Information Security Analyst
Core
Support security assurance workflows including customer security reviews, third-party risk assessments, vendor security reviews, and evidence management.
Role type
Information Security Analyst (Security Trust)
Builds
Security assurance workflows, Trust Center operations, and risk assessment processes
Domain
Information Security / Governance, Risk, and Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Security assurance, third-party risk management, security questionnaire analysis, compliance documentation review, risk assessment, evidence management, AI tool utilization, process improvement
Preferred skills
SaaS security experience, Trust Center platform experience, third-party risk management platform experience, cloud platform familiarity, security automation experience, security certifications
Technologies
SOC 2, ISO 27001, NIST CSF, NIST SP 800-53, PCI DSS, HIPAA, Conveyor, SafeBase, Vanta, AWS, Azure, Google Cloud Platform
Responsibilities
Respond to customer security questionnaires and vendor assessments; Review security artifacts including SOC 1/2 reports and penetration testing results; Translate technical security information into clear responses for stakeholders; Evaluate security risks and recommend remediation options; Maintain reusable security content and knowledge bases; Partner with cross-functional teams to support security reviews; Track security review status and operational metrics; Support internal and external audit readiness; Identify opportunities to automate repetitive work using AI.
Seniority
Mid-level, hands-on IC