Bonterra Tech logo
Bonterra Tech

Bonterra Tech is a social good software startup offering technological support, services, and expertise to organizations and businesses that serve others, including more than 15,00

Information Security Compliance Analyst

Location

United States

Posted

9 days ago

Salary

$76K - $100K / year

Seniority

Mid Level

Professional Certificate

Job Description

Information Security Compliance Analyst

Bonterra Tech

Role Description The Bonterra Information Security Risk and Compliance department is looking to hire a Compliance Specialist to our team. If you enjoy problem solving, are enthusiastic working in a team format and want to thrive in the ever-changing risk & compliance field while learning new concepts and principles as part of your continuing education, look no further! - Perform as the primary in the executing our annual Service Organization Controls (SOC) reporting initiatives, which includes several Bonterra products. - Works closely with other members of the Information Security Risk team. - Works closely with control owners across the company and internal and external auditors to ensure requests are completed in a timely manner as part of the overall project management process. - Performs technical risk assessments of third party suppliers' security and privacy controls. - Maintains register of relevant suppliers/vendors, controls, and risks for ongoing vendor risk management activities. - Will be responsible for the playbook for reporting of high risk events that involve compliance, risk and information security. - Assists in maintaining our overall security awareness, role based security trainings and phishing simulation programs across the enterprise. - Assists in conducting user activity audits where required. Qualifications - 3+ years experience performing risk and compliance activities. - Project management experience. - A strong understanding of both SOC and ISO as there will be overlap. - Experience managing multiple priorities independently and in a team environment to achieve goals. - Excellent verbal and written communication skills. - Excellent organizational, planning and time management skills. - Excellent research and analytical skills. - Ability to exercise good judgement and tact in dealing with Bonterra senior management. - Proficient with technology and ability to learn our software systems, including GRC, ticketing and project management software and workflows. - Proven track record of proactively identifying needs and implementing solutions. - Information systems security professional certifications preferred (CRISC, CISA, CISSP, CISM, GSEC, GCFA, GCTI, CCSP, or other relevant Information Security certifications). Benefits - Comprehensive benefits package that supports your health, well-being and growth. - Compensation and benefits for this role apply to full-time employees in the United States and may vary based on local standards, laws and norms. - Pay is determined by location, skills, experience, and education, and is one part of Bonterra’s total rewards package, which may also include bonuses, incentives, equity, and a comprehensive benefits program. Equal Opportunity & Accommodations At Bonterra, we are proud to be an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We provide equal employment opportunities without regard to race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, veteran status, or any other characteristic protected by law. If you require a reasonable accommodation during the application process, please submit a request.

Related Job Pages

More Security Analyst Jobs

Title: Lead Analyst, Cyber Security Location: Macon United States Job Description: Our technology organization is transforming how we work at Smurfit Westrock. We align with our businesses to deliver innovative solutions that: - Address specific business challenges, integrate processes, and create great experiences - Connect our work to shared goals that propel Smurfit Westrock forward in the Digital Age - Imagine how technology can advance the way we work by using disruptive technology We are looking for forward thinking technologists that can accelerate our focus areas such as building stronger foundational technology capabilities, reducing complexity, employing digital transformation concepts, and leveraging disruptive technology. Location and/or Business/Division Details (if applicable) Lead, IT Identity & Access Management (IAM) Engineer (IGA) - Atlanta, GA (remote may be considered) The opportunity: This opportunity would allow you to apply your strong understanding of designing, configuring, implementing, and supporting Identity Governance & Administration (IGA) solutions and processes. As a Lead IT IAM Engineer (IGA) you will work directly with technology and business partners in a global organization to ensure the IAM services and technology are delivered in accordance with Cyber Security strategy. In this role, the Lead will be part of the Identity and Access Management within Cyber Security and will collaborate with many cross functional teams within and outside of Smurfit Westrock's IT Solutions including Infrastructure & Services, Productivity & Platforms, Core Engineering, Operations, Service Delivery, Human Resources IT teams to grow and mature IAM security program, while protecting Smurfit Westrock's identities and access protocols from the latest threat actors and threat vectors. You will be responsible for technical deployment, rollout, maintenance, and support of key IAM processes and security practices related to Identity Governance and Administration (IGA) and end-to-end identity lifecycle management systems (SailPoint Identity Security Cloud - ISC / IdentityNow or other IGA Solutions), implementing birthright access provisioning/de-provisioning, establishing access certifications/governance workflows, as well as developing and supporting Role Based Access Control (RBAC) frameworks and modern access management solutions, such as single sign-on, multi-factor authentication, proper authorization etc. The successful candidate will have excellent collaboration and communication skills. How you will impact Smurfit Westrock: - Provides technical support across IAM applications to define, implement and enhance current and new IAM software, hardware requirements, delivering and supporting IGA applications, solutions, and processes - Provide support with respect to implementation, and concurrent delivery of two or more Identity platforms (i.e., IGA and PAM) such as SailPoint, Saviynt, BeyondTrust, Okta, Ping Federate, Microsoft Azure AD - Assist with configuring, implementing, maintenance, and documentation of all layers of IAM applications and robust identity and access solutions including tools to support account creation, onboarding, offboarding, user provisioning, deprovisioning, authorization, authentication, single-sign, federated identities, multi-factor authentication, and privileged access management activities - Assist to modernize access control protocols, design from scratch, implement, and maintain role-based access controls (RBAC) and birthright provisioning/de-provisioning mechanisms to execute and maintain a strategy of "least privilege" - Conducts proper root cause analysis and make recommendations to improve IAM processes or prevent future occurrence of end user access issues - Assist in the analysis of user and permission data, and the development and documentation of test cases for applications on boarding, user access and other identified entitlements repositories that have been re-permissioned. What you need to succeed: - Bachelor's degree or a similar level of training in IT and information security - 8-10 years of IT experience focused on Identity Governance Administration (IGA) and other security practices. - 8-10 years working knowledge of two or more IGA solutions (SailPoint, Saviynt, One Identity), etc - 8+ years hands-on knowledge and experience with designing, configuring, implementing, and supporting IAM solutions such as SailPoint, Saviynt, BeyondTrust, Thycotic, CyberArk, Okta or Ping Federate or any IDAM tools - Minimum 8 years hands-on experience with Identity Life-cycle Management processes and Identity Governance related to onboarding and offboarding, good understanding of Active Directory, Single Sign On (SSO) and modern authentication and authorization standards and protocols (i.e., SAML, OpenID Connect, OAuth) - Solid understanding of IGA concepts and frameworks to resolve IAM complex issues in effective/creative ways - Hands-on technical ability to support (SailPoint Identity Security Cloud - ISC / IdentityNow) - Minimum 8 years' experience and know how in any combination of Cloud (AWS IAM), Network, Cyber - Some understanding of Domains, Trusts, AD replication (configuration and troubleshooting), and Group Policy Object (GPO) management and experience in completing Identity migrations post-merger/acquisition. - Experience with JavaScript, Python, Ruby, PowerShell, or other scripting languages - Strong experience with Java, BeanShell, XML, and SQL - Minimum 4 years working with Amazon Web Services (AWS) including EC2 and Lambda - Certifications a plus such as: CISSP, CISM, CRISC, CISA and other similar IAM related certifications. - Must have strong communications skills with the ability to interface with both executives and technical staff - Experience running risk management programs and IT architecture planning and implementation. - Travel up to 30%, although this may be higher when ramping up - Professional proficiency with the MS suite of products (Word, Excel, PPT, Visio, Project) - Self-directed, results-oriented and ability to work under tight deadlines in a fast-paced environment - Strong attention to detail, analytical, decision-making, effective document, and process review skills - Demonstrates strategic thinking in application of security technologies and interoperability What we offer: - Corporate culture based on loyalty, integrity, & respect. - Comprehensive training with numerous learning and development opportunities - An attractive salary reflecting skills, competencies, and potential. - A career with a global packaging company where Sustainability, Safety and Inclusion are business drivers and foundational elements of the daily work.

Georgia
UT Southwestern Medical Center logo

Senior Information Security Analyst

UT Southwestern Medical Center

With over 75 years of excellence in Dallas-Fort Worth, Texas, UT Southwestern is committed to excellence, innovation, teamwork, and compassion. As a world-renowned medical and research center, we strive to provide the best possible care, resources, and benefits for our valued employees. Ranked as the number 1 hospital in Dallas-Fort Worth according to U.S. News & World Report, we invest in you with opportunities for career growth and development to align with your future goals.

Security Analyst10 days ago
Full TimeRemoteTeam 5,001-10,000

Role Description We’re looking for an Information Security professional to support and enhance cybersecurity across a decentralized healthcare environment for UT Southwestern. This role protects the confidentiality, integrity, and availability of sensitive data, including patient information. Responsibilities include: - Implement and promote security best practices - Monitor security systems and identify threats - Perform risk assessments and address vulnerabilities - Ensure compliance with HIPAA and internal policies - Collaborate with teams across the organization to strengthen security posture Our ideal candidate has a strong cybersecurity background, ideally in healthcare, knowledge of risk management and regulatory requirements, and effective communication and collaboration skills. This position is 100% remote with occasional on-site meetings. Incumbent must reside in Texas. Qualifications - High School Diploma or equivalent - 3 years' experience in information security, cybersecurity operations, incident response, security engineering, or a related technical security discipline - Extensive demonstrated hands-on experience using security tools and technology, including vulnerability management, encryption, monitoring systems, and email gateway security solutions - Must possess one or more of the following, or obtain within one year of hiring: CompTIA Security+, CISSP, CISM, CEH, or GIAC - Other similar industry-recognized security-related certifications within 1 Year - Preferred: Bachelor's Degree in a computer science and technology or related field Requirements - Direct responses to security incidents to prevent further loss, obtain and preserve forensic evidence, and lead root cause analysis efforts - Maintain a database of security incidents and provide reports to leadership, university management, and external regulatory agencies - Assist technical support staff in identifying and implementing appropriate security safeguards - Oversee Active Directory protection alerts and remediation - Respond to email gateway alerts, manage quarantine folder reviews, and coordinate email gateway agent updates - Aggregate and analyze SIEM logs to detect and respond to security events - Provide security training and awareness programs for technical and non-technical users - Review quarterly reports to identify and address security concerns related to physical access control systems - Prepare technical briefings, reports, and slide presentations on security incidents, trends, and initiatives for leadership - Perform other duties as assigned Benefits - PPO medical plan, available day one at no cost for full-time employee-only coverage - 100% coverage for preventive healthcare - no copay - Paid Time Off, available day one - Retirement Programs through the Teacher Retirement System of Texas (TRS) - Paid Parental Leave Benefit - Wellness programs - Tuition Reimbursement - Public Service Loan Forgiveness (PSLF) Qualified Employer

United States
Job Closed
Mercor logo

Security Analyst

Mercor

Cincinnatus is an enterprise staffing company that partners with leading technology companies to source and employ highly skilled professionals for full-time and long-term contingent roles. Cincinnatus serves as the employer of record for these engagements, providing W-2 employment, payroll, benefits, and compliance, while placing employees directly within client teams to work on high-impact initiatives. Roles hired through Cincinnatus are not project-based or freelance engagements. They are structured, role-based positions that typically involve full-time or fixed-term commitments, close collaboration with a client's internal teams, and integration into standard enterprise workflows. Cincinnatus is a legal entity separate from Mercor. While opportunities may be discovered through Mercor's platform, employment, onboarding, payroll, and benefits for these roles are administered by Cincinnatus. Equal Employment Opportunity Cincinnatus is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or any other legally protected characteristic. Cincinnatus is committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans throughout the job application process.

Security Analyst10 days ago
Part TimeRemoteH1B No Sponsor

Role Description Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey. Position: Cybersecurity Experts Type: Contract Compensation: $70–$90/hour Location: Remote Duration: ~2 months Role Responsibilities - Analyze and review content for security vulnerabilities with a focus on pattern recognition and classification in an AI context. - Apply expertise in systems programming and security concepts to enhance AI model threat detection and reasoning. - Work independently and asynchronously with a team of experts to solve real-world problems. - Craft, solve, and review challenging problems with real-world applicability. - Collaborate to improve AI model performance and security assessment. Qualifications - 2+ years of experience in programming with low-level languages such as C, C++, or Java. - Familiarity with security vulnerability classification frameworks like OWASP or CVEs. - Understanding of core cybersecurity concepts, including web security and common attack vectors. - Strong attention to detail and pattern recognition skills. - Clear written and verbal communication in English. - Based in the U.S., Canada, UK, Australia, or New Zealand. - Ability to pass an enhanced background check. Requirements - Start Date: Mid-April; exact dates confirmed closer to the start date. - Interview Process: Short interview and questionnaire to assess domain expertise. - Paid for up to 1 hour of onboarding time, including screening and onboarding videos if hired. - Application Process (Takes 20–30 mins to complete): Upload resume, AI interview based on your resume, Submit form. Resources & Support - For details about the interview process and platform information, please check: Interview Process Details - For any help or support, reach out to: support@mercor.com - PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.

United States + 4 moreAll locations: United States | United Kingdom | Canada | Australia | New Zealand
$70 - $90 / hour
Fortrea logo

Senior Cybersecurity Analyst – SOC Lead

Fortrea

Fortrea is a contract research organization (CRO) that provides advanced laboratory-focused services that help change lives. On a mission to deliver “life-cha

Security Analyst10 days ago

• Lead sophisticated cyber forensic investigations • Spearhead the SOC's threat detection and incident response efforts • Work collaboratively with cybersecurity architecture and engineering teams • Contribute to the development of SOC, focusing on advanced forensic analysis • Assist in the identification and monitoring of operational metrics • Stay ahead of emerging cybersecurity threats and forensic methodologies

Poland