Information Security Analyst

Xpansiv%20

United States

On-site

USD 80,000 - 95,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Xpansiv is seeking an Information Security Analyst to strengthen and mature its cybersecurity posture across security operations, risk management, and threat detection. You will monitor alerts, perform vulnerability assessments, and support compliance efforts in a fintech/regulated environment.

The role requires experience with cloud security, SIEM, EDR, and incident response, with a focus on secure configurations and collaboration with IT/DevOps teams.

Qualifications

  • 3–5 years of hands-on experience in cybersecurity, information security, or IT risk.
  • Strong understanding of networking fundamentals, endpoint protection, and cloud security (AWS, Azure, or GCP).
  • Familiarity with SIEM platforms, SAST, DAST, vulnerability management tools, and incident response processes.
  • Familiarity with common EDR platforms.
  • Knowledge of security frameworks such as NIST CSF, ISO 27001, or CIS Controls.
  • Bachelor’s degree in Information Security, CS, or related field (or equivalent experience).
  • Experience in fintech, financial services, or other regulated environments.
  • Exposure to compliance standards such as NFA, FCA, SOC 2, or ISO 27001.
  • Relevant certifications (e.g., CompTIA Security+, CySA+, CEH, etc.).
  • Scripting or automation experience (Python, PowerShell) a plus.

Responsibilities

  • Monitor, investigate, and respond to security alerts and incidents across systems, networks, and cloud environments.
  • Perform regular vulnerability assessments, patch verification, and risk remediation tracking.
  • Support security awareness programs and ensure employees adhere to company security policies, procedures and standards.
  • Assist in managing endpoint security tools (EDR, DLP, MDM, etc.) and identity/access management systems.
  • Collaborate with IT, DevOps, and engineering teams to implement secure configurations, code reviews, and cloud security best practices.
  • Conduct periodic access reviews and support audit and compliance efforts (SOC 2, ISO 27001, etc.).
  • Document incident response actions and recommend process improvements.
  • Contribute to risk assessments and control testing for new vendors, applications, and systems.
  • Stay current on emerging threats, vulnerabilities, and regulatory requirements impacting the business.
  • Demonstrate a business-first mindset.

Skills

Security operations
Risk management
Threat detection
Networking fundamentals
Cloud security
SIEM familiarity
Incident response
Compliance standards
Security frameworks
Python scripting

Education

Bachelor's degree in Information Security, CS, or related field

Tools

EDR
DLP
MDM
SAST
DAST
SIEM

Job description

Position Summary

We are seeking a detail-oriented and proactive Information Security Analyst to help strengthen and mature our cybersecurity posture. The ideal candidate has a solid foundation in security operations, risk management, and threat detection, with a passion for continuous improvement and secure innovation. Experience in fintech or other regulated industries (financial services, energy, SaaS) is preferred but not required.

Responsibilities
  • Monitor, investigate, and respond to security alerts and incidents across systems, networks, and cloud environments.
  • Perform regular vulnerability assessments, patch verification, and risk remediation tracking.
  • Support security awareness programs and ensure employees adhere to company security policies, procedures and standards.
  • Assist in managing endpoint security tools (EDR, DLP, MDM, etc.) and identity/access management systems.
  • Collaborate with IT, DevOps, and engineering teams to implement secure configurations, code reviews, and cloud security best practices.
  • Conduct periodic access reviews and support audit and compliance efforts (SOC 2, ISO 27001, etc.).
  • Document incident response actions and recommend process improvements.
  • Contribute to risk assessments and control testing for new vendors, applications, and systems.
  • Stay current on emerging threats, vulnerabilities, and regulatory requirements impacting the business.
  • Demonstrate a business-first mindset.
Qualifications
  • 3–5 years of hands‑on experience in cybersecurity, information security, or IT risk.
  • Strong understanding of networking fundamentals, endpoint protection, and cloud security (AWS, Azure, or GCP).
  • Familiarity with SIEM platforms, SAST, DAST, vulnerability management tools, and incident response processes.
  • Familiarity and experience with common EDR platforms.
  • Knowledge of security frameworks such as NIST CSF, ISO 27001, or CIS Controls.
  • Excellent problem‑solving and communication skills.
  • Bachelor’s degree in Information Security, Computer Science, or related field (or equivalent experience).
  • Experience in fintech, financial services, or other regulated environments.
  • Exposure to compliance standards such as NFA, FCA, SOC 2, or ISO 27001.
  • Relevant certifications (e.g., CompTIA Security+, CySA+, CEH, etc.).
  • Scripting or automation experience (Python, PowerShell) a plus.
Compensation

Compensation for this role will vary among specific regions due to geographic differentials in the labor market; actual pay will be determined considering relevant skills, experience, knowledge, education, and training. However, the compensation range for this role is expected to be as follows: $80,000–$95,000.

EEO Statement

Here at Xpansiv, we cultivate diversity, celebrate individuality, and believe unique perspectives are key to our collective success in building trust and transparency in global efforts toward net‑zero future. Xpansiv is committed to equal employment opportunity regardless of race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, protected veteran status, or any status protected by applicable federal, state, or local law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analyst
Information Security Analyst

Clearcapital • Reno (NV)

On-site
USD 113,800 - 139,000
Comprehensive medical, dental, and vision insurance
401(k) retirement plan with employer match
Paid time off (PTO) and paid holidays
Security Operations Analyst: Threat Detection & Risk
Security Operations Analyst: Threat Detection & Risk

Xpansiv%20 • United States

On-site
USD 80,000 - 95,000
Senior Security Analyst
Senior Security Analyst

Yardi • Santa Barbara (CA)

On-site
USD 97,000 - 110,000
Security Analyst (6-month contract)
Security Analyst (6-month contract)

Cerebras • United States

On-site
Unlimited PTO
Paid parental leave
Mental wellness benefits
+1
Information Security Analyst
Information Security Analyst

ISNetworld • Dallas (TX)

On-site
USD 85,000 - 120,000
100% company-paid medical premiums
Dental, Vision, Life Insurance
401(k) retirement matching
+6
Information Security Analyst
Information Security Analyst

NPAworldwide • City of Syracuse (NY)

On-site
USD 85,000 - 90,000
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Security Operations Engineer
Security Operations Engineer

Reserv • Atlanta (GA)

Hybrid
USD 80,000 - 100,000
Generous health-insurance package
401(k) retirement plan with employer matching
Competitive PTO policy
+1
Information Security Analyst
Information Security Analyst

Family Assist • Town of Norway (WI)

On-site
Security Analyst
Security Analyst

SupportFinity™ • Colorado

On-site
USD 90,000 - 105,000