The Cyber Security Analyst – Senior II is a regional role within FedEx InfoSec, responsible for driving cybersecurity, risk, and compliance initiatives across the AMEA region. This role acts as a trusted advisor to business stakeholders, ensuring alignment with global security standards while enabling regulatory compliance and secure business operations. The position focuses on risk visibility, security program delivery, and embedding secure‑by‑design principles, while also mentoring junior team members and supporting incident response activities.
About The Role
FedEx Information Security (InfoSec) plays a critical role in safeguarding enterprise systems, enabling business agility, and ensuring regulatory compliance across global operations. As a Cyber Security Analyst – Senior II, you are not just executing tasks, you are driving security outcomes at a regional level. This role sits at the intersection of business, risk, and technology, acting as a trusted advisor and regional SME while leading high‑impact security and compliance initiatives across the AMEA region. You will work closely with business leaders, global InfoSec teams, and regulatory stakeholders to translate security into business value, while strengthening the organization’s security posture.
Key Responsibilities
Strategic Security Leadership
- Lead and drive regional security initiatives including regulatory compliance, risk management, and governance programs
- Act as a trusted advisor to senior stakeholders, providing risk‑based and practical security guidance
- Own and manage end‑to‑end delivery of security programs with minimal supervision
BISO‑Aligned Business Engagement
- Act as a single point of contact for InfoSec within supported business areas
- Bridge communication between business teams, InfoSec SMEs, and global security functions
- Embed secure‑by‑design principles into business initiatives and technology solutions
Risk Visibility & Compliance
- Provide aggregated risk visibility through dashboards, scorecards, and reporting (Power BI or equivalent)
- Drive remediation efforts for vulnerabilities and compliance gaps
- Ensure adherence to global InfoSec standards and regional regulatory requirements (e.g., GDPR and local laws)
Security Architecture & Operations
- Oversee regional security design alignment with global standards
- Support and guide implementation of:
- Network segmentation
- Identity & access controls (RBAC, MFA)
- Logging, monitoring, and incident response
- Data protection (DLP, encryption)
Program & Project Leadership
- Lead strategic initiatives such as:
- Business continuity and disaster recovery planning
- Vulnerability management programs
- Security automation and reporting improvements
- Apply LEAN, AGILE, and automation practices to improve efficiency and scalability
Team Mentorship & Capability Building
- Mentor and guide junior team members and analysts, supporting their development in cybersecurity, compliance, and risk management practices
- Provide knowledge sharing, coaching, and practical guidance on security frameworks, tools, and processes
- Promote consistency in execution and help elevate overall team capability within the region
Incident & Investigation Support
- Act as an extension of the BISO‑CERT function during active security incidents
- Provide business context and coordination during security investigations and response efforts
Core Skills & Experience
Technical & Domain Expertise
- Strong experience in cybersecurity governance, risk, and compliance (GRC)
- Deep understanding of:
- Regulatory frameworks (GDPR, regional regulations)
- Vulnerability management and security operations
- Enterprise security architecture principles
Tools & Technologies
- Hands‑on experience with:
- ServiceNow (GRC / SecOps modules)
- Power BI / reporting tools
- Automation tools (Power Automate, RPA, scripting)
Program & Delivery
- Proven experience in leading large‑scale security initiatives
- Strong foundation in project/program management (Agile/Lean)
Soft Skills That Actually Matter Here
- Ability to influence without authority (this is critical at Senior II level)
- Strong stakeholder management across technical and non‑technical audiences
- Sharp analytical thinking with practical problem‑solving approach
- Clear communicator who can translate security risks into business impact
Qualifications
- Bachelor’s degree in Computer Science, Information Security, or related field
- Typically 7–10 years of experience in cybersecurity, risk, or compliance roles
- Relevant certifications (preferred): CISSP, CISM, CRISC, ISO 27001
What Success Looks Like In This Role
- You become the go‑to security advisor for your business area
- Risks are not just reported, they are understood, prioritized, and reduced
- Security is seen as a business enabler, not a blocker
- You operate independently, yet stay aligned with global strategy
Why This Role Is Different
This is not a monitoring or execution‑heavy role. This is a high‑visibility, influence‑driven role where you work closely with stakeholders to guide security decisions, drive remediation, and strengthen the region’s security posture in alignment with global standards.
Preferred Qualifications
Not available.
All qualified applicants will receive consideration for employment regardless of age, race, color, national origin, genetics, religion, gender, marital status, pregnancy (including childbirth or a related medical condition), physical or mental disability, or any other characteristic protected by applicable laws, regulations, and ordinances.