Governance and Information Security Analyst
Governance and Information Security
Job Title: Governance and Information Security Analyst
Location: Local
Department: Governance and Information Security
Job Summary:
The Security Analyst / Cybersecurity Analyst is responsible for implementing, operating, and continuously improving the organization’s security controls, incident response capabilities, vulnerability management, and compliance posture. This role supports governance objectives by ensuring security technologies, processes, and controls are aligned with business requirements, regulatory standards, and defined security SLAs.
Key Responsibilities:
1. Security Technology Implementation & Operations
- Deploy, configure, and continuously optimize enterprise security technologies, including but not limited to:
- Endpoint Detection & Response (EDR)
- Data Loss Prevention (DLP)
- Privileged Access Management (PAM)
- Vulnerability Management solutions
- Secure Web Gateway (SWG)
- Network Detection & Response (NDR)
- Integrate security tools withSIEM,SOAR, and IT service management (ITSM) workflows.
- Ensure security controls operate effectively and generate measurable detection and prevention outcomes.
Outcome:
Stable, effective, and measurable security controls that enhance the organization’s overall security posture.
2. 24×7 Incident Response Operations
- Participate in the24×7 security incident response rotation, including on-call duties as required.
- Investigate, respond to, and manageSeverity 1 and Severity 2 security incidents.
- Perform containment, eradication, and recovery activities in accordance with incident response procedures.
- Escalate incidents to internal stakeholders and leadership when necessary.
Outcome:
Rapid incident response with minimized business impact to critical systems and operations.
3. Vulnerability Management & Security Engineering Enablement
- Conduct regularvulnerability assessmentsand analyze scan results.
- Recommend, track, and validate remediation actions in coordination with IT and business teams.
- Monitor remediation progress and report on risk posture and SLA adherence.
- Align security controls with business and IT requirements.
- Supportsecure-by-designprinciples in system changes, enhancements, and deployments.
Outcome:
Reduced security risk aligned with defined SLAs and improved integration of security into IT change processes.
4. Audit, Compliance, and Risk Support
- Support internal and external audits by providing evidence, documentation, and control validation.
- Assist in remediation of audit findings and track closure of observations.
- Support access reviews, control testing, and compliance reporting activities.
- Coordinate with governance, risk, and compliance (GRC) stakeholders as required.
Outcome:
Timely audit support, reduced audit observations, and strengthened compliance and governance posture.
5. Threat Intelligence & Security Posture Improvement
- Track emerging security threats, vulnerabilities, and regulatory requirements.
- Evaluate threat intelligence and recommend security enhancements.
- Contribute to the continuous improvement of the organization’s security roadmap and control maturity.
Outcome:
Ongoing improvement of security posture through informed and proactive control enhancements.
6. Ad-hoc and Operational Support
- Perform additional duties as required to support evolving security initiatives, incidents, or governance priorities.
Outcome:
Responsive and adaptable security support aligned with organizational and risk priorities.
Qualifications:
- Experience with enterprise security tools (EDR, DLP, SIEM, SOAR, PAM, Vulnerability Management)
- Incident response and security operations experience
- Knowledge of security governance, risk, and compliance concepts
- Familiarity with audit processes and regulatory requirements
- Strong analytical, documentation, and stakeholder communication skills