**Can be 100% remote in TX, NJ, NC, WV, AL, VA, MD, MO, DC, GA, or FL** Click here to learn about BRMi's culture. Click here to see BRMi’s Glassdoor reviews.
Technical Analyst
Location
United States
Posted
78 days ago
Salary
$80K - $110K / year
Seniority
Mid Level
Job Description
Technical Analyst
BRMi
Role Description The Secrets Management Technical Analyst is responsible for discovering, compiling, researching, analyzing, and documenting data, requirements, workflows, controls, and business processes within Enterprise Security Product and Services. This role serves as a subject matter expert and liaison between technical and business teams, supporting cybersecurity compliance and secure credential handling practices. The analyst will support Secrets Management operations, ensuring rapid remediation of exposed credentials identified through automated scanning tools. - Discover, review, validate, and analyze alerts generated by secret scanning platforms to identify insecurely stored or exposed secrets - Support Non-Human Identity (NHI) management, including governance, lifecycle oversight, and alignment of system and service accounts with enterprise security policies - Monitor and enforce secret rotation compliance, ensuring credentials are rotated according to policy and assisting teams in meeting regulatory and internal requirements - Coordinate with application teams, business owners, system owners, and engineering partners to remediate compromised credentials and enforce secure rotation workflows - Collaborate with security engineers to validate findings, confirm ownership, and assess the impact of policy or process changes - Track findings end to end, ensuring timely resolution and accurate attribution of ownership - Assist in improving scanning accuracy and optimizing discovery and remediation pipelines in partnership with engineering teams - Serve as a liaison between IAM and business partners to ensure cohesive remediation and secure credential usage practices - Prepare and deliver metrics and dashboards related to exposed secrets, mean time to detect and remediate, repeat findings, and overall security posture trends - Maintain procedural documentation and develop automation runbooks - Perform other duties as assigned Qualifications - Bachelor’s degree in Information Technology, Cybersecurity, or a related field, or an equivalent combination of education, training, and experience - Knowledge of IT policies, security procedures, and identity governance frameworks - Understanding of foundational security concepts such as authentication, authorization, and Zero Trust - Experience with secret scanning technologies, automated discovery tools, or credential hygiene workflows - Familiarity with IAM concepts, incident response processes, and secure access management within enterprise environments - Strong analytical, problem solving, and communication skills Requirements - Experience generating security metrics, supporting risk mitigation efforts, or assembling audit evidence - Exposure to Privileged Access Management tools such as CyberArk - Ability to translate technical findings into clear, actionable business recommendations - Process improvement mindset with a focus on security, quality, and operational efficiency - Ability to serve as a trusted advisor to development, infrastructure, and business teams - Experience working in multicloud environments such as AWS, OCI, or Azure Benefits - Comprehensive Medical, Dental, and Vision Insurance - Employer-Paid Life Insurance - Employer-Paid Short-Term and Long-Term Disability Insurance - 401(k) - Paid Time Off (PTO) that includes Vacation Leave, Sick Leave, and 11 Paid Holidays - Educational Assistance
Job Requirements
- Bachelor’s degree in Information Technology, Cybersecurity, or a related field, or an equivalent combination of education, training, and experience
- Knowledge of IT policies, security procedures, and identity governance frameworks
- Understanding of foundational security concepts such as authentication, authorization, and Zero Trust
- Experience with secret scanning technologies, automated discovery tools, or credential hygiene workflows
- Familiarity with IAM concepts, incident response processes, and secure access management within enterprise environments
- Strong analytical, problem solving, and communication skills
- Experience generating security metrics, supporting risk mitigation efforts, or assembling audit evidence
- Exposure to Privileged Access Management tools such as CyberArk
- Ability to translate technical findings into clear, actionable business recommendations
- Process improvement mindset with a focus on security, quality, and operational efficiency
- Ability to serve as a trusted advisor to development, infrastructure, and business teams
- Experience working in multicloud environments such as AWS, OCI, or Azure
Benefits
- Comprehensive Medical, Dental, and Vision Insurance
- Employer-Paid Life Insurance
- Employer-Paid Short-Term and Long-Term Disability Insurance
- 401(k)
- Paid Time Off (PTO) that includes Vacation Leave, Sick Leave, and 11 Paid Holidays
- Educational Assistance
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Mid-level Cybersecurity Analyst, Edge Protection, PKI
RPE🟠Somos a força por trás dos pagamentos que movem o varejo brasileiro.
• Manage, operate, and optimize edge security solutions (WAF, CDN, Anti-DDoS, Bot Management) on market-leading platforms. • Analyze network traffic and security logs to identify, classify, and respond to incidents such as denial-of-service (DDoS) attacks, exploitation attempts, and malicious bot activity. • Create, tune, and maintain WAF rules and security policies to protect web applications and APIs against known and emerging threats while minimizing false positives. • Manage the lifecycle of digital certificates (SSL/TLS) for edge applications and services, ensuring validity, security, and proper deployment. • Serve as the technical focal point in investigations of application-related security incidents, actively participating in incident response. • Collaborate with development teams to integrate security practices early in the software development lifecycle (DevSecOps), ensuring new applications and APIs are secure by design. • Work with infrastructure and network teams to ensure security architecture aligns with business needs and industry best practices. • Develop and maintain detailed technical documentation on configurations, policies, and security procedures. • Automate operational and security analysis tasks using scripting languages (e.g., Python, Shell). • Produce security reports and metrics for leadership that demonstrate control effectiveness and application risk posture.
Senior Information Security Analyst – Access Management
RPE🟠Somos a força por trás dos pagamentos que movem o varejo brasileiro.
• Work on identity and access management (IAM) processes, including creation, modification, revocation, and periodic review of access to systems and resources. • Administer the IAM solution and ensure RPE systems are properly integrated. • Automate manual tasks using available tools and scripts (shell scripting, Python, etc.). • Implement new security solutions and technologies related to access management. • Serve as an identity and access specialist supporting development and product projects as well as operational processes at RPE. • Prepare and maintain technical and procedural documentation (runbooks) for Access Management activities. • Foster collaboration with IT teams to ensure compliance and security across environments. • Support internal and external audits related to access management controls.
Analista de Segurança da Informação – Delinea
It4us Cyber SecurityGarantindo a Cyber Segurança de nossos amigos e clientes !
• Apoiar na administração e suporte da ferramenta **Delinea** • Controlar acessos de usuários a sistemas e ambientes críticos • Cadastrar, revisar e atualizar credenciais e permissões • Ajudar na criação de políticas de acesso e segurança • Monitorar acessos e apoiar na identificação de possíveis riscos • Trabalhar junto com times de TI e segurança no dia a dia
• Lead end-to-end RMF activities, including control implementation, artifact development, risk documentation, and POA&M management. • Guide ATO preparation, package development, and remediation planning efforts across project teams. • Evaluate authorization packages, identify compliance gaps, and drive resolution of risks and findings. • Ensure alignment with VA Handbook 6500, NIST SP 800-53, NIST SP 800-37, TIC 3.0, and federal cloud security standards. • Assess system security posture across networks, cloud environments, and applications to support secure solution design. • Perform vulnerability assessments using tools such as Nessus and Fortify, and track remediation and residual risk. • Develop RMF documentation including SSPs, Incident Response Plans, and Contingency Plans, and present findings to stakeholders. • Take on additional tasks and responsibilities as needed to support team objectives and ensure the success of the project.



