Job Closed
This listing is no longer active.
The #1 supply chain platform delivering more growth, less waste and amazing customer experiences. #Fulfillyourpotential
Lead Security Compliance Analyst
Location
United States
Posted
85 days ago
Salary
0
No structured requirement data.
Job Description
Lead Security Compliance Analyst
Blue Yonder
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description This role will work across teams to ensure Blue Yonder product and internal processes are operating and managed with appropriate IT and security controls that meet regulatory, industry, and internal standards. This role partners with cross-functional teams to ensure controls are implemented and operating effectively and manage audit engagements. - Lead IT and security control assessments against information systems, services and teams that support Blue Yonder solutions and internal business processes. - Identify control deficiencies and drive remediation activities with stakeholders. - Support evidence collection and documentation of controls in support of internal and external audits. - Regularly communicate compliance posture to stakeholders and leadership. - Train and prepare control owners for audit participation and evidence collection. - Plan and coordinate internal and external audits. - Manage report reviews, respond to audit findings, and track remediation to closure. Qualifications - 5 years of information security compliance OR IT audit roles. - Must have experience performing end-to-end IT and Security Control testing and remediation tracking. - Strong understanding of IT and security control frameworks (ISO 27001, SOC2, SOX). - Familiarity with cloud security practices and the shared responsibility model. - Certifications such as CISA, CISM, or CISSP (preferred but not required). - Excellent communication and stakeholder management skills. - Bachelor’s degree or equivalent in Information Systems, Accounting, Business or related field. Benefits - Comprehensive Medical, Dental and Vision. - 401K with Matching. - Flexible Time Off. - Corporate Fitness Program. - A variety of voluntary benefits such as Legal Plans, Accident and Hospital Indemnity, Pet Insurance and much more.
Job Requirements
- 5 years of information security compliance OR IT audit roles.
- Must have experience performing end-to-end IT and Security Control testing and remediation tracking.
- Strong understanding of IT and security control frameworks (ISO 27001, SOC2, SOX).
- Familiarity with cloud security practices and the shared responsibility model.
- Certifications such as CISA, CISM, or CISSP (preferred but not required).
- Excellent communication and stakeholder management skills.
- Bachelor’s degree or equivalent in Information Systems, Accounting, Business or related field.
Benefits
- Comprehensive Medical, Dental and Vision.
- 401K with Matching.
- Flexible Time Off.
- Corporate Fitness Program.
- A variety of voluntary benefits such as Legal Plans, Accident and Hospital Indemnity, Pet Insurance and much more.
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Cyber Security Analyst
IntertekIntertek is a leading quality assurance provider serving businesses in the chemicals, construction, engineering, energy, commodities, food, healthcare, consumer goods, retail, gove
• Perform security event analysis as part of the daily responsibilities • Take part in the incident response activities within the region • Support the web, network and email security solutions during the EMEA shift • Become an expert in managing security technologies and participate in incident response process • Help structure the analysis model and incident response process
Security Analyst - Web Application Firewall
TEKsystemsWe're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia.
Description Position Requirements : *Acquire working knowledge of business-critical web applications. *Analyze the installation and configuration of Radware cWAAP whilst sensitive to the behavior of protected web applications. *Review and analyze daily Radware cWAAP logs, relaxing and/or constricting rules as deemed appropriate. *Analyze integration of Radware cWAAP logs with SIEM data. *Collaboration with the Network Services team to sustain acceptable levels of support for Radware cWAAP operations. *Work in collaboration with the Border Protection team to analyze the onboarding of protected web applications. Basic Qualifications: * Three or more years’ experience in direct job-related field (Security, Engineering/Architecture, Computer Science, Cybersecurity). *Ability to adjust to multiple demands, changing priorities, ambiguity, and rapid change, while multitasking effectively. *Exhibit strong influencing / negotiation skills as well as written/verbal communication skills and presentation skills. *Ability to work with and influence developers, development managers, project managers, technology peers, and business contacts are required. *Strong problem solving/analytical skills. Ideal Candidate Will Also Have: * 5+ years of Information Security Knowledge of Information Security, IT Risks and Controls assessment. * Good Python, SQL scripting skills. Bonus points for experience in integration with Radware APIs and Snowflake Data Platform. * Knowledge of information security frameworks, ISO 27001, 27002, NIST CSF, NIST 800-82. * Good Knowledge of OWASP Guidelines for application security. * Good Knowledge of software development processes, integration of security assessments in Software development life cycle (SDLC) process, secure coding is desirable. * Understanding of web application firewall tools, concepts, methodologies. * 1-3 years of broad AWS and Azure experience. Skills SAST, Security, Vulnerabilities, Scanning, OWASP, Java, .NET, Radware, CWAF, Web Application Firewall Top Skills Details SAST, Security, Vulnerabilities, Scanning, OWASP, Java, .NET,Radware,CWAF,Web Application Firewall Additional Skills & Qualifications None Experience Level Intermediate Level Job Type & LocationThis is a Contract position based out of Remote, OR. Pay and BenefitsThe pay range for this position is $60.00 - $65.00/hr. Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following: • Medical, dental & vision • Critical Illness, Accident, and Hospital • 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available • Life Insurance (Voluntary Life & AD&D for the employee and dependents) • Short and long-term disability • Health Spending Account (HSA) • Transportation benefits • Employee Assistance Program • Time Off/Leave (PTO, Vacation or Sick Leave) Workplace TypeThis is a fully remote position. Application DeadlineThis position is anticipated to close on Mar 13, 2026. h4>About TEKsystems: We're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services, and real-world application, we work with progressive leaders to drive change. That's the power of true partnership. TEKsystems is an Allegis Group company. The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law. About TEKsystems and TEKsystems Global Services We’re a leading provider of business and technology services. We accelerate business transformation for our customers. Our expertise in strategy, design, execution and operations unlocks business value through a range of solutions. We’re a team of 80,000 strong, working with over 6,000 customers, including 80% of the Fortune 500 across North America, Europe and Asia, who partner with us for our scale, full-stack capabilities and speed. We’re strategic thinkers, hands-on collaborators, helping customers capitalize on change and master the momentum of technology. We’re building tomorrow by delivering business outcomes and making positive impacts in our global communities. TEKsystems and TEKsystems Global Services are Allegis Group companies. Learn more at TEKsystems.com. The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
Join Our Mission: To Save the World from Unsafe Mobile Apps! NowSecure is the mobile app security software company trusted by the world’s most demanding organizations and most advanced security teams. As the standards-based mobile app risk management company, NowSecure protects the Mobile App Economy. The world’s most demanding organizations, innovative mobile developers and advanced security, privacy, safety and compliance teams entrust NowSecure to safeguard millions of mobile app users across banking, insurance, high tech, IoT, retail, hospitality, energy and government sectors. Only NowSecure delivers continuous security and compliance with the depth, speed, accuracy, and efficiency to meet modern business demands. Dedicated to the open-source community and standards including OWASP,and NIAP, NowSecure is SOC 2 certified and recognized by IDC, Deloitte, Gartner and TAG Cyber.www.nowsecure.com YOUR OPPORTUNITY We’re looking for a Senior Application Security Analyst — a hands-on pentester who thrives on technical challenges, thinks creatively under pressure, and has an insatiable curiosity for how things work (and how they break). If you’re the kind of person who spins up a quick Python script to automate a test, roots a phone just to see what’s inside, or finds joy in reverse engineering an app at 2 AM — you’ll fit right in. In this role, you’ll hunt vulnerabilities, dissect mobile apps and APIs, and collaborate with a team of world-class testers who live and breathe offensive security. You’ll also help evolve our methodologies, develop new tooling, and contribute to NowSecure’s cutting-edge research across mobile, web, and connected systems. WHAT YOU’LL DO - Perform hands-on penetration testing of mobile apps (iOS/Android), APIs, web apps and connected ecosystems (IoT, automotive, medical, wearable). - Conduct vulnerability assessments and reverse engineering using tools like Burp Suite, Frida, mitmproxy, Ghidra, Radare2, IDA, or custom scripts. - Create clear, actionable technical reports that communicate findings and remediation guidance to both developers and security teams. - Act as a trusted advisor to customers, helping them make informed, risk-based decisions about their mobile and app security posture - Build or adapt custom scripts, fuzzers, or automation tools to make testing faster, smarter, and more reliable. - Collaborate with teammates to refine methodologies, share research, and continuously push the boundaries of mobile and web security testing. - Tackle complex problems with creativity; when something doesn’t work, figure out another way. “Scrappy” is a skill set here, not a slogan. WHO YOU ARE You’re a technical problem-solver who thrives on exploration and experimentation. You’re comfortable diving into unfamiliar codebases, debugging network traffic, and learning new tools on the fly. You’re not a button pusher; you’re the kind of tester who asks why something works (or doesn’t) and can pivot quickly when the usual tools fall short. You can translate technical detail into clear communication and enjoy mentoring or collaborating with others. You take ownership, seek out challenges, and are never satisfied with “good enough.” REQUIREMENTS (You must have … ) - Bachelor’s degree in a technical field or 6–8 years of equivalent security experience. - 2+ years of experience in penetration testing or vulnerability assessment of mobile, web, or IoT apps/devices. - Deep understanding of OWASP MASVS / MASTG and app security fundamentals. - Strong experience with intercepting and analyzing traffic using tools like Burp Suite, mitmproxy, ZAP, Charles, or Fiddler. - Proficiency in mobile device rooting/jailbreaking and familiarity with iOS and Android internals, or equivalent hands-on experience in web application penetration testing or firmware reverse engineering. - Strong scripting or development experience (e.g., Python, Java, JavaScript, Ruby, or PowerShell). - Solid grasp of network and web fundamentals — TCP/UDP, HTTP requests, headers, cookies, APIs, and authentication flows. - Excellent technical writing and documentation skills. - Comfort working with Linux, Windows, and macOS environments. - A self-starter mindset - able to work independently, manage multiple projects, and find creative solutions to tough problems. - A demonstrated drive to learn, experiment, and stay on the cutting edge of mobile and appsec trends. DESIRED SKILLS (Stand out from the crowd…) - Familiarity with DAST/SAST tools, mobile instrumentation (e.g., Frida), and dynamic analysis. - Professional services or consulting experience. - Prior security research or exploit development experience. - Knowledge of system/network security, authentication, and applied cryptography. - Familiarity with Frida, Binary Ninja, Radare2, or IDA Pro. - Experience testing in AWS, Azure, or GCP environments. - Contributions to open-source security projects or published research. - Past public speaking experience (conferences, podcasts, etc) - One or more active certifications such as: - Infosec Certified Mobile and Web Application Penetration Tester (CMWAPT) - Offensive Security Web Expert (OSWE) - Offensive Security Certified Professional (OSCP) - GIAC Certified Penetration Tester (GPEN) - GIAC Certified Web Application Defender (GWEB) - GIAC Web Application Penetration Tester (GWAPT) - INE Web Application Penetration Tester eXtreme (eWPTX) - GIAC Mobile Device Security Analyst (GMOB) - 8kSec Certified Mobile Security Engineer (CMSE) - INE Mobile Application Penetration Tester (eMAPT) - TCM-SEC Mobile Application Penetration Testing BONUS POINTS (You have our attention…) - Experience with LTE / GSM protocols or 5G network analysis. - Prior experience using NowSecure tools. - Master’s degree in Computer Science, Cybersecurity, or related field. WE VALUE DIVERSITY We believe that the best ideas come from teams where diverse points of view uncover new solutions to hard problems. We welcome and value team members who bring diverse life experiences, educational backgrounds, cultures, and work experiences. COMPENSATION & BENEFITS - The salary band for this position ranges is competitive and commensurate with experience and performance. This position will be eligible for a competitive annual bonus and equity package. - Comprehensive Medical/Dental/Vision coverage - 401K Plan + Company Match - Remote work flexibility - Home Office Stipend - Paid Parental Leave - Flexible PTO
• Collaborate with the engineering departments to implement security controls from approved security frameworks and drive best IT practices. • Interface with internal partner teams to help drive best practices and compliance. • Evaluate and perform Risk Assessments of new software solutions with internal partners. • Drive deployment of new systems/solutions as needed. • Write procedure documentation for end users as needed to facilitate process improvement. • Help develop IT security training content and drive completion of required security training in collaboration with Human Resources. • Respond to complex security questionnaires, RFP/RFI requests, and client audits. • Facilitate end-to-end evidence gathering for external audits, ensuring all technical and administrative artifacts align strictly with security control requirements and regulatory frameworks. • Evaluate, identify, and remediate the risks associated with current vendors, new vendor acquisitions, and consumer data exchanges. • Perform risk oversight tasks of vendor security compliance. • Help run internal, external and vendor related audits. • Conduct security analysis of deployed software. • Monitor for risks to the enterprise and to implemented controls. • Identify, maintain, and publish the requirements for the IT department to achieve compliance and privacy standards in SOC 2, HITRUST, FedRAMP, and other frameworks. • Work with the internal team in communicating related security notifications and IT controls within the organization while collaborating with teams and vendors on changes, remediations, and updates. • Experience with incident management Drive use cases to enable threat detection and hunting based on threat intelligence frameworks. • Experience with Agile and/or Kanban with emphasis on Scrum to drive continuous process improvement. • Perform Access Reviews.


