance activities. 
  • Maintain and mature the organization's Integrated Management System (IMS). 
  • Develop, maintain, and improve security policies, standards, procedures, and supporting documentation. 
  • Perform enterprise security risk assessments and maintain the organizational risk register. 
  • Conduct comprehensive third-party/vendor security assessments and ongoing vendor risk monitoring. 
  • Track remediation activities and ensure timely resolution of audit findings and identified risks. 

Data Privacy & Governance 

  • Work directly with Product and Engineering to implement application and cloud security and privacy requirements and address identified risks. 
  • Conduct Data Protection Impact Assessments (DPIAs) and privacy risk assessments in collaboration with Legal and appropriate business stakeholders. 
  • Coordinate enterprise data mapping and data flow documentation initiatives. 
  • Maintain data retention, deletion, and classification standards in collaboration with Legal and applicable data owners. 
  • Support organizational compliance efforts related to applicable privacy and data protection requirements, including GDPR, CCPA/CPRA, and other relevant regulations. 
  • Support Legal, leadership, and appropriate stakeholders in privacy incident assessment, investigation, and regulatory notification activities. 
  • Maintain privacy-related policies, procedures, notices, and supporting documentation in collaboration with Legal and appropriate stakeholders. 

Vulnerability & Threat Management 

  • Administer vulnerability management platforms and coordinate enterprise vulnerability scanning. 
  • Analyze vulnerability intelligence and emerging threats. 
  • Prioritize remediation efforts based on business risk. 
  • Coordinate with infrastructure, engineering, and application teams to ensure timely remediation. 
  • Track remediation metrics and provide regular reporting to leadership. 

Security Architecture & Technical Risk 

  • Participate in architecture reviews for new technologies, cloud services, integrations, and business initiatives. 
  • Identify security risks during project planning and recommend appropriate mitigations. 
  • Review identity, authentication, authorization, and access control designs. 
  • Evaluate technical solutions against security standards and organizational risk tolerance. 
  • Support Zero Trust, Identity and Access Management (IAM), and security architecture initiatives. 

Security Operations & Incident Response

  • Participate in and support the organization's incident response program. 
  • Investigate security events and coordinate incident response activities, including investigation, containment, remediation, and recovery. 
  • Assist with the development and maintenance of incident response procedures and playbooks. 
  • Conduct and facilitate root cause analysis and post-incident reviews. 
  • Recommend process and technology improvements based on lessons learned. 
  • Assist with disaster recovery and business continuity planning from a security perspective. 

Security Awareness & Leadership 

  • Promote a culture of security awareness throughout the organization. 
  • Develop and deliver security awareness training. 
  • Mentor junior security analysts and provide technical guidance. 
  • Assist with strategic security improvement initiatives. 
  • Stay current on emerging threats, technologies, regulatory developments, and industry best practices. 
  • Represent Information Security on cross-functional projects and steering committees. 

Cross-Functional Collaboration 

  • Work directly with Product and Engineering to implement application and cloud security requirements and address identified risks. 
  • Collaborate with third-party vendors to ensure adherence to Energage security requirements. 
  • Support customer security assessments and due diligence activities. 
  • Provide security guidance during the procurement and implementation of new technologies. 

Qualifications 

Required 

  • Bachelor's degree in Information Security, Computer Science, Information Technology, or equivalent professional experience. 
  • 3+ years of progressive experience in Information Security, Cybersecurity, Security Engineering, or a related discipline. 
  • Experience supporting security and compliance programs involving ISO 27001, SOC 2, NIST CSF, or similar standards and frameworks. 
  • Experience performing security risk assessments and vulnerability management. 
  • Working knowledge of cloud security principles and technologies in environments such as AWS, Azure, or Google Cloud. 
  • Experience with SIEM, endpoint security, vulnerability management, identity management, and security monitoring tools. 
  • Strong understanding of networking, authentication, encryption, access control, and security architecture principles. 
  • Experience supporting privacy compliance initiatives involving regulations such as GDPR and CCPA/CPRA. 
  • Strong written and verbal communication skills, including the ability to communicate security risks and recommendations to technical and non-technical stakeholders. 

Preferred Certifications 

One or more relevant information security, privacy, audit, or cloud certifications are preferred, such as: 

  • Certified Information Systems Security Professional (CISSP) 
  • Certified Information Security Manager (CISM) 
  • Certified Cloud Security Professional (CCSP) 
  • Global Information Assurance Certification (GIAC) 
  • Certified Information Privacy Professional (CIPP) 
  • CompTIA Security+ 
  • ISO 27001 Lead Implementer or Lead Auditor 

Equivalent or comparable industry-recognized certifications will also be considered.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Energage account will be created for you. Energage's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.