Job Closed
This listing is no longer active.
We propel every doer of good to their peak impact.
Information Security Compliance Analyst
Location
United States
Posted
155 days ago
Salary
$76K - $100K / year
Seniority
Senior
Job Description
Information Security Compliance Analyst
Bonterra
• Perform as the primary in the executing our annual Service Organization Controls (SOC) reporting initiatives, which includes several Bonterra products • Works closely with other members of the Information Security Risk team • Works closely with control owners across the company and internal and external auditors to ensure requests are completed in a timely manner as part of the overall project management process • Performs technical risk assessments of third party suppliers' security and privacy controls • Maintains register of relevant suppliers/vendors, controls, and risks for ongoing vendor risk management activities • Will be responsible the play book for reporting of high risk events that involve compliance, risk and information security • Assists in maintaining our overall security awareness, role based security trainings and phishing simulation programs across the enterprise • Assists in conducting user activity audits where required
Job Requirements
- 6+ years’ experience performing risk and compliance activities or open to less with a relevant degree
- Project management experience
- Experience managing multiple priorities independently and in a team environment to achieve goals
- Excellent organizational, planning and time management skills
- Excellent research and analytical skills
- Excellent verbal and written communication skills
- Ability to exercise good judgement and tact in dealing with Bonterra senior management
- Proficient with technology and ability to learn our software systems, including GRC, ticketing and project management software and workflows
- Proven track record of proactively identifying needs and implementing solutions
- Information systems security professional certifications preferred (CRISC, CISA, CISSP, CISM, GSEC, GCFA, GCTI, CCSP, or other relevant Information Security certifications)
Benefits
- Comprehensive benefits package that supports your health, well-being and growth
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Access Control Specialist
USAP - US Anesthesia PartnersFounded in 2012 to help anesthesiologists create positive patient outcomes, USAP - U.S. Anesthesia Partners serves as a strategic partner to high-quality groups
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description US Anesthesia Partners is seeking an Access Control Specialist who is responsible for managing user access across enterprise systems, ensuring compliance with internal security policies and external regulatory requirements. This role plays a critical part in safeguarding sensitive data by overseeing provisioning, deprovisioning, and access reviews, while maintaining detailed documentation for audit readiness. Qualifications - High school diploma. - Minimum 3 years of experience with access reviews, audit preparation, and compliance reporting. - Strong understanding of identity lifecycle management and access control best practices. - Ability to manage and protect sensitive information with discretion and accuracy. - Strong organizational and documentation skills including high attention to detail. - Proficient in using Excel, Microsoft Entra ID and access tracking tools. - Excellent verbal and written communication skills. - Proficient in managing and navigating insurance/payer portals for administrative tasks. - Identity & Access Management (IAM): Microsoft Entra ID, Active Directory. - Ticketing Systems: ServiceNow, FreshService. - Productivity Tools: Microsoft Excel, Power BI, SharePoint, SmartSheet. Requirements - Processes user access requests, including provisioning, deprovisioning, and modifications, based on control policies and employee status. - Identifies and resolves access issues, ensuring alignment with security policies and regulatory standards. - Monitors and responds to Workday notifications regarding employee terminations, transfers, and role changes; promptly revokes or adjusts access as needed. - Conducts regular access reviews to validate appropriate user access and remove outdated access. - Collaborates with HR, IT, and department leadership to support onboarding, offboarding, and internal transfers. - Maintains detailed documentation to ensure all changes are accurately recorded and auditable. - Participates in internal and external audits by providing access control evidence and responding to inquiries. - Supports automation initiatives related to access provisioning and deprovisioning using tools like Power Automate or ServiceNow workflows. Benefits - Occasional Standing. - Occasional Walking. - Frequent Sitting. - Frequent hand, finger movement. - Use office equipment (in office or remote). - Communicate verbally and in writing.
Lead Security Analyst, Cloud & Endpoint Incident Response
HubSpotThe easy-to-use CRM to scale your business.
• Track emerging threats and assess relevance to AWS environment • Triage external and internal inputs and drive validation and investigation • Translate threat intelligence into actions: containment guidance and prioritized remediation • Lead and execute high-severity security incidents across AWS and endpoints • Drive incidents from initial signal through containment and recovery • Reconstruct attacker activity and produce clear incident documentation • Investigate AWS incidents and lead investigations involving common AWS compromise patterns • Improve detection coverage and partner with detection engineering • Build and maintain investigation and response automation using SOAR tools
Senior Security Services Advisor
SentinelThe Sentinel is a news organization serving the Cumberland County area of Central Pennsylvania, and it is based in Carlisle, Pennsylvania. With a print edition, website, and profil
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description As a Sr. Security Services Advisor, you will be responsible for providing premium consulting services focused in the areas of cyber security, risk and business continuity to our clients. Your responsibilities include: - Providing assessment services, consulting projects, and ongoing executive consulting engagements. - Coordinating consulting engagements under the lead of dedicated project management teams. - Coordinating technical resources performing assessment work and consolidating technical assessment data into business outcome-driven consulting deliverables. - Acting as the client’s trusted advisor with high expectations for professionalism, excellence in communications, and presentation capabilities. - Interacting with a range of IT and business resources, including C-level executives and customer boards. This is a national role with a primary location and moderate travel expectations. This position can work remotely but will require occasional support onsite at our Downers Grove, IL headquarters. Qualifications - 10+ years of experience in a similar role. - CMMC experience and CyberAB CMMC Certified Professional Certification highly required. - Ability to consult organizations on cyber security risk and technologies, governance, policy standards, and alignment with maturity to industry standard models. - Experience performing and/or managing security assessments in regulated organizations. - Experience managing, interpreting, and remediating findings from Pen testing. - Ability to adapt to various customer environments. - Experience guiding organizations to achieve and maintain compliance attestations such as SOC II, PCI, HITRUST, and other relevant certifications. - Experience with NIST Cyber Security Framework is required. - Experience building cybersecurity strategies for enterprise organizations. - Experience with Center for Internet Security (CIS) benchmarks is highly desirable. - Ability to write organization security and governance standards. - Experience delivering risk assessments using NIST SP 800-30 or ISO 27005. - Experience participating in and/or performing cyber incident response testing and tabletop exercises desirable. - Bachelor’s Degree or higher is preferred. - Process-oriented with excellent people skills. - Ability to communicate both written and orally with various members of an organization from Engineers to Executive teams. - Ability to consult customers on incident response, disaster recovery, and document processes. - Must have a car for travel between locations and transportation of equipment. - A valid driver’s license and proof of vehicle insurance will be required. - Legally authorized to work in the US without sponsorship. - Must demonstrate a “can-do” attitude. - Focus on candidates that display the “ACE” factor – Attitude, Compassion, and Enthusiasm. Requirements - Compensation: $200,000-$220,000. Benefits - Energetic work environment with many corporate culture amenities. - Competitive salary and rich benefit plan including: - Medical, Dental, Vision. - 401K, 529. - Life Insurance. - Income Protection Short and Long-Term Disability. - Medical and Child/Elder Care. - Flexible Spending Account Plans. - Family Planning Benefits. - Financial Education. - Identity Theft Protection and Assistance. - Legal Services. - Employee Assistance Program. - Two weeks’ vacation and additional paid time-off for Personal and Sick. - Certification and hands-on training. - Employee discount for product services and entertainment. Company Description Sentinel Technologies, Inc. has been rated a top workplace every year since 2012! Sentinel delivers solutions that can efficiently address a range of IT needs – from security, to communications, to systems & networks, to software applications, to cloud and managed services; all of which include our staffing solutions for our clients. Since 1982, Sentinel has grown from providing technology maintenance services to our current standing as one of the leading IT services and solutions providers in the US. We have aligned with many of today’s global technology leaders including Cisco, Dell, VMware, and Microsoft. Sentinel services customers both nationally and internationally with primary support operating centers in: - Downers Grove (HQ) - Chicago - Springfield, IL - Phoenix, AZ - Lansing and Grand Rapids, MI - Milwaukee, WI - Denver, CO If you are MOTIVATED… you can make IT happen at Sentinel. Our commitment to our employees is to create a work environment that encourages creativity, an entrepreneurial spirit, fosters growth through certification and hands-on training, and values a team-oriented culture with rewards based on impact!
• Monitor, investigate, and respond to security alerts and incidents across systems, networks, and cloud environments. • Perform regular vulnerability assessments, patch verification, and risk remediation tracking. • Support security awareness programs and ensure employees adhere to company security policies, procedures and standards. • Assist in managing endpoint security tools (EDR, DLP, MDM, etc.) and identity/access management systems. • Collaborate with IT, DevOps, and engineering teams to implement secure configurations, code reviews, and cloud security best practices. • Conduct periodic access reviews and support audit and compliance efforts (SOC 2, ISO 27001, etc.). • Document incident response actions and recommend process improvements. • Contribute to risk assessments and control testing for new vendors, applications, and systems. • Stay current on emerging threats, vulnerabilities, and regulatory requirements impacting the business. • Demonstrate a business-first mindset.



