Be your best when it really matters. At the #MomentOfService
FedRamp Information Security Analyst
Location
Illinois
Posted
2 days ago
Salary
0
Seniority
Junior
Job Description
FedRamp Information Security Analyst
IFS
• Responsible for supporting 24x7 operations within the Unified Support Security Operations Center (SOC) and Observability functions • Continuous monitoring of security events and system health across IFS customer environments • Analyzing alerts from both security and observability platforms • Identifying potential threats or service anomalies • Ensuring timely incident triage and response • Responsible for monitoring the IFS customer security state • Analyze real-time events and triage incidents based on the severity of the situation • Assist in identifying and addressing information security gaps, with a focus on cloud environments • Stay up to date on the latest cybersecurity threats and vulnerabilities and support the implementation of recommended mitigations • Proactively monitor alerts for all cloud hosted IFS products • Communicate with other resolver groups to rectify them • Contribute to the operation (Observability) coverage of 24x7x365 • Identify and categorize prioritized incoming events or alerts for IFS products via Observability stack • Generate regular reports on the organization’s security posture and incident trends • Contribute to the creation and maintenance of operational documentation and knowledge base articles • Any other duties as designated by the line manager
Job Requirements
- A degree in Information Security, Computer Science, or Information Technology with 1 years of experience in security operations or information security role in the industry
- Knowledge in SIEM, XDR, cloud security threats, malware protection, and vulnerability management
- One or combination of: CEH / ECSA / Security+ or other similar qualifications
- Any cloud security specific certification or other qualifications is an added advantage
- Previous experience of one of Cloud providers (AWS, Azure, Google Cloud)
- Scripting skills (Bash, PowerShell, or Python) are a plus
- 1 year experience in L1 Support (Event Management/Observability/DevOps/Help Desk)
Benefits
- Flexible paid time off, including sick and holiday
- Medical, dental, & vision insurance
- 401K with Company contribution
- Flexible spending accounts
- Life insurance and disability benefits
- Tuition assistance
- Community involvement and volunteering events
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
• Own complex incident investigations end-to-end, from detection to containment and remediation. • Conduct root cause analysis and post-incident reviews. • Continuously hunt for anomalies and threats across on-prem and cloud environments using threat intelligence, analytics, and behavioral patterns. • Monitor global threat actor activity, transform raw intel into actionable defense strategies, and collaborate with internal teams to harden security posture of OutSystems. • Work with engineering and DevSecOps teams to improve detection coverage, enrich SIEM use cases, and automate response processes. • Develop, optimize, and maintain incident response and threat hunting playbooks, ensuring operational excellence and consistency. • Identify gaps, suggest improvements, and contribute to capability building for detection, response, and threat modeling.
Role Description Our client in IT/Tech sector is seeking a SOC Analyst II to join the security operations team. This is a hands-on, second-line role at the center of the client's detection and response program. The ideal candidate will spend each day: - Investigating security alerts that have escalated beyond the initial triage layer. - Distinguishing genuine threats from false positives. - Driving confirmed incidents through containment, remediation, and resolution. - Operating in a fast-paced, telemetry-rich environment spanning cloud and on-premises infrastructure, thousands of endpoints, and a modern security stack that includes SIEM, EDR, and email security platforms. Beyond day-to-day monitoring, the ideal candidate will: - Take ownership of improving the effectiveness of the security operations function. - Contribute to maturing detection content. - Reduce alert fatigue by tuning false positives. - Enhance incident response runbooks and playbooks to ensure consistent handling across shifts. - Work closely with senior SOC analysts, threat hunters, and detection engineers to strengthen technical expertise and progress toward a Tier 3 SOC Analyst or specialized Security Engineering career path. This is a fully remote opportunity available on either a full-time or contract basis. Qualifications - 2 to 4 years of hands-on SOC, incident response, or security analyst experience. - Working knowledge of SIEM platforms such as Splunk, Microsoft Sentinel, or QRadar. - Familiarity with EDR tooling including CrowdStrike, SentinelOne, or Microsoft Defender. - Solid grounding in networking fundamentals, TCP/IP, DNS, and common attack techniques. - Ability to interpret logs and telemetry to reconstruct an attack timeline. - Strong written documentation and clear communication under time pressure. Requirements - Security+, CySA+, GCIH, or equivalent certification. - Experience with SOAR platforms and automation scripting in Python or PowerShell. - Working familiarity with the MITRE ATT&CK framework and threat-informed defense. - Exposure to cloud security monitoring in AWS or Azure.
Role Description The Lead Information Security Analyst is a senior cybersecurity leader responsible for protecting the organization’s digital ecosystem across product development, manufacturing, and enterprise IT systems. This role ensures the security of connected medical/surgical devices, intellectual property, and regulated environments, while maintaining compliance with cybersecurity guidance, ISO standards, and global regulations. This position plays a critical role in enabling secure product innovation, patient safety, and operational resilience across the device lifecycle. Key Responsibilities: - Security Operations & Incident Response - Lead detection and response for incidents affecting: - Manufacturing systems (OT/ICS) - Connected medical/surgical devices - Enterprise IT environments - Manage SOC operations with prioritization of IT security, production integrity, and supply chain impact - Investigate and respond to incidents involving: - Intellectual property theft - Disruptions and/or ransomware affecting production lines - IT vulnerabilities - Lead regulatory-aligned incident handling and disclosure (local/global authorities) - Production & IT Security (Critical Focus Area) - Partner with IT, production, and engineering to embed secure-by-design principles across the IT & product lifecycle - Conduct threat modeling and security risk assessments for surgical and medical devices - Support compliance with: - IT security guidance - SOX - ISO27001 - EU GDPR / NIS2 - Identify and remediate product vulnerabilities (secure firmware, APIs, connectivity) - Support coordinated vulnerability disclosure (CVD) processes - Manufacturing & Operational Technology (OT) Security - Secure manufacturing environments (plants, production lines, robotics, control systems) - Implement segmentation between IT and OT networks - Lead vulnerability and patch management for industrial control systems - Reduce risk to production continuity and product integrity - Threat & Vulnerability Management - Monitor threat landscape with emphasis on: - Nation-state attacks targeting IP - Supply chain compromise - Medical device exploitation - Lead proactive threat hunting across: - Cloud environments - OT/manufacturing systems - Product telemetry (if applicable) - Drive enterprise-wide vulnerability management with prioritization based on patient and product impact - Security Engineering & Architecture - Implement Zero Trust principles across corporate IT and manufacturing environments - Drive consolidation and optimization of: - SIEM/XDR (Sentinel, Defender, etc.) - Identity platforms (Entra ID, PAM) - Data protection tools (DLP, encryption for IP and regulated data) - Secure cloud platforms supporting R&D, analytics, and digital health capabilities - Regulatory Compliance & Risk Management - Ensure alignment with: - SOX - ISO 27001 - NIST CSF / NIST 800-53 - Global data protection regulations (GDPR where applicable) - Lead cyber risk assessments tied to patient safety, product risk, and regulatory exposure - Support internal and external audits and regulatory inspections - Translate cybersecurity risk into business impact (recalls, production disruption, liability) - Data Protection & Intellectual Property Security - Protect sensitive data, designs, and trade secrets - Implement controls for: - Secure collaboration with third-party manufacturers and partners - Data encryption and access governance - Monitor for data exfiltration and insider threats - Leadership & Mentorship - Provide technical leadership across security operations and engineering functions - Mentor analysts and engineers on: - IT/OT security - Production security - Incident response in regulated environments - Act as escalation point for high-impact security events affecting products or manufacturing - Stakeholder Collaboration - Partner with: - CIO - CISO - Chief Product/Engineering Officers - Quality & Regulatory Affairs - Manufacturing / Plant leadership - Legal and Compliance teams - Communicate cybersecurity risks in terms of: - IT security & safety - Regulatory impact - Revenue / production risk Qualifications - Bachelor’s degree in Cybersecurity, Engineering, IT, or related field (or equivalent experience) - 5+ years of experience in cybersecurity, with exposure to regulated industries or manufacturing environments, with 7+ years highly preferred - Hands-on experience with: - SIEM/XDR platforms - Endpoint, network, and cloud security - Vulnerability and incident response programs - Strong knowledge of: - Security frameworks (NIST, ISO 27001) - Identity and access management - Network segmentation and Zero Trust principles Requirements - Experience in medical device, healthcare technology, or manufacturing (OT/ICS) - Familiarity with: - ISO27001 - NIS2 - SOX - NIST CF 800-53 - EU GDPR - Preferred Certifications: CISSP, CEH, GIAC, GICSP (Industrial Control Systems) or HCISPP (strong plus) - Experience with: - IT/Production security testing - Threat modeling (e.g., STRIDE) - Secure SDLC practices Benefits - Competitive compensation - Excellent healthcare including medical, dental, vision and prescription coverage - Short & long term disability plus life insurance -- cost paid fully by CONMED - Retirement Savings Plan (401K) -- CONMED matches your contributions dollar for dollar, with the potential for up to 7% per pay period - Employee Stock Purchase Plan -- allows stock purchases at discounted price - Tuition assistance for undergraduate and graduate level courses
• Protect sensitive data and critical assets from current and emerging threats. • Analyze problems, structure issues and perform analysis. • Partner cross-functionally to identify trends and resolve issues. • Ensure initiative/project goals are met in a timely manner.




