Information Security Analyst

Nepc, Llc

Boston (MA)

Hybrid

USD 81,000 - 108,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

NEPC, LLC, a Boston-based investment consulting firm, is seeking an Information Security Analyst to join the department led by the Director of Information Security. The role focuses on security operations, investigations, and vulnerability follow-through, with governance and risk coordination as secondary responsibilities.

You will monitor alerts, coordinate remediation with IT and business partners, document findings, and support risk and compliance activities including the risk register and

Qualifications

  • 3–5 years of information security experience.
  • Certifications such as Security+, CySA+, CISSP or ISC2 noted.
  • Associate degree preferred but not required.

Responsibilities

  • Monitor, investigate, and triage security alerts, events, vulnerabilities.
  • Coordinate remediation with IT, analysts, and stakeholders.
  • Document investigatory steps, evidence, and remediation progress.
  • Support vulnerability management activities and track overdue items.
  • Maintain the risk register and document operational risks and control gaps.
  • Assist with Operational Risk Council materials and audit evidence.
  • Partner with Compliance on security and privacy requirements.
  • Support procedures, policy updates, and security awareness.

Skills

Security operations
Threat triage
Vulnerability management
SIEM
Communication
Documentation
Procedural discipline
Endpoint protection
Vulnerability platforms
Ticketing systems
Dashboards

Education

Security certifications (Security+, CySA+, CISSP/ISC2)
Associate degree preferred

Tools

Endpoint protection
Vulnerability management platforms
SIEM
Ticketing systems
Dashboards

Job description

Location: Flexible (East Coast preferred). Must reside in a state where we are registered.

Role Summary:

The Information Security Analyst is a role reporting to the Director of Information Security and focused primarily on security operations, investigations, and vulnerability follow-through, with secondary responsibility for governance and operational risk coordination. The analyst works across security tools and business processes toidentifyissues, investigate activity, document findings, and drive remediation with IT and other stakeholders.

This roleis responsible formonitoring and investigating alerts and vulnerabilities, coordinating response and remediation efforts,maintainingclear documentation, and supporting core security governance activities such as the risk register, committee records, and audit evidence. Success in this role requires strong judgment, disciplined procedure-following, clear communication, and the ability to work independently while collaborating across technical and non-technical teams.

Core Responsibilities:

  • Monitor, investigate, and triage alerts, events, vulnerabilities, and escalated helpdesk tickets acrossthesecuritystack;Understandingpotential impactanddistinguishingmeaningful threats from false positives or low-risk activity.
  • Coordinate with IT, Business Analysts, process owners, and other stakeholders to drive remediation, containment, follow-up, and closure of security and operational risk issues.
  • Document investigative steps, evidence, decisions, remediation progress, and outcomes in a clear, consistent, and repeatable manner;identifyrecurring issues, process gaps, and broader trends, and elevate them appropriately.
  • Support vulnerability management activities, including scan coordination, review of findings, remediation tracking, follow-up on overdue items, and validation of progress against defined timelines.
  • Maintain the risk register, including risk descriptions, owners, mitigation plans, status updates, and supporting records, and work alongside Business Analysts and process owners toidentifyand document operational risks, control gaps, and dependencies revealed through incidents, investigations, or project work.
  • Assist with Operational Risk Council activities by preparing materials, tracking action items, andmaintainingmeeting records, andorganizedocumentation and evidence needed for audits, regulatory requests, and internal reviews.
  • Partner with the Compliance team to support security and privacy requirements related to client contractual obligations, Regulation S-P, and emerging technology use cases.
  • Support security procedures, policy updates, and awareness efforts by helping keep documentation current andidentifyinguseful communication or training opportunities based on trends andobservedissues.

Required and Preferred Qualifications:

Experience and Background

  • Requires3–5years ofworkingexperience in information security, ITInfrastructure, systems administration, networking,and/ortechnical support;additionalaudit, compliance, or risk-related experience is helpful.
  • Relevant certifications may include Security+,CySA+, ISC2 entry-level certifications, GSEC, or similar information security, audit, or risk-related certifications.
  • Associate’s degree preferred but notrequired.

Skills and Knowledge

  • Working knowledgeofandexperience withsecurity operationsactivities suchas alert triage, vulnerability tracking,investigationworkflows, escalation, and documentation.
  • Proficiencyusingsecurity and IT tools such as endpoint protection, vulnerability management platforms, SIEM, ticketing systems, dashboards, and related technologies.
  • Strong written and verbal communication skills across teams with different technical and operational backgrounds.
  • Ability to follow procedures carefully, improve documentation where needed, and manage work with minimal supervision.
  • Sound judgment, attention to detail, and the ability to prioritize effectively when handling multiple issues.
  • Familiarity with CIS Controls, NIST, CISA publications, and related standards is helpful.

Compensation:

The base salary for this role is $80,500 - $107,500 per year with an additional annual performance bonus. Individual compensation is based on a variety of factors, including experience, education, certifications, location, responsibilities of the role, internal equity and alignment with market data.

Company Background:

NEPC, LLC is a full-service investment consulting firm based in Boston, Massachusetts. We were founded in 1986 and now have approximately 375 employees and over 400 clients. We help governments, institutions, families, and individuals preserve and grow their capital across different asset classes and market cycles. We provide a variety of consulting services such as asset allocation, performance measurement, policy formulation, investment manager research, and discretionary portfolio management. Our clients include defined benefit, defined contribution, endowments, foundations, trusts, public, corporate, Taft-Hartley, health & welfare, high net worth, insurance, and private plans.

Culture is important to us here at NEPC – our values include putting clients first, doing the right thing, bringing your whole self to work, building trust, embracing change, and having a we before me approach in our work. Advancing diversity and inclusion within our firm and industry is also a core initiative at NEPC. We are a strong advocate of promotion from within, so excellent potential exists for professional growth. We’re a fun (but demanding) company with excellent working conditions, a very supportive, team-oriented environment, and a full benefits program to support your life and well-being. We offer a competitive salary and bonuses (when applicable).

NEPC is an Affi

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations & Risk Analyst
Security Operations & Risk Analyst

Nepc, Llc • Boston (MA)

Hybrid
USD 81,000 - 108,000
Senior Information Security Analyst
Senior Information Security Analyst

Marotta Controls, Inc. • Parsippany-Troy Hills (NJ)

On-site
USD 121,000 - 132,000
Quarterly bonus
401(k) with company match
Tuition aid
+1
Senior Information Security Analyst
Senior Information Security Analyst

Marotta Controls, Inc • Parsippany-Troy Hills (NJ)

On-site
USD 121,000 - 132,000
Quarterly bonus
401(k) with company match
Medical, dental, vision insurance
Information Security Analyst
Information Security Analyst

Boston Partners • Boston (MA)

On-site
USD 125,000 - 175,000
Information Security Analyst
Information Security Analyst

Boston Partners Global Investors, Inc. • Boston (MA)

On-site
USD 125,000 - 175,000
IT Support Specialist
IT Support Specialist

Nepc, Llc • Boston (MA)

On-site
USD 62,000 - 81,000
Information Security Analyst
Information Security Analyst

Clearcapital • Reno (NV)

On-site
USD 113,800 - 139,000
Comprehensive medical, dental, and vision insurance
401(k) retirement plan with employer match
Paid time off (PTO) and paid holidays
Junior Security Analyst
Junior Security Analyst

The Cadmus Group LLC • United States

On-site
USD 75,000 - 95,000
Medical insurance
Dental insurance
Vision insurance
+4
Security and Compliance Engineer, IT - CMMC/NIST SP 800-171
Security and Compliance Engineer, IT - CMMC/NIST SP 800-171

Technical Support International • Massachusetts

On-site
USD 120,000 - 150,000
Health and dental
Life Insurance
Paid time off
+2
Junior Security Analyst
Junior Security Analyst

Cadmus • Richmond (VA)

On-site
USD 75,000 - 95,000