Cisive is an employee background screening service designed to help organizations "hire with confidence." The company provides compliance-focused workforce scre
Information Security Analyst
Location
Maryland
Posted
16 days ago
Salary
0
Seniority
Senior
Job Description
Information Security Analyst
Cisive
• Monitor, tune, and triage alerts across the SIEM platform, escalating confirmed incidents per established runbooks • Manage the vulnerability management lifecycle— including scanning, prioritization, remediation tracking, and executive reporting • Support endpoint security, email security, and network monitoring tools; identify gaps and recommend configuration improvements • Conduct periodic threat hunting activities and contribute to the development of detection rules and playbooks • Participate in incident response activities including containment, eradication, and post-incident reviews • Support ongoing SOC 2 Type II compliance efforts, including evidence collection, control testing, and coordination with external auditors • Assist with NIST CSF assessments — mapping current controls to framework functions and identifying gaps for remediation • Maintain and update security policies, standards, and procedures in collaboration with senior team members • Conduct periodic security risk assessments and contribute findings to the organization risk register • Track remediation efforts for identified risks and control deficiencies through to closure • Partner with IT, Engineering, and business stakeholders to embed security best practices into day-to-day operations • Assist in security awareness initiatives and provide guidance to staff on security topics • Prepare clear, concise reporting on security metrics, vulnerability status, and compliance posture for management
Job Requirements
- 3–5 years of experience in an information security role with exposure to both technical operations and compliance functions
- Hands-on experience with SIEM platforms (Splunk, Microsoft Sentinel, or equivalent)
- Working knowledge of vulnerability management tools such as Tenable Nessus/IO or Qualys
- Demonstrated understanding of SOC 2 Trust Service Criteria and NIST Cybersecurity Framework
- Familiarity with common attack techniques and defensive countermeasures (MITRE ATT&CK familiarity a plus)
- Strong analytical and problem-solving skills
- Excellent written and verbal communication skills; ability to translate technical findings for non-technical audiences
Benefits
- Health insurance
- Paid time off
- Flexible work arrangements
- Professional development
- Wellness programs
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Role Description Depending upon assignment, plans, designs, customizes, updates, develops, and maintains assigned application, technology infrastructure component, and related systems including large and small data processing and application systems serving work unit, division, department, multi departmental, and county wide functions. - Participate as a member of a team or lead a small team of application development, infrastructure, or systems support staff. - Work with users and troubleshoot and resolve system issues. - Implement system improvements and upgrades. - Participate as a responsible, cooperative, and positive team member. - Assignments may include software development, database administration, security administration, network, and server administration, service desk management, and GIS. Levels in this classification are flexibly staffed and are allocated based on the level, nature, and complexity of assignment. The eligible list created as a result of this recruitment will be used to fill full-time and part-time regular, limited-term or extra-help positions as vacancies occur in the Department of Information Technology. Qualifications - Equivalent to an Associate’s degree, preferably in information technology, or a closely related field. - Five (5) years of experience performing progressively responsible software development, or infrastructure management duties and functions. - A Bachelor’s degree from an accredited college or university, preferably in information technology, management information systems may be substituted for two years of experience. - Additional experience may substitute on a year for year basis for the educational requirement. Requirements - Applicants may be required to possess a valid California Driver’s License, Class C. - All licenses, certificates and registrations must be kept current while employed in this class. Benefits - All candidates are strongly encouraged to submit a copy of their college diploma or official/unofficial transcripts by the final filing deadline. - Candidates who fail to submit their diploma or transcripts by the final filing date may be disqualified from the recruitment. - Candidates who attended a college or university that is accredited by a foreign or non-U.S. accrediting agency must have their educational units evaluated by an educational evaluation service. Selection Process - 07/06/2026 – 5:00pm Deadline to submit application and required documents for first application review. - Qualified applicants may be invited for further examination. - Responses to supplemental questions may be used as screening and testing mechanisms. - A minimum score of 70% is required to continue in the selection process. - All potential new hires and employees considered for promotion will be subject to a background and reference check after contingent job offer is accepted. How to Apply - Applications must be submitted through the NEOGOV system. Paper copies of applications are not accepted. - All additional application materials must be submitted by July 6, 2026. - Previously submitted application materials for prior recruitments will not be applied for this recruitment. - Questions can be directed to the Department of Human Resources at (707) 784-6170, business hours are Monday-Friday, 8:00 a.m.-5:00 p.m. Veterans Preference Points - To be eligible, applicant must have served at least 181 consecutive days of active duty in the Armed Forces of the United States. - A COPY OF THE DD 214, SHOWING DISCHARGE TYPE MUST BE RECEIVED IN THE HUMAN RESOURCES DEPARTMENT BY THE FINAL FILING DATE. - Veteran applicants for initial County employment with an honorable or general under conditions discharge shall receive five (5) points added to their combined score. - Disabled veterans rated at not less than 30% disability shall have ten (10) points added to their combined score. Americans with Disabilities Act It is the policy of Solano County that all employment decisions and personnel policies will be applied equally to all County employees and applicants.
Analista de Segurança da Informação
AM53 Smart SolutionsA tecnologia certa. O talento ideal. No momento exato.
• Monitorar eventos e alertas de segurança em ambientes cloud e on-premises. • Identificar, analisar e tratar vulnerabilidades em sistemas, aplicações e infraestrutura. • Apoiar a implementação e manutenção de políticas, normas e procedimentos de segurança. • Participar da investigação e resposta a incidentes de segurança. • Realizar análises de riscos e propor ações preventivas e corretivas. • Apoiar auditorias internas e externas relacionadas à segurança da informação. • Garantir conformidade com a LGPD e demais requisitos regulatórios aplicáveis. • Acompanhar indicadores de segurança e elaborar relatórios gerenciais. • Apoiar equipes de desenvolvimento, infraestrutura e dados na adoção de boas práticas de segurança. • Conduzir ações de conscientização e treinamento sobre segurança da informação.
SOC Analyst Purple Team, Production Security
OnePointWepoint is the architect of major transformations for businesses and public sector organizations. We support our clients from strategy through technological implementation, always striving to think beyond the obvious and to act within the framework of Economic, Social, Environmental, and Technological Responsibility (RESET). Our goal is to create new ways of working, new economic models, and smarter environments. In nearly 20 years, we have become one of the key players in digital transformation, employing 3,500 people across Europe, Tunisia, North America, and the Asia-Pacific region.
Role Description En tant qu'Analyste SOC Purple Team, sécurité en production, vous apportez votre expertise en cybersécurité à un centre d’opérations de sécurité (SOC) 24/7. Votre rôle consiste à concevoir, implémenter et améliorer en continu des cas d’usage de détection ainsi que des règles de corrélation afin de détecter, prévenir et répondre aux cybermenaces visant les infrastructures. Vous contribuez activement à l’évolution des capacités de cybersécurité et au renforcement des mécanismes de défense. Vous participez également aux activités de threat hunting et aux investigations de sécurité afin d’améliorer les capacités du SOC en tant que première ligne de défense. Responsibilities - Analyser et suivre les tendances issues des journaux de sécurité provenant de multiples sources; - Développer et valider des cas d’usage de détection; - Concevoir et faire évoluer des capacités de threat hunting; - Investiguer, documenter et produire des rapports sur les incidents et tendances de sécurité; - Identifier des activités malveillantes potentielles dans les réseaux et contribuer à leur remédiation; - Participer à des exercices Purple Team pour tester et améliorer les mécanismes de détection; - Fournir du support et de la recherche sur des problématiques de sécurité; - Travailler de manière autonome tout en collaborant avec d’autres équipes; - Suivre les procédures de gestion des incidents et effectuer les analyses de triage; - Escalader les incidents critiques et recommander des améliorations opérationnelles; - Maintenir une connaissance des architectures technologiques, des vulnérabilités et des solutions de sécurité; - Améliorer continuellement les processus, outils, règles et contenus de détection. Qualifications - Expérience en gestion d’incidents de sécurité informatique (niveau intermédiaire à avancé); - Bonne connaissance des techniques utilisées par les malwares et les acteurs avancés; - Solide culture en cybersécurité; - Connaissance des environnements réseaux, systèmes (Windows/Unix) et bases de données; - Expérience en scripting (Shell, Python, Java, PowerShell, Ansible, SQL); - Expérience avec des technologies de sécurité telles que SIEM, EDR, IDS/IPS, pare-feux, DLP; - Expérience en analyse de logs, réponse à incident et analyse réseau (PCAP); - Bonne compréhension des fondamentaux réseaux (OSI, TCP/IP, DNS, HTTP(S), SMTP); - Connaissance des techniques d’attaque (phishing, scan de ports, attaques web, DDoS, mouvements latéraux); - Certifications en cybersécurité (GCFA, GCIH, OSCP ou équivalent) considérées comme un atout; - Excellente communication français et en anglais. L'anglais est requis, le poste demandant de communiquer avec des clients et des partenaires situés à l'extérieur du Québec. - Seuls les candidats légalement autorisés à travailler pour tout employeur au Canada seront considérés. Benefits - Minimum of 3 weeks of vacation starting from the first year; - Comprehensive group insurance with a generous employer contribution; - Employer contribution to a group RRSP; - Full remote work flexibility: Hybrid, Remote, or On-site; - A warm, bright, and welcoming office offering fresh fruit, coffee, beverages, occasional meals, etc.; - Annual IT equipment budget; - A balanced work environment with flexible working hours; - Career development: training and certifications, online or in-person learning, Wepoint Academy, etc.; - An international community of experts ready to share their knowledge; - A company culture focused on individuals’ needs and their belonging to a strong community.
Senior Information Security Analyst
Smith+NephewWe design and manufacture technology that takes the limits off living.
Role Description Join us as an Information Security Compliance Analyst and play a key role in shaping and delivering our annual HIPAA programme. This is an opportunity to work closely with leaders across Governance Risk and Compliance, with support and guidance from senior experts while owning essential programme activities that help protect our patients, people and systems. - Become the driving force behind the annual HIPAA programme. - Plan the programme’s schedule and coordinate with a wide range of partners. - Oversee the annual Security Risk Assessment, shaping its scope and collaborating with third party specialists. - Carry out security assessments on IT systems, record outcomes, track actions, and keep documentation updated in OneTrust. - Monitor changes in HIPAA law and support updates to internal policy. - Bring insights and recommendations forward to leadership and the Steering Committee. - Blend hands-on security experience with strong organisation and leadership skills. - Translate security controls into clear activities and turn complex challenges into structured actions. - Contribute to the growth of the HIPAA programme year after year. Qualifications - Bachelor's degree in Computer Science or related subject preferred. - Privacy or Security certifications would be advantageous but are not essential (e.g., any HIPAA certification, CISA, CISSP, ISO27001 or equivalent). Requirements - At least 5 years in Information Security, some of which should be in a compliance function. - At least 2 years working on HIPAA compliance is required. - At least 3 years in Program or Project Management. - Prior experience of Privacy Law related Security Controls compliance would be very well received. - Experience deploying and assessing Information Security controls, ideally aligned to frameworks such as HIPAA, GDPR TOMS, ISO27001, HiTrust or NIST. - Familiarity with tools such as OneTrust or IT risk management platforms, or the ability to learn them quickly. - Travel Requirements: < 5% Benefits - Base compensation range: $111,750 to $167,500 USD annually. - Competitive bonus and benefits, including medical, dental, and vision coverage. - 401(k) and tuition reimbursement. - Medical leave programs and parental leave. - Generous PTO and paid company holidays. - 8 hours of volunteer time annually. - Wellness offerings such as EAP. - 401k Matching Program, 401k Plus Program, Discounted Stock Options, Tuition Reimbursement. - Flexible Personal/Vacation Time Off, Paid Holidays, Flex Holidays, Paid Community Service Day. - Health Savings Account (Employer Contribution of $500+ annually). - Fertility and Adoption Assistance Program. - Hands-On, Team-Customized Training and Mentorship. - Discounts on fitness clubs, travel and more!

