Info Security Analyst I
Fenton, MI - USA
Job Summary
Where Human Connection Fuels Possibility
At Maritz decades of innovation and perseverance have built more than just a strong reputation theyve shaped a culture where human connection and collaboration are at the heart of everything we do.
Joining Maritz means becoming part of a workplace grounded in a critical truth; people and their potential is our greatest resource.
Maritz helps companies achieve their business goals by inspiring people to perform their best. We design experiences incentives and recognition programs that spark action and deliver measurable impact.
And weve brought this human-first design inward intentionally building teams that care for each other and collaborate our most recent employee survey nearly 90% of respondents said that their managers care about their concerns and 82% said they feel genuinely appreciated. We know that when employees feel seen supported and celebrated for who they are they thrive and so does our business.
Thats why weve created a flexible environment that empowers you to do your best work without sacrificing what matters most to fact in that same survey nearly 90% of respondents said they have the flexibility they need to balance work and personal life and nearly 80% said Maritz does a great job prioritizing employee well being.
We have a passion for excellence and genuine care for the people making it possible.
As a member of the Engagement Solutions Business Information Security Team Analysts are responsible for partnering with business and technology teams to identify assess and mitigate information security risks while supporting Maritzs overall information security program through security reviews vulnerability management threat evaluation incident response support DevSecOps initiatives risk assessment fraud operational support and audit / compliance activities.Working under the guidance of senior security professionals the analyst helps evaluate business processes applications and technologies to ensure alignment with security policies regulatory requirements and industry best practices. This position serves as a liaison between security technology and business stakeholders while developing foundational expertise in cybersecurity risk management governance compliance fraud protections and security operations.
What Youll Be Doing
30% Support secure use case reviews application security assessments architecture reviews security exception requests and third-party/vendor risk evaluations. Research emerging technologies and security requirements to identify risks and recommend appropriate controls mitigations and security best practices.
25% Support vulnerability management and DevSecOps initiatives by reviewing vulnerability findings evaluating remediation plans and extension requests maintaining application security scans tracking remediation activities coordinating efforts with application infrastructure and DevOps teams and assisting with the evaluation and response to emerging security threats and vulnerabilities.
20% Support security governance compliance and audit activities including customer security assessments PCI and SOC evidence collection policy and standards maintenance and responses to client security questionnaires and vendor assessments.
15% Develop maintain and utilize security reporting automation and analysis solutions through scripting APIs security tools and data analysis to improve operational efficiency and provide meaningful security metrics.
10% Collaborate with development DevOps infrastructure business and security teams to communicate security requirements support remediation efforts assist with security initiatives promote secure practices and contribute to continuous improvement efforts.
What Youll Bring
Bachelors Degree in Cybersecurity Computer Science Information Technology Information Systems or related field of study; equivalent practical experience may be considered in lieu of a degree.
At least two years of experience within information security.
Ability to research unfamiliar technologies analyze technical documentation troubleshoot issues and develop practical recommendations or solutions.
Knowledge of fundamental cybersecurity concepts including risk management vulnerability management incident response secure software development network security cloud security and authentication and authorization principles.
Strong written and verbal communication skills with the ability to communicate technical concepts security requirements and risk-based recommendations to both technical and non-technical audiences.
Ability to work independently and within a team environment to identify and analyze security risks formulate recommendations and coordinate remediation activities across multiple stakeholders.
Basic scripting automation or data analysis experience using Python PowerShell SQL APIs Bash Power Automate or similar technologies preferred.
Familiarity with cybersecurity frameworks and standards such as NIST Cybersecurity Framework CIS Controls PCI DSS SOC 1 and SOC 2.
Experience working with cloud platforms application security tools vulnerability management platforms source code repositories CI/CD pipelines or ticketing systems preferred.
Nice To Have
Security Network GSEC or other security-focused certifications.
Academic research experience cybersecurity competition participation internships homelab projects or other hands-on technical experience.
Exposure to cloud-native architectures containers APIs infrastructure-as-code or DevSecOps practices.
Experience using collaboration DevOps cloud and security platforms such as Jira Confluence Bitbucket Rapid7 SonarQube GCP (and SCC) Azure AWS or similar technologies.
Things You Should Know
This is a hybrid role based in Fenton MO (Tuesday Wednesday Thursday).
The successful candidate must be able to think critically and be capable of researching unfamiliar technologies to identify risks and recommend practical solutions. The candidate should be able to interpret Maritz security policies communicate effectively with internal teams and clients and make risk-based recommendations that align with Maritzs security objectives and risk tolerance. Works collaboratively with others to support daily security operations compliance initiatives incident response activities and larger security program projects.
DISCLAIMER: This job description is designed to indicate the general nature and level of work performed by associates within this classification. It is not designed to confirm or be interpreted as a comprehensive summary of all duties responsibilities and qualifications required of associates assigned to this job.
Maritz offers a comprehensive benefits package for full-time employees including medical dental vision life insurance disability paid parental leave 401k tuition reimbursement paid time off year end holiday closure and more!
Maritz will only employ applicants who have authorization to work permanently in the U.S. This is not a position for which sponsorship will be provided. Those who need sponsorship for work authorization now or in the future are not eligible for hire. No calls or agencies please.
Maritz is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to sex race color religion national origin age marital status political affiliation sexual orientation gender identity genetic information disability or protected veteran status. We are committed to providing a workplace free of any discrimination or harassment.
If you have a disability and are having difficulty accessing or using this website to apply for a position you can request help by calling 1- or by sending an email to .
Required Experience:
IC
About Company
At Maritz, we inspire people. Unleashing their full potential so they can perform at their best. With science. And art. And passion.