Job Closed

This listing is no longer active.

Bonterra logo
Bonterra

We propel every doer of good to their peak impact.

Information Security Compliance Analyst

Security AnalystSecurity AnalystOtherRemoteSeniorTeam 1,001-5,000H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

155 days ago

Salary

$76K - $100K / year

Seniority

Senior

Bachelor Degree6 yrs expEnglish

Job Description

Information Security Compliance Analyst

Bonterra

• Perform as the primary in the executing our annual Service Organization Controls (SOC) reporting initiatives, which includes several Bonterra products • Works closely with other members of the Information Security Risk team • Works closely with control owners across the company and internal and external auditors to ensure requests are completed in a timely manner as part of the overall project management process • Performs technical risk assessments of third party suppliers' security and privacy controls • Maintains register of relevant suppliers/vendors, controls, and risks for ongoing vendor risk management activities • Will be responsible the play book for reporting of high risk events that involve compliance, risk and information security • Assists in maintaining our overall security awareness, role based security trainings and phishing simulation programs across the enterprise • Assists in conducting user activity audits where required

Job Requirements

  • 6+ years’ experience performing risk and compliance activities or open to less with a relevant degree
  • Project management experience
  • Experience managing multiple priorities independently and in a team environment to achieve goals
  • Excellent organizational, planning and time management skills
  • Excellent research and analytical skills
  • Excellent verbal and written communication skills
  • Ability to exercise good judgement and tact in dealing with Bonterra senior management
  • Proficient with technology and ability to learn our software systems, including GRC, ticketing and project management software and workflows
  • Proven track record of proactively identifying needs and implementing solutions
  • Information systems security professional certifications preferred (CRISC, CISA, CISSP, CISM, GSEC, GCFA, GCTI, CCSP, or other relevant Information Security certifications)

Benefits

  • Comprehensive benefits package that supports your health, well-being and growth

Related Job Pages

More Security Analyst Jobs

USAP - US Anesthesia Partners logo

Access Control Specialist

USAP - US Anesthesia Partners

Founded in 2012 to help anesthesiologists create positive patient outcomes, USAP - U.S. Anesthesia Partners serves as a strategic partner to high-quality groups

Security Analyst156 days ago

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description US Anesthesia Partners is seeking an Access Control Specialist who is responsible for managing user access across enterprise systems, ensuring compliance with internal security policies and external regulatory requirements. This role plays a critical part in safeguarding sensitive data by overseeing provisioning, deprovisioning, and access reviews, while maintaining detailed documentation for audit readiness. Qualifications - High school diploma. - Minimum 3 years of experience with access reviews, audit preparation, and compliance reporting. - Strong understanding of identity lifecycle management and access control best practices. - Ability to manage and protect sensitive information with discretion and accuracy. - Strong organizational and documentation skills including high attention to detail. - Proficient in using Excel, Microsoft Entra ID and access tracking tools. - Excellent verbal and written communication skills. - Proficient in managing and navigating insurance/payer portals for administrative tasks. - Identity & Access Management (IAM): Microsoft Entra ID, Active Directory. - Ticketing Systems: ServiceNow, FreshService. - Productivity Tools: Microsoft Excel, Power BI, SharePoint, SmartSheet. Requirements - Processes user access requests, including provisioning, deprovisioning, and modifications, based on control policies and employee status. - Identifies and resolves access issues, ensuring alignment with security policies and regulatory standards. - Monitors and responds to Workday notifications regarding employee terminations, transfers, and role changes; promptly revokes or adjusts access as needed. - Conducts regular access reviews to validate appropriate user access and remove outdated access. - Collaborates with HR, IT, and department leadership to support onboarding, offboarding, and internal transfers. - Maintains detailed documentation to ensure all changes are accurately recorded and auditable. - Participates in internal and external audits by providing access control evidence and responding to inquiries. - Supports automation initiatives related to access provisioning and deprovisioning using tools like Power Automate or ServiceNow workflows. Benefits - Occasional Standing. - Occasional Walking. - Frequent Sitting. - Frequent hand, finger movement. - Use office equipment (in office or remote). - Communicate verbally and in writing.

United States
Job Closed
HubSpot logo

Lead Security Analyst, Cloud & Endpoint Incident Response

HubSpot

The easy-to-use CRM to scale your business.

Security Analyst156 days ago
OtherRemoteTeam 1,001-5,000Since 2006H1B Sponsor

• Track emerging threats and assess relevance to AWS environment • Triage external and internal inputs and drive validation and investigation • Translate threat intelligence into actions: containment guidance and prioritized remediation • Lead and execute high-severity security incidents across AWS and endpoints • Drive incidents from initial signal through containment and recovery • Reconstruct attacker activity and produce clear incident documentation • Investigate AWS incidents and lead investigations involving common AWS compromise patterns • Improve detection coverage and partner with detection engineering • Build and maintain investigation and response automation using SOAR tools

United States
$130.8K - $209.3K / year
Job Closed

Senior Security Services Advisor

Sentinel

The Sentinel is a news organization serving the Cumberland County area of Central Pennsylvania, and it is based in Carlisle, Pennsylvania. With a print edition, website, and profil

Security Analyst157 days ago

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description As a Sr. Security Services Advisor, you will be responsible for providing premium consulting services focused in the areas of cyber security, risk and business continuity to our clients. Your responsibilities include: - Providing assessment services, consulting projects, and ongoing executive consulting engagements. - Coordinating consulting engagements under the lead of dedicated project management teams. - Coordinating technical resources performing assessment work and consolidating technical assessment data into business outcome-driven consulting deliverables. - Acting as the client’s trusted advisor with high expectations for professionalism, excellence in communications, and presentation capabilities. - Interacting with a range of IT and business resources, including C-level executives and customer boards. This is a national role with a primary location and moderate travel expectations. This position can work remotely but will require occasional support onsite at our Downers Grove, IL headquarters. Qualifications - 10+ years of experience in a similar role. - CMMC experience and CyberAB CMMC Certified Professional Certification highly required. - Ability to consult organizations on cyber security risk and technologies, governance, policy standards, and alignment with maturity to industry standard models. - Experience performing and/or managing security assessments in regulated organizations. - Experience managing, interpreting, and remediating findings from Pen testing. - Ability to adapt to various customer environments. - Experience guiding organizations to achieve and maintain compliance attestations such as SOC II, PCI, HITRUST, and other relevant certifications. - Experience with NIST Cyber Security Framework is required. - Experience building cybersecurity strategies for enterprise organizations. - Experience with Center for Internet Security (CIS) benchmarks is highly desirable. - Ability to write organization security and governance standards. - Experience delivering risk assessments using NIST SP 800-30 or ISO 27005. - Experience participating in and/or performing cyber incident response testing and tabletop exercises desirable. - Bachelor’s Degree or higher is preferred. - Process-oriented with excellent people skills. - Ability to communicate both written and orally with various members of an organization from Engineers to Executive teams. - Ability to consult customers on incident response, disaster recovery, and document processes. - Must have a car for travel between locations and transportation of equipment. - A valid driver’s license and proof of vehicle insurance will be required. - Legally authorized to work in the US without sponsorship. - Must demonstrate a “can-do” attitude. - Focus on candidates that display the “ACE” factor – Attitude, Compassion, and Enthusiasm. Requirements - Compensation: $200,000-$220,000. Benefits - Energetic work environment with many corporate culture amenities. - Competitive salary and rich benefit plan including: - Medical, Dental, Vision. - 401K, 529. - Life Insurance. - Income Protection Short and Long-Term Disability. - Medical and Child/Elder Care. - Flexible Spending Account Plans. - Family Planning Benefits. - Financial Education. - Identity Theft Protection and Assistance. - Legal Services. - Employee Assistance Program. - Two weeks’ vacation and additional paid time-off for Personal and Sick. - Certification and hands-on training. - Employee discount for product services and entertainment. Company Description Sentinel Technologies, Inc. has been rated a top workplace every year since 2012! Sentinel delivers solutions that can efficiently address a range of IT needs – from security, to communications, to systems & networks, to software applications, to cloud and managed services; all of which include our staffing solutions for our clients. Since 1982, Sentinel has grown from providing technology maintenance services to our current standing as one of the leading IT services and solutions providers in the US. We have aligned with many of today’s global technology leaders including Cisco, Dell, VMware, and Microsoft. Sentinel services customers both nationally and internationally with primary support operating centers in: - Downers Grove (HQ) - Chicago - Springfield, IL - Phoenix, AZ - Lansing and Grand Rapids, MI - Milwaukee, WI - Denver, CO If you are MOTIVATED… you can make IT happen at Sentinel. Our commitment to our employees is to create a work environment that encourages creativity, an entrepreneurial spirit, fosters growth through certification and hands-on training, and values a team-oriented culture with rewards based on impact!

United States
$200K - $220K / year
Job Closed
Xpansiv logo

Information Security Analyst

Xpansiv

Infrastructure for an Evolving World

Security Analyst161 days ago
OtherRemoteTeam 201-500H1B Sponsor

• Monitor, investigate, and respond to security alerts and incidents across systems, networks, and cloud environments. • Perform regular vulnerability assessments, patch verification, and risk remediation tracking. • Support security awareness programs and ensure employees adhere to company security policies, procedures and standards. • Assist in managing endpoint security tools (EDR, DLP, MDM, etc.) and identity/access management systems. • Collaborate with IT, DevOps, and engineering teams to implement secure configurations, code reviews, and cloud security best practices. • Conduct periodic access reviews and support audit and compliance efforts (SOC 2, ISO 27001, etc.). • Document incident response actions and recommend process improvements. • Contribute to risk assessments and control testing for new vendors, applications, and systems. • Stay current on emerging threats, vulnerabilities, and regulatory requirements impacting the business. • Demonstrate a business-first mindset.

United States
$80K - $95K / year