Cutover logo
Cutover

The Collaborative Automation platform

Information Security Analyst

Security AnalystSecurity AnalystOtherRemoteTeam 51-200Since 2016H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

91 days ago

Salary

$145K - $155K / year

No structured requirement data.

Job Description

Information Security Analyst

Cutover

An inclusive work environment is an empowering one. At Cutover, we lead with empathy and enable others to succeed through curiosity, kindness, and self-expression. Location: US, remote (CST or EST time zone), willing to travel to New York office for audits as required We regret that we are unable to provide work visa sponsorship at this time. Cutover provides enterprise technology operations teams with an AI-powered SaaS solution that automates and streamlines complex processes with intelligent runbooks. The Cutover solution enables teams to respond to incidents quickly, recover from IT outages, and manage cloud migrations with precision and efficiency. Cutover is used in many of the world's largest financial institutions to support their critical technology operations, including 5 out of the top 6 largest asset managers and 3 out of the top 5 US banks. What does this role mean to us? We are looking for a versatile, proactive mid-Level Security Analyst to join our lean but high-impact security team. This “generalist” role offers a 360-degree view of Information Security and is designed for someone who thrives on variety—one day you’ll be leading a SOC 2 audit, and the next you’ll be triaging a security alert or refining our AWS security posture. As a key member of a small team, you won’t just be following a playbook; you’ll be writing it. You will have significant autonomy and the power to influence our global security strategy directly. What will you be doing as our Information Security Analyst? - Compliance & Audit Leadership: Support the maintenance of our compliance frameworks, specifically ISO 27001 and SOC2 Type II. You will need to be comfortable being a primary point of contact for external auditors. - Client Assurance: Own the end-to-end process for Client Audits and Security RFIs, translating our complex technical controls into clear, professional, and digestible responses for stakeholders. - Cloud Governance: Apply a GRC lens to our cloud environment, ensuring that our AWS infrastructure aligns with best practices (CIS benchmarks) and triage alerts in line with our internal risk appetite. - Incident Management & Triage: Monitor security tools and act as a first-to-second responder for alert triage. You’ll manage the lifecycle of security incidents, from discovery to post-mortem. - Third-Party Risk Management: Conduct thorough due diligence on suppliers, integrations , ensuring our supply chain meets our rigorous security standards. - Risk-Based Decision Making: Conduct risk assessments across the business, providing actionable advice that balances security requirements with operational efficiency. - Security Automation: Identify opportunities to automate manual GRC and SecOps tasks to increase the team's velocity. What we’d like you to bring to the table… - 3-5 years experience in Information Security, with a proven track record in a ‘full stack’ security or GRC role - Experience triaging alerts (CSPM/SIEM/EDR), incident management and a foundational understanding of cloud native security tools - You enjoy creating processes where none exist and can move from "problem identified" to "solution implemented" independently. - You’ve led SOC2 or ISO27001 audits and know how to manage evidence collection, auditor expectations and communicate to stakeholders effectively. - Relevant certifications are a plus (CISA, CISSP), but we value functional experience and the ability to apply security principles to real-world business problems above all else. The good stuff… - We're excited to offer Share Options as part of our compensation package. - 20 days of PTO per year + public holidays, and we want you to take all of them! - 3 volunteer days to use for any charitable/voluntary cause you would like. - A top-tier private health insurance package. - 401k contribution plan - Work from home stipends - A personal learning and development budget through Learnerbly. You’ll be supported in your quest for knowledge, whatever that looks like to you. - If you’re thinking of starting or growing your family, then you’ll be in great company - more than half of our team are parents and we’ve built a globally consistent parental leave approach that we’re proud of. - Employee Referral Scheme. - Safeguarding the mental health of our teams is paramount for us. If you’d like to, then you’ll be able to avail yourself of multiple Cutover mental health initiatives, from fully subsidized therapy sessions to subscriptions to leading wellbeing platforms. Target compensation package: $145,000-155,000 base salary + stock options + benefits The final offer may vary from the target compensation package, taking into consideration factors such as your experience level and skill set. If we aren't aligned on salary at this stage, we’d still love to hear from you to better understand if there are more suitable opportunities at Cutover. Diversity Statement - Empowering Our Teams We encourage our team to bring their authentic selves to work, which we have found has strengthened workplace relationships and fostered a genuine sense of community. If you are excited by this role, we invite you to apply! Even if your profile doesn’t check all the boxes, please don't simply scroll past! We recognize that talent lies everywhere and that some demographic groups are more likely to apply for a "stretch role" than others. We are always open to different perspectives and professional backgrounds to keep Cutover's culture evolving and to ensure that we never stop learning. Cutover is an Equal Opportunity Employer. Maintaining an equitable hiring process is imperative to our mission. All applicants are considered without regard to race, ethnicity, national origin, religion, sex, gender identity, sexual orientation, age, mental or physical disability, marital status, protected veteran or parental status. Learn more about Life at Cutover, our Guiding Principles, and our latest news on Twitter and LinkedIn

Related Job Pages

More Security Analyst Jobs

CYBER SECURITY ANALYST- (REMOTE- NATIONWIDE)

Compass Group

Founded in 1941, Compass Group is a multinational corporation and the world’s largest provider of contract foodservice and support services. Headquartered in Chertsey, England, U

Security Analyst92 days ago

Salary: $90,000-$110,000 Compass Technology is a dedicated internal team for Compass Group delivering enterprise-wide initiatives that support our diverse customer base and enhance our business operations. Our domain encompasses a vast spectrum of opportunities, from hands-on desk support to Cybersecurity, Cloud Engineering, AI, and Modern Application development. We are committed to building robust IT infrastructures, driving digital transformation, and much more. Job Summary The Cyber Security Analyst is a key contributor in the Cybersecurity organization, primarily responsible for designing, administering, and continuously improving Compass Group North America’s phishing simulation and security awareness program. This role focuses on reducing organizational risk from email borne threats—such as phishing, business email compromise (BEC), malware delivery, and credential harvesting—by shaping user behavior through realistic simulations, targeted education, and measurable outcomes. In addition to leading phishing simulation and awareness initiatives, the cyber security analyst provides support for email security alerting and response, including analysis of reported phishing messages and collaboration with Cybersecurity Administration and Incident Response teams when real-world threats are identified. The ideal candidate is detail oriented, metrics driven, and comfortable blending user communication and technical analysis to strengthen Compass’s human layer defenses. Job Responsibilities - Administer the enterprise phishing simulation program, including campaign planning, user segmentation, scheduling, templates, landing pages, and reporting, ensuring simulations reflect current threat trends and business relevant scenarios. - Design and deliver targeted security awareness and training materials, such as microlearning's, job aids, tip sheets, and role or behavior based interventions informed by simulation results and observed attack patterns. - Analyze phishing simulation and awareness metrics, including susceptibility rates, reporting rates, repeat clickers, and false positives, and translate results into actionable insights and recommendations for technical and business stakeholders. - Continuously mature the phishing and awareness program, introducing new attack techniques (e.g., QR phishing, OAuth consent phishing, BEC scenarios) and adjusting cadence, difficulty, and messaging to align with organizational risk priorities. - Partner with Cybersecurity leadership, HR, and Compliance to align phishing simulations and awareness initiatives with policy requirements, training expectations, and broader culture of security objectives. - Serve as a subject matter resource for phishing related education, providing guidance to stakeholders on emerging social engineering trends and prevention strategies. - Monitor email security posture and phishing activity to identify trends and insights that inform awareness content and simulation design. - Coordinate with Incident Response and other cyber teams on confirmed incidents, ensuring lessons learned are fed back into simulations and training content to prevent recurrence. Program and Operational Support - Generate regular metrics for reporting and dashboards covering phishing simulation performance, awareness effectiveness, email threat trends, and communicate results clearly to both technical and nontechnical audiences. - Support tuning and optimization of phishing defense and email security tooling where improvements directly enhance reporting accuracy, user experience, or simulation fidelity. - Document simulations, investigations, and program changes to ensure repeatability, auditability, and continuous improvement. Qualifications & Experience - 3+ years of experience in cybersecurity, security awareness, phishing defense, or a closely related discipline, with hands-on experience supporting phishing simulations and/or user education initiatives. - Practical experience with phishing simulation and email security platforms, ideally including KnowBe4, Abnormal, and/or Proofpoint (or comparable enterprise solutions). - Strong understanding of phishing and social engineering techniques, attacker tradecraft, and how human behavior influences organizational security risk. - Working knowledge of email security fundamentals (message anatomy, headers, URLs, attachments, sender reputation) sufficient to support investigations and accurate training content. - Demonstrated ability to analyze metrics and trends and translate technical data into clear, actionable awareness messaging. Strong written and verbal communication skills, with the ability to engage effectively with technical teams and end users. Experience working with documentation, metrics, and repeatable processes to support program maturity and operational consistency. Apply to Compass Group today! Click here to Learn More about the Compass Story Compass Group is an equal opportunity employer. At Compass, we are committed to treating all Applicants and Associates fairly based on their abilities, achievements, and experience without regard to race, national origin, sex, age, disability, veteran status, sexual orientation, gender identity, or any other classification protected by law. Qualified candidates must be able to perform the essential functions of this position satisfactorily with or without a reasonable accommodation. Disclaimer: this job post is not necessarily an exhaustive list of all essential responsibilities, skills, tasks, or requirements associated with this position. While this is intended to be an accurate reflection of the position posted, the Company reserves the right to modify or change the essential functions of the job based on business necessity. We will consider for employment all qualified applicants, including those with a criminal history (including relevant driving history), in a manner consistent with all applicable federal, state, and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, the San Francisco Fair Chance Ordinance, and the New York Fair Chance Act. Compass Technology maintains a drug-free workplace. Applications are accepted on an ongoing basis. Associates at Corporate are offered many fantastic benefits. - Medical - Dental - Vision - Life Insurance/ AD - Disability Insurance - Retirement Plan - Paid Time Off - Holiday Time Off (varies by site/state) - Associate Shopping Program - Health and Wellness Programs - Discount Marketplace - Identity Theft Protection - Pet Insurance - Commuter Benefits - Employee Assistance Program - Flexible Spending Accounts (FSAs) - Paid Parental Leave - Personal Leave Associates may also be eligible for paid and/or unpaid time off benefits in accordance with applicable federal, state, and local laws. For positions in Washington State, Maryland, or to be p formed Remotely, click here or copy/paste the link below for paid time off benefits information. https://www.compass-usa.com/wp-content/uploads/2023/08/2023_WageTransparency_CorpAndFoodbuy.pdf Certain positions may require Florida Level 2 background screening. Details: https://info.flclearinghouse.com/ Req ID: 1514147 Compass Technology MARY DICKSON

United States
$90K - $110K / year
Job Closed
OtherRemoteTeam 10,001+Since 1928H1B Sponsor

• Ensure the organization complies with relevant regulatory requirements (e.g., GDPR, HIPAA, CCPA/CPRA) and industry standards (e.g., ISO 27001, SOC 2, NIST CSF, PCI DSS). • Develop, implement, and maintain information security policies, standards, and guidelines. • Conduct regular audits and assessments to identify gaps and ensure adherence to compliance frameworks. • Lead in risk assessments to evaluate potential security threats and vulnerabilities. • Collaborate with cross-functional teams to remediate compliance gaps and reduce risks. • Act as the primary liaison for internal and external audits, including regulatory audits, client security assessments, and third-party audits. • Proactively stay up to date with changes in regulatory and compliance requirements, as well as industry trends.

California + 4 moreAll locations: California | Montana | Minnesota | Mississippi | Missouri
$100K - $150K / year
Job Closed
Rad AI logo

Senior Cybersecurity Analyst

Rad AI

Made for radiologists, by radiologists.

Security Analyst92 days ago
OtherRemoteTeam 51-200Since 2018H1B Sponsor

• Manage SOC 2 Type II audit cycles from scoping through evidence collection to final report, serving as the primary point of contact for auditors and collaborators. • Coordinate HIPAA compliance assessments, including risk analyses, policy reviews, and Business Associate Agreement (BAA) management. • Conduct structured gap analyses against applicable frameworks (SOC 2, HIPAA, ISO 42001, NIST CSF) to identify control deficiencies and develop prioritized remediation roadmaps. • Track risk mitigation and remediation plans, ensuring accountability and measurable progress against accepted risk thresholds. • Serve as the primary responder to enterprise customer security questionnaires, and engage directly with customers and prospects. • Demonstrate a solid understanding of system and data architecture, including cloud infrastructure, data flows, and access controls, in order to answer technical assessment questions accurately and confidently. • Develop and maintain a reusable security response library (trust portal, standard questionnaire answers, and diagrams) to accelerate future engagements. • Act as a security partner to Engineering, Product, Legal, Sales, and Customer Success, translating security requirements into actionable guidance for non-security audiences. • Participate in architecture and design reviews, ensuring new systems and features meet security and compliance requirements before deployment. • Maintain fluency in artificial intelligence and automation technologies, understanding their security and compliance implications within Rad AI’s platforms. • Leverage AI-assisted tools to improve security operations efficiency, including threat analysis, automated evidence collection, and other cybersecurity workflows.

United States
$125K - $175K / year
Job Closed
Rad AI logo

Senior Cybersecurity Analyst

Rad AI

Made for radiologists, by radiologists.

Security Analyst92 days ago
OtherRemoteTeam 51-200Since 2018H1B Sponsor

About Rad AI At Rad AI, we’re on a mission to transform healthcare with artificial intelligence. Founded by a radiologist, our AI-driven solutions are revolutionizing radiology—saving time, reducing burnout, and improving patient care. With one of the largest proprietary radiology report datasets in the world, our AI has helped uncover hundreds of new cancer diagnoses and reduced error rates in tens of millions of radiology reports by nearly 50%. Rad AI has secured over $140M in funding, including a recently oversubscribed Series C ($68M round) led by Transformation Capital, bringing our valuation to $528M. Our investors include Khosla Ventures, World Innovation Lab, Gradient Ventures, Cone Health Ventures, and others—all backing our mission to empower physicians with cutting-edge AI. Our latest advancements in generative AI are used by thousands of radiologists daily, supporting more than one-third of radiology groups and healthcare systems and nearly 50% of all medical imaging in the U.S. at partners including Cone Health, Jefferson Einstein Health, Geisinger, Guthrie Healthcare System, and Henry Ford Health. Recognized as one of the most promising healthcare AI companies by CB Insights and AuntMinnie, and ranked by Deloitte as the 19th fastest-growing company in North America, we are building AI-powered solutions that make a real impact. Most recently, Rad AI was named to CNBC’s Disruptor 50 list, highlighting the innovation and momentum behind our mission. If you’re ready to shape the future of healthcare, we’d love to have you on our team! Why Join Us: Rad AI is redefining the boundaries of artificial intelligence in healthcare. As our Senior Cybersecurity Analyst, you will play a critical role in securing the company, driving compliance programs, managing risks, and serving as a trusted partner to customers and internal teams alike. This is not a purely technical role: it demands equal parts audit, security expertise, project management discipline, and clear communication. This role will report directly to the Director of IT & Cybersecurity. What You'll Be Doing: - Manage SOC 2 Type II audit cycles from scoping through evidence collection to final report, serving as the primary point of contact for auditors and collaborators. - Coordinate HIPAA compliance assessments, including risk analyses, policy reviews, and Business Associate Agreement (BAA) management. - Conduct structured gap analyses against applicable frameworks (SOC 2, HIPAA, ISO 42001, NIST CSF) to identify control deficiencies and develop prioritized remediation roadmaps. - Track risk mitigation and remediation plans, ensuring accountability and measurable progress against accepted risk thresholds. - Serve as the primary responder to enterprise customer security questionnaires, and engage directly with customers and prospects. - Demonstrate a solid understanding of system and data architecture, including cloud infrastructure, data flows, and access controls, in order to answer technical assessment questions accurately and confidently. - Develop and maintain a reusable security response library (trust portal, standard questionnaire answers, and diagrams) to accelerate future engagements. - Act as a security partner to Engineering, Product, Legal, Sales, and Customer Success, translating security requirements into actionable guidance for non-security audiences. - Participate in architecture and design reviews, ensuring new systems and features meet security and compliance requirements before deployment. - Maintain fluency in artificial intelligence and automation technologies, understanding their security and compliance implications within Rad AI’s platforms. - Leverage AI-assisted tools to improve security operations efficiency, including threat analysis, automated evidence collection, and other cybersecurity workflows. Who We're Looking For: - Bachelor’s degree in Information Security, Computer Science, or a related field. - 6+ years of experience in cybersecurity, with at least 2 years of hands-on involvement in compliance programs or security audits. - Demonstrated experience leading or significantly contributing to SOC 2 through full audit lifecycle. - Practical knowledge of risk management frameworks (NIST RMF, ISO 42001, FAIR) and risk treatment processes. - Experience responding to enterprise customer security questionnaires and interfacing directly with customers on security topics. - Strong project management skills with the ability to manage multiple concurrent workstreams in a fast-paced environment. - Ability to communicate complex security and compliance topics clearly to both technical and non-technical audiences, including in customer-facing settings. - Experience reviewing and maintaining information security policies and procedures. - Active security certifications; ideally a CISSP and CISA. Nice to Haves: - Healthcare industry experience and understanding of healthcare data handling obligations. - Experience with project management methodologies (PMP, Agile, Scrum) or formal project management training. - Familiarity with additional compliance frameworks: ISO 27001, NIST CSF, or HITRUST. - Knowledge of DevSecOps practices and integration of security into CI/CD pipelines. Join our world-class team as we build and deploy AI solutions that empower physicians and transform patient care—making a meaningful impact on millions of lives. Driven by our mission, we prioritize transparency, inclusion, and close collaboration, bringing together exceptional people to revolutionize healthcare. If you're passionate about driving innovation and delivering impactful healthcare solutions, we'd love to hear from you! To learn more about what it's like to work at Rad AI, visit https://www.radai.com/life-at-rad-ai For US-Based Full-Time Roles, Rad AI offers a variety of benefits, including: - Comprehensive Medical, Dental, Vision & Life insurance - HSA (with employer match), FSA, & DCFSA - 401(k) - 11 Paid Company Holidays - Location Flexibility (Remote-first company!) - Flexible PTO policy - Annual company-wide offsite - Periodic team offsites - Annual equipment stipend - For roles based outside the US, your recruiter can share more details At Rad AI, we value diversity and provide equal employment opportunities (EEO) to all employees and applicants without regard to race, color, religion, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the San Francisco Fair Chance Ordinance. Please be vigilant regarding job scams. We advise all candidates to apply directly through our official careers page. Our recruiters will use email addresses with the domain @radai.com or no-reply@ashbyhq.com.

United States
$125K - $175K / year