Creatio logo
Creatio

Creatio is a global vendor of a no-code platform to automate workflows and CRM with a maximum degree of freedom.

Security Analyst

Security AnalystSecurity AnalystFull TimeRemoteJuniorTeam 501-1,000Since 2014H1B No SponsorCompany SiteLinkedIn

Location

Poland

Posted

5 days ago

Salary

0

Seniority

Junior

Bachelor Degree1 yr expEnglishCloudCyber Security

Job Description

Security Analyst

Creatio

• Monitor and analyze security events using SIEM reports and other security tools. • Support incident response activities, including triage, investigation, evidence collection, and root cause analysis. • Perform access management activities, including periodic access reviews and entitlement validation. • Support vulnerability management by tracking findings, remediation progress, and risk acceptance. • Prepare and maintain security metrics, KPIs, reports, risk registers, and remediation logs. • Support audit readiness and evidence collection for ISO 27001/17/18, SOC 2, GDPR, HIPAA, and other relevant frameworks. • Assist with maintaining security policies, procedures, standards, and control documentation. • Support third-party vendor security reviews and track vendor risk documentation. • Collaborate with IT, engineering, compliance, and business teams on security-related topics.

Job Requirements

  • 1+ years of experience in information security, cybersecurity, IT, compliance, audit, risk management, or a related field.
  • Hands-on experience in a Security Analyst or similar cybersecurity role.
  • Understanding of IAM, access reviews, vulnerability management, and incident response.
  • Exposure to cloud security, endpoint security, cloud IAM models, and networking fundamentals.
  • Familiarity with security and compliance frameworks such as SOC 2, ISO 27001, NIST CSF, CIS Controls, or GDPR.
  • Experience working with security documentation, policies, procedures, audit evidence, and compliance reviews.
  • Ability to analyze security data, trends, and metrics and communicate findings clearly.
  • Strong analytical, organizational, and problem-solving skills with high attention to detail.
  • Experience with tools such as SharePoint, Microsoft 365, ticketing tools, document repositories, or collaboration platforms.

Benefits

  • Growth & Development: Clear career paths, mentorship opportunities, and access to continuous learning to help you reach your full potential.
  • Flexibility & Well-Being: We provide flexible work arrangements and initiatives that empower you to manage your schedule effectively, stay productive, and thrive both personally and professionally.
  • Recognition & Impact: A culture that celebrates achievements, values your ideas, and empowers you to make real contributions from day one.
  • Innovative Culture: Be part of a company that embraces new ideas, modern technologies, and bold thinking to stay ahead of the curve.
  • Benefits & Rewards Package: We provide competitive compensation and benefits designed to support you and your family. Our rewards approach goes beyond salary, recognizing your contributions and commitment. The exact package may vary depending on your country of residence and employment type.

Related Job Pages

More Security Analyst Jobs

NVISO logo

SOC Analyst

NVISO

We are a young team of cyber security professionals who decided to do things differently. With innovation rooted in our foundations, we offer services that are up against the modern adversary and that help you Prevent, Detect & Respond to cyber attacks.

Role Description As a SOC analyst in Greece (Remote/Athens) in evening shift, your daily activities will include but are not limited to: - Analyze security alerts and report on threats and incidents across various platforms and environments. - Monitor and analyze emerging threats, vulnerabilities and exploits. - Triage, assess, and analyze security incidents related to e.g. phishing and malware. - Participate in incident management calls and coordinate response, triage, recovery, and reporting of incidents. - Participate in security process improvements. - Assist with rule tuning, filter-outs and operational improvements on the existing service offering. Qualifications - You bring experience working in one or more of the following areas: Email Security, Network Security, Intrusion Detection Systems, Threat Intelligence, Threat Detection. - You understand networking and core internet protocols (TCP/IP, HTTP, SSL) and have experience in analyzing malicious network traffic. - You have hands-on experience with the large-scale analysis of log data using SIEM and/or SOAR products and tools, as well as a basic understanding of security automation (SOAR) principles. - You possess excellent communication skills and proven experience in working with multiple stakeholders such as engineering/operations teams, internal business units, external incident response teams and clients throughout the incident lifecycle. - You are fluent in English. - You are eligible for a NATO clearance. Requirements - Experience working in a Security Operations Center. - Experience analyzing large data sets for threat hunting. - Knowledge of security frameworks, e.g. the MITRE ATT&CK. - Experience with analyzing network traffic, endpoint indicators, IOCs. - Basic understanding of cloud infrastructure and cloud identities. Benefits - A training budget of 10.000€ and 10 days every 2 years. - Working and learning from the best people in the European cyber security industry. - An entrepreneurial and agile company, where you will be stimulated and supported in driving new initiatives. - Our commitment to coach and counsel you and help you grow; each employee receives a personal coach within the team. - Home office possibilities (+working abroad options). - Monthly Benefits. - Statutory leave plus 5 additional leave days by NVISO. Company Description We are a young team of cyber security professionals who decided to do things differently. With innovation rooted in our foundations, we offer services that are up against the modern adversary and that help you Prevent, Detect & Respond to cyber attacks.

Greece
Slalom logo

Cyber Security Risk Management

Slalom

Slalom is a management consulting firm focused on strategy, technology, and business transformation. Headquartered in Seattle, Washington, the company has grown to employ over 6,50

Title: Cyber Security Risk Management Location: Remote, Remote Project Based Full-time consulting contract Job Description: Cyber Security Risk Management About Us Slalom is a purpose-led, global business and technology consulting company. From strategy to implementation, our approach is fiercely human. In six+ countries and 43+ markets, we deeply understand our customers-and their customers-to deliver practical, end-to-end solutions that drive meaningful impact. Backed by close partnerships with over 400 leading technology providers, our 10,000+ strong team helps people and organizations dream bigger, move faster, and build better tomorrows for all. We're honored to be consistently recognized as a great place to work, including being one of Fortune's 100 Best Companies to Work For seven years running. Learn more at Slalom.com. Key Responsibilities: - Lead and coordinate the implementation of security control requirements and related processes based on Federal Reserve information security framework and standards This includes executing security activities based on NIST frameworks and related assessment activities for FedNow information systems - Review and analyze inherited service provider documentation, establish control ownership, and identity control gaps and associated risk - In coordination with various stakeholders, develop records for system security documentation including system security plans and associated security and operational processes - Identify control gaps and complete risk assessment for control deficiencies Design plans of actions to address control gaps or risk acceptance Develop, obtain, and maintain approval documentation - Coordinate security reviews and collaborate with security, assessment teams, and business and technical stakeholders to complete the reviews on schedule Review assessment results, identify and document residual risks and action plans - Gather and present authorization packages including analysis and information on security posture and plans for continuous control assurance Coordinate and obtain appropriate authorizations and sign-offs - Develop and manage a portfolio of continuous assurance and compliance activities including ongoing control monitoring and data-driven reporting on FedNow users, process, and technology to guide risk management decisions Qualifications: - Technical experience with GRC engineering activities is strongly preferred - Possess knowledge and experience with AI capabilities - Knowledge and experience normally acquired through, or equivalent to, the completion of a Bachelor's degree and a minimum of 6-10 years of relevant job experience - Possess knowledge of risk management principles and industry-standard security risk management frameworks (eg NIST, ISO, FedRAMP) - Experience in applying security frameworks and risk management activities in a cloud environment is strongly preferred - Possess knowledge about or have experience in supporting payments applications or platforms - Must possess or be able to obtain appropriate industry certifications such as the CISSP, CRISC, and/or CCSP Must possess or be able to obtain FRS security risk management certification - Must possess or be able to obtain appropriate industry relevant cloud certifications - Proven ability to prioritize, reprioritize and demonstrates appropriate agility to manage competing and sometimes conflicting priorities - Strong attention to detail and work ownership and accountability - Strong oral and written communication skills - Proven project management skills and the ability to lead and direct technical and business teams without formal authority - Ability to flexibly adapt to a rapidly changing environment and generate effective and innovative solutions to address change - A self-starter who is willing to explore, learn new areas and concepts, and promote and support innovation Compensation and Benefits Slalom prides itself on helping team members thrive in their work and life. As a result, Slalom is proud to invest in benefits that include meaningful time off and paid holidays, 401(k) with a match, a range of choices for highly subsidized health, dental, & vision coverage, adoption and fertility assistance, and short/long-term disability. We also offer yearly $350 reimbursement account for any well-being-related expenses. Slalom is committed to fair and equitable compensation practices. For this position, the base salary pay range is $80/hr to $95/hr. Actual compensation will depend upon an individual's skills, experience, qualifications, location, and other relevant factors. The salary pay range is subject to change and may be modified at any time. EEO and Accommodations Slalom is an equal opportunity employer and is committed to inclusion, diversity, and equity in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veterans' status, or any other characteristic protected by federal, state, or local laws. Slalom will also consider qualified applications with criminal histories, consistent with legal requirements.

Worldwide
$80 - $95 / hour
ProMedica logo

IT Security Analyst II

ProMedica

ProMedica is a mission-driven, not-for-profit health care organization headquartered in Toledo, Ohio. It serves communities across nine states and provides a range of services, including acute and ambulatory care, a dental plan, and academic business lines. ProMedica owns and operates 10 hospitals and has an affiliated interest in one additional hospital. The organization employs over 1,300 health care providers through ProMedica Physicians and has more than 2,300 physicians and advanced practice providers with privileges. Committed to its mission of improving health and well-being, ProMedica has received national recognition for its clinical excellence and its initiatives to address social determinants of health. For more information about ProMedica, please visit promedica.org/aboutus .

Full TimeRemoteTeam 10,001+Since 1986H1B Sponsor

Role Description As the IT Security Analyst II, you will assess threats to ProMedica’s information technology resources and data while developing policies, processes, and procedures related to a comprehensive security program. - Ensure compliance with IT security policies. - Review security logs for suspicious activities. - Investigate security incidents and upgrades. - Perform risk assessments. - Available for rotational, on-call 24/7 support. The above summary is intended to describe the general nature and level of work performed in this role. It should not be considered exhaustive. Qualifications - Bachelor’s degree or equivalent work experience. - 4 years overall IT experience with at least 3 years in a security role. Requirements - Master’s Degree (Preferred). - CISSP, CISA, CISM, CHPS (Preferred). - Experience with Splunk, Defender for Endpoints, CrowdStrike, Windows 11, PowerShell, Active Directory (Preferred). Benefits - Competitive benefits package effective day one of employment. - Medical, dental, and vision coverage. - Company paid life insurance. - Paid time off. - 401k retirement plan. - Employee assistance program. - Voluntary coverage options and employee discounts.

United States
Southern New Hampshire University logo

Information Security Analyst II

Southern New Hampshire University

Southern New Hampshire University is a team of innovators. World changers. Individuals who believe in progress with purpose. Since 1932, our people-centered strategy has defined us — and helped us grow a team that now serves over 180,000 learners worldwide. Our mission to transform lives is made possible by talented people who bring diverse industry experience, backgrounds and skills to the university. And today, we're ready to expand our reach. All we need is you. At SNHU, you'll have the option to work remotely in the following states: Alabama, Arizona, Arkansas, Delaware, Florida, Georgia, Hawaii, Idaho, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Michigan, Mississippi, Missouri, Nebraska, New Hampshire, New Mexico, North Carolina, North Dakota, Ohio, Oklahoma, South Carolina, South Dakota, Tennessee, Texas, Utah, Vermont, Virginia, West Virginia, Wisconsin and Wyoming.

Full TimeRemoteTeam 51-200

Role Description The Information Security Analyst II will report to the Director of Information Security Operations. You will be a senior member of the Security Operations Center (SOC) team and is responsible for monitoring a large, complex enterprise technology ecosystem, detecting, analyzing, and investigating information security events within that ecosystem, and responding to information security incidents to ensure the protection of SNHU's mission critical technology resources and institutional information. The SOC team is responsible for analyzing events from multiple sources from across all university technology resources including networks, applications, and other assets. The critical duties and responsibilities of the SOC team must continue to be performed during crisis situations and contingency operations, which may necessitate extended hours of work, and/or require work during non-business hours. You will work 100% remotely from any of our approved states. What You'll Do: - Be an initial triage point for all security-related tickets that come into the team's multiple queues (including triage, containment, and remediation). - Understand the basic incident response lifecycle and the analytical mindset needed when it comes to triage and investigations. - Excel at documentation and detailed notetaking, including SOP writing, incident reporting, email and instant messaging etiquette, and most importantly, documenting incident actions. - Collect and analyze log data from complex, virtualized, multi-site computing environments and SNHU's technology ecosystem. - Conduct real-time monitoring of security events from multiple sources and use analytical and problem-solving skills to identify, triage, analyze, investigate, and escalate information security events and alerts. - Analyze digital evidence to identify indicators of compromise, adversary activity, root cause, incident timelines, and attack vector(s). - Perform incident response activities like endpoint isolation, malware remediation, forensic analysis, malware analysis, community member interviews, and network traffic analysis. - Perform investigation and escalation for complex or high severity security threats or incidents. - Coordinate information security incident response according to SNHU's Information Security Incident Response Plan. - Communicate with partners, in a non-technical manner, at all organizational levels as part of incident response and remediation activities. - Design and implement or monitor information security incident remediation plans. - Design, configure, deploy, and manage security tools (e.g. Splunk, Halcyon, Microsoft Defender, Tenable). - Design, deploy, and manage detections and alerts for specific or common threat conditions. - Design and implement standard operational processes for handling common incident types. - Maintain automation scripts and other tools to enhance security operations effectiveness. - Familiarity with enterprise security tools like Splunk, Tenable, Proofpoint tools, Microsoft Defender components, Office 365 tools, PowerShell, and multiple network tools. - Demonstrate a deep source of ethics, integrity, and confidentiality. - Can remain calm and function at the highest level during a crisis. - Remain up to date on latest threat intelligence. - Develop strategies and solutions that improve or mitigate the risks associated with these threats. - Work cross-functionally across ITS and all SNHU departments to provide support, guidance, and technical implementations to include triage, containment, and remediation when applicable. - Provide customer support according to SNHU's Core Values and understand how and when to escalate potential issues. - Help with risk management, vulnerability management, security assessment, auditing, and security authorization projects, as directed by the university's Information Security Management team. - Provide coaching/mentoring to junior analysts. - Other duties and responsibilities as assigned. Qualifications - 5+ years of experience in information technology. - 2+ years working in a security operations center (SOC), a cybersecurity operations center or on a cybersecurity incident response team. - High School Diploma or equivalent (GED). - Experience collecting, organizing, and analyzing security data from enterprise monitoring tools, including SIEM, IPS, NAC, vulnerability scanners, Windows/Linux system logs, network scanners, log aggregation platforms, and EDR solutions. - Experience with vulnerability management and penetration testing concepts and activities. - Knowledge of MITRE ATT&CK framework. - Professional Certification(s): ISC2 CISSP Certification, Microsoft Azure, Cisco, CompTIA, Security+, GSEC, or other relevant industry certification. Requirements - Office Hours: Monday through Friday 8:00am – 4:30pm. - Professional office environment. Sedentary work: Requires remaining in a stationary position, often standing or sitting for prolonged periods. Benefits - High-quality, low-deductible medical insurance. - Low to no-cost dental and vision plans. - 5 weeks of paid time off (plus almost a dozen paid holidays). - Employer-funded retirement. - Free tuition program. - Parental leave. - Mental health and wellbeing resources.

United States
$94.1K - $150.6K / year