IT Security Analyst

Fortegra

Jacksonville (FL)

On-site

USD 85,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Fortegra seeks a Security Analyst to lead day-to-day security operations across on‑premises, cloud, and SaaS environments. You’ll drive investigations, containment, and remediation for incidents and partner with engineering to bake security into the software lifecycle, including AI governance and risk controls.

You will design and tune detections, perform tabletop exercises, and oversee secure deployments with IAM, CSPM, and zero-trust initiatives to reduce risk across the organization.

Qualifications

  • Bachelor’s degree in Computer Science or Information Security, or equivalent experience.
  • 2+ years in Information Security or Security Analyst roles.
  • Strong working knowledge of NIST CSF, NIST 800-53, ISO 27001, CIS controls, MITRE ATT&CK.
  • Hands-on with at least one major cloud provider (AWS, Azure, or GCP).
  • Experience embedding security into CI/CD pipelines (SAST, DAST, SCA, IaC scanning).
  • Experience with vulnerability remediation across endpoints, servers, cloud workloads.

Responsibilities

  • Monitor and tune security solutions (SIEM, EDR/XDR, SOAR, email security, DLP, CSPM).
  • Lead investigations into security incidents beyond Tier 1; triage, containment, eradication, recovery.
  • Develop and tune detections aligned to MITRE ATT&CK and threat models.
  • Conduct tabletop exercises, purple-team engagements, and incident drills annually.
  • Maintain runbooks and playbooks for incident types including AI/LLM incidents.

Skills

Security analytics
Cloud security
Incident response
CI/CD security integrations
Threat modeling

Education

Bachelor's degree or equivalent

Tools

SIEM
EDR/XDR
SOAR
DLP
CSPM

Job description

Responsible for safeguarding confidentiality, integrity, and availability of data, applications, infrastructure, and AI systems across the organization. The Security Analyst leads day‑to‑day operations of the company’s security tooling across on‑premises, cloud, and SaaS environments, drives the identification, investigation, and resolution of security events, and partners with engineering and operations teams to embed security throughout the software development and deployment lifecycle. The role also helps the organization securely adopt, deploy, and govern AI technologies.

Primary Job Functions
Security Operations & Incident Response
  • Monitor and tune in‑place security solutions (SIEM, EDR/XDR, SOAR, email security, DLP, CSPM) for efficient and appropriate operation.
  • Lead investigations into security incidents escalated beyond Tier 1, including triage, forensic analysis, containment, eradication, and recovery.
  • Develop, maintain, and tune detections (e.g., SIEM rules, EDR custom detections) aligned to MITRE ATT&CK and the organization’s threat models.
  • Conduct and participate in tabletop exercises, purple‑team engagements, and incident management drills at least annually.
  • Maintain runbooks and playbooks for common incident types, including cloud, identity, ransomware, and AI/LLM‑related incidents.
Vulnerability & Threat Management
  • Lead vulnerability remediation across endpoints, servers, cloud workloads, containers, and SaaS applications, working with infrastructure and engineering teams to drive risk down.
  • Design and execute vulnerability assessments, penetration tests, red‑team exercises, and security audits; manage findings through to closure.
  • Maintain hardened, up‑to‑date baselines (CIS Benchmarks or equivalent) for workstations, servers, cloud resources, containers, and network devices.
  • Consume and operationalize threat intelligence to anticipate and defend against new attacks and threat vectors.
  • Design, implement, and review security controls across cloud environments including IAM, network segmentation, encryption, logging, and posture management (CSPM/CNAPP).
  • Advance the organization’s Zero Trust strategy across identity, device, network, application, and data layers.
  • Review Infrastructure‑as‑Code manifests for security misconfigurations; help maintain policy‑as‑code guardrails.
  • Partner with IT and identity teams on IAM, SSO, MFA, privileged access management, and conditional access policies.
Application & Software Supply Chain Security
  • Partner with the CISO and engineering leadership to enforce secure coding practices; deliver annual secure‑development training, including OWASP Top 10 and OWASP LLM Top 10 content.
  • Integrate and tune security testing in CI/CD pipelines: SAST, DAST, SCA, secret scanning, container image scanning, and IaC scanning.
  • Establish and maintain software supply chain controls, including SBOM generation, dependency review, and alignment with frameworks such as SLSA.
  • Lead threat‑modeling sessions for new products, services, and AI‑enabled features.
AI Security & Governance
  • Help define and enforce policies for the safe adoption and use of AI tools within the organization, including LLM‑based assistants, agentic systems, and Model Context Protocol (MCP) or similar tool integrations.
  • Assess and mitigate risks specific to AI/ML systems the organization builds or consumes, including prompt injection, jailbreaks, insecure output handling, training‑data and model integrity, sensitive‑data leakage, and model/identity supply‑chain risks.
  • Apply AI security frameworks (OWASP LLM Top 10, MITRE ATLAS, NIST AI Risk Management Framework, ISO/IEC 42001 concepts) when evaluating AI vendors, internal AI products, and AI‑generated code.
  • Review AI‑generated code for security vulnerabilities and licensing issues before it reaches production.
  • Partner with Legal, Privacy, and Engineering on AI data handling, retention, and disclosure practices.
AI‑Augmented Security Operations & Tooling
  • Evaluate and deploy AI‑assisted security tooling (e.g., LLM‑powered alert triage, log summarization, threat‑intel enrichment, phishing analysis, AI‑assisted code review) to improve analyst productivity and reduce mean time to detect/respond.
  • Build lightweight automations and scripts (Python, PowerShell, or similar), leveraging AI coding assistants where appropriate, to streamline detection, response, and reporting workflows.
  • Prepare for and respond to internal and external IT audits and risk assessments (GDPR, DORA, PCI DSS, HIPAA, GDPR/CCPA, as applicable).
  • Maintain awareness of applicable laws and regulations related to security, data privacy, and AI (including emerging AI regulation).
  • Recommend new or enhanced security solutions and assist with their deployment, integration, and configuration in line with the organization’s security standards.
  • Maintain up‑to‑date knowledge of the security industry, including new attack techniques, defensive tooling, and AI‑related threats and defenses.
Minimum Qualifications
  • Bachelor’s degree in Computer Science, Information Security, or a related technical field, OR equivalent professional experience.
  • 2+ years of experience in Information Security, Security Analyst, or closely related role.
  • Working knowledge of common cybersecurity frameworks (NIST CSF, NIST 800‑53, ISO 27001, CIS Controls, MITRE ATT&CK).
  • Hands‑on experience securing at least one major cloud provider (AWS, Azure, or GCP), including identity, network, and workload controls.
  • Experience with vulnerability management, patching, and remediation across servers, endpoints, containers, and cloud workloads.
  • Experience integrating security into CI/CD pipelines (SAST, DAST, SCA, secret scanning, IaC scanning).
  • Incident response experience, including triage, containment, eradication, recovery, and post‑incident review.
Licensure, Certification, and/or Registration
  • One or more of the following preferred: Security+, CySA+, GIAC (e.g., GSEC, GCIH, GCFA, GCSA), OSCP, SC‑900.
  • AI/ML security credentials (e.g., AI Security/Governance certifications) a plus.

Applicants must be authorized to work for any employer in the United States. We are unable to sponsor or assume sponsorship of employment visas at this time. We welcome applicants of all backgrounds and national origins.

Equal Opportunity Employer. This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security AI Engineer
Senior Security AI Engineer

Imperial PFS • Kansas City (MO)

On-site
USD 130,000 - 160,000
Senior Security AI Engineer
Senior Security AI Engineer

IPFS Corporation • Kansas City (MO)

On-site
USD 120,000 - 150,000
Information Technology Security Analyst
Information Technology Security Analyst

Brooksource • Allentown

On-site
USD 75,000 - 95,000
Information Security Application and Compliance Analyst
Information Security Application and Compliance Analyst

Vinson & Elkins • Houston (TX)

On-site
USD 110,000 - 150,000
Information Security Analyst
Information Security Analyst

Compunnel, Inc. • Charlotte (NC)

On-site
USD 80,000 - 120,000
Information Security Application and Compliance Analyst - Austin, Dallas, Houston
Information Security Application and Compliance Analyst - Austin, Dallas, Houston

Vinson & Elkins • Dallas (TX)

On-site
USD 110,000 - 160,000
Senior AI DevSecOps Engineer
Senior AI DevSecOps Engineer

Jobtailor • Kansas

On-site
USD 120,000 - 180,000
AI Security Analyst-- BHADC5698041
AI Security Analyst-- BHADC5698041

Compunnel Inc. • United States

On-site
USD 70,000 - 90,000
Information Security Engineer
Information Security Engineer

Dealer Tire • United States

On-site
USD 120,000 - 155,000
Security Engineer
Security Engineer

CRICO • Boston (MA)

On-site
USD 90,000 - 130,000