Enter a job title or keyword

Sr Infosec Analyst


Job Location:

Woburn, MA - USA

Monthly Salary: Not provided by the employer
Posted: 21 September 2026 (9 hours ago)
Application Deadline: 19 December 2026
Vacancies: 1 Vacancy

Job Summary

The Senior Information Security Analyst is a key member of the Second Line of Defense providing independent oversight credible challenge and risk-based guidance to strengthen the effectiveness of the organizations information security program. This role conducts advanced cybersecurity risk assessments evaluates the design and operating effectiveness of security controls supports security governance activities and advises on regulatory architectural and compliance matters. The analyst partners closely with First Line teams Independent Risk Oversight Compliance Legal IT and business stakeholders to ensure security risks are identified assessed monitored and managed in alignment with regulatory expectations industry standards and organizational objectives.
Roles and Responsibilities:
Lead and execute complex risk assessments across applications infrastructure and business processes.
Evaluate and challenge the design and operating effectiveness of security controls implemented by First Line teams recommending practical improvements to strengthen the control environment.
Monitor and report on key risk indicators (KRIs) control performance and emerging threats.
Analyze security logs threat intelligence and incident data to identify systemic risks and recommend mitigation strategies.
Serve as subject matter expert on regulatory frameworks (e.g. NIST CSF FFIEC PCI DSS).
Support the development and enhancement of security policies standards and procedures.
Lead or assist incident response activities including triage investigation containment and post-incident review.
Provide second-line oversight of vulnerability management including reporting risk prioritization remediation tracking and escalation of significant issues.
Participate in internal and external audits regulatory exams and risk committee reporting.
Collaborate with IT Legal Compliance and business units to independently assess security risk in new initiatives and technologies.
Independently assess and challenge cybersecurity risk associated with cloud services applications infrastructure artificial intelligence solutions and third-party vendors ensuring risks are appropriately identified rated and escalated in accordance with the organizations risk appetite.
Advise IT infrastructure and business teams on security risk and control best practices providing independent risk-based guidance without assuming ownership or operational responsibility for control design or implementation.
Research emerging cybersecurity threats trends and technologies recommending practical solutions to address evolving risks.
Leverage Microsoft Purview capabilities including Data Loss Prevention and eDiscovery to support compliance requirements and protect sensitive information.
Contribute to the development of the GRC platform and risk reporting dashboards.
Required Skills:
6-9 years of experience in information security IT risk management security engineering or a related discipline preferably within a regulated industry.
Bachelors degree in Information Security Computer Science or a related field; Masters degree or relevant certifications (e.g. CISSP CISM CRISC CISA) strongly preferred.
Strong understanding of cybersecurity risk management governance and control frameworks such as NIST CSF ISO 27001 COBIT FFIEC and PCI DSS.
Experience performing security assessments threat modeling architectural reviews and risk analysis.
Experience with Microsoft Purview and Microsoft Defender preferred.
Proficiency in cloud security endpoint protection and data loss prevention (DLP) technologies.
Familiarity with SIEM tools vulnerability management platforms and incident response processes.
Experience with governance risk and compliance (GRC) platforms such as Archer ServiceNow IRM RiskConnect or similar.
Familiarity with artificial intelligence tools and their cybersecurity implications including data protection threat detection automation and third-party risk considerations.
Strong analytical communication and stakeholder engagement skills with the ability to influence technical teams business stakeholders and leadership through clear risk-based recommendations.
Naturally curious and hands-on with the ability to solve complex problems learn new technologies and address evolving security challenges.
Preferred Skills:
Masters degree or relevant certifications (e.g. CISSP CISM CRISC CISA) strongly preferred.
Experience with Microsoft Purview and Microsoft Defender preferred.
Supervisory Responsibilities:
None.
Complexity & Difficulty:
This position requires strong analytical judgment sound risk management discipline independence and the ability to constructively challenge and influence stakeholders. The role balances technical security considerations regulatory expectations business priorities and emerging cyber risks while delivering clear practical recommendations to strengthen the organizations security posture.