About the role
The Cybersecurity Analyst is responsible for leading and managing enterprise cybersecurity programs that protect the organization's information assets, technology infrastructure, client environments, and regulatory obligations. This role serves as the primary liaison between Information Technology, Information Security, business stakeholders, and external clients to ensure cybersecurity initiatives are successfully planned, implemented, governed, and maintained. The Cybersecurity Analyst oversees security projects, compliance initiatives, risk management activities, customer security requirements, third-party security assessments, and continuous improvement programs while ensuring alignment with business objectives and industry best practices.
Key responsibilities
- Own and continuously improve the company's cybersecurity program, including policies, controls, risk assessments, and incident response plans.
- Develop, implement, and manage enterprise cybersecurity programs and strategic initiatives.
- Lead cross-functional security projects from planning through execution.
- Develop project plans, timelines, budgets, risk registers, and executive status reports.
- Coordinate internal and external stakeholders to ensure successful delivery of security initiatives.
- Monitor for vulnerabilities and threats across systems and vendor integrations, drive remediation to closure.
- Maintain compliance with relevant frameworks and regulations (e.g., SOC 2, ISO 27001, PCI-DSS, GDPR, as applicable).
- Partner with IT, engineering, and business stakeholders to embed security requirements into projects and vendor onboarding.
- Report program status, risks, and metrics to leadership on a regular cadence.
- Manage security incident response, including investigation, containment, and post-incident review.
About you
- 3+ years of experience in cybersecurity, with at least 2 years in a team-lead capacity.
- Experience managing third-party/vendor security risk, ideally including large-scale contact center operations, as well as delivery, logistics, or platform integration partners.
- Working knowledge of security frameworks (NIST, ISO 27001, CIS Controls) and compliance requirements relevant to the business.
- Strong understanding of network security, identity and access management, and cloud security fundamentals.
- Excellent communication skills, with the ability to translate technical risk into business terms for non-technical stakeholders.
- Relevant certifications (CISSP, CISM, or similar) preferred but not required.
- Exceptional customer service orientation.
- Program and project management capabilities.
- Risk management expertise.
- Keen attention to detail.