IT Security and Compliance Analyst

Bristow Group

Georgia

On-site

USD 90,000 - 130,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Bristow Group is seeking an IT Security & Compliance Analyst to support and operationalize its global information security program across aviation operations. The role focuses on security operations, vulnerability management, identity governance, third-party risk, and audit readiness.

You will work with Infrastructure, Applications, and business stakeholders to reduce risk, ensure effective controls, and advance security maturity in global IT environments.

Qualifications

  • Bachelor’s degree in Computer Science, Information Technology, or equivalent professional experience.
  • Security or audit-related certifications preferred (CISSP, CISM, CISA, Security+, SSCP).
  • 3+ years of experience in cybersecurity operations, compliance, vulnerability management, or audit support.
  • Experience supporting incident response, vulnerability remediation, and audit evidence production; experience with third-party providers and regulated environments is desirable.

Responsibilities

  • Monitor, analyze, and investigate security events using SIEM, EDR, email, cloud, and endpoint security tools.
  • Coordinate incident response activities including containment, eradication, recovery, and post-incident reviews.
  • Maintain and improve incident response playbooks and track response metrics and corrective actions.
  • Coordinate vulnerability scanning and validation across infrastructure, endpoint, cloud, and application environments.
  • Prioritize vulnerabilities based on severity, asset criticality, and exploitability.
  • Track remediation SLAs, exceptions, and risk acceptances; report status and trends to stakeholders.
  • Support on-premises and cloud identity platforms and secure authentication controls.
  • Assist joiner/mover/leaver processes, access reviews, and privileged access governance.
  • Support enforcement of MFA, conditional access, and least-privilege principles.
  • Support internal and external audits including SOX ITGC, ISO 27001, NIST CSF, NIST 800-171, and contractual requirements.
  • Maintain audit evidence, control documentation, and test artifacts.
  • Support proactive control monitoring to reduce repeat audit findings.
  • Assist with regulatory readiness including aviation-specific security requirements (e.g., EASA Part-IS).
  • Support supplier security due diligence including questionnaires and review of SOC and ISO artifacts.
  • Track vendor remediation actions and reassessment schedules for higher-risk suppliers.
  • Partner with Procurement and Legal to support security obligations in vendor contracts.
  • Support IT emergency response, disaster recovery, and business continuity planning and exercises.
  • Assist with security awareness initiatives and targeted training programs.

Skills

Information security controls
Operational risk management
Documentation
Analytics
Stakeholder communication

Education

Bachelor’s degree in Computer Science, IT, or equivalent
Security or audit certifications (CISSP, CISM, CISA, Security+, SSCP)

Job description

Job Description:

The IT Security & Compliance Analyst supports and operationalizes the organization’s global information security and compliance program in support of mission-critical, safety-sensitive, and highly regulated aviation operations. The role focuses on improving security operations, vulnerability management, audit readiness, identity governance, third-party risk management, and overall security maturity across global IT environments.

Working closely with Infrastructure & Operations, Applications, and business stakeholders, the Analyst helps reduce enterprise risk, strengthen regulatory compliance, and ensure security controls are effective, repeatable, and defensible.

PRINCIPAL RESPONSIBILITIES:
SECURITY OPERATIONS & INCIDENT RESPONSE
  • Monitor, analyze, and investigate security events using SIEM, EDR, email, cloud, and endpoint security tools.
  • Coordinate incident response activities including containment, eradication, recovery, and post-incident reviews.
  • Maintain and improve incident response playbooks and track response metrics and corrective actions.
VULNERABILITY MANAGEMENT & RISK REDUCTION
  • Coordinate vulnerability scanning and validation across infrastructure, endpoint, cloud, and application environments.
  • Prioritize vulnerabilities based on severity, asset criticality, and exploitability.
  • Track remediation SLAs, exceptions, and risk acceptances; report status and trends to stakeholders.
IDENTITY, ACCESS & SECURITY CONTROLS
  • Support on-premises and cloud identity platforms and secure authentication controls.
  • Assist with joiner/mover/leaver processes, access reviews, and privileged access governance.
  • Support enforcement of MFA, conditional access, and least-privilege principles.
COMPLIANCE, AUDIT & CONTINUOUS READINESS
  • Support internal and external audits including SOX ITGC, ISO 27001, NIST CSF, NIST 800-171, and contractual requirements.
  • Maintain audit evidence, control documentation, and test artifacts.
  • Support proactive control monitoring to reduce repeat audit findings.
  • Assist with regulatory readiness including aviation-specific security requirements (e.g., EASA Part-IS).
THIRD PARTY & SUPPLIER SECURITY
  • Support supplier security due diligence including questionnaires and review of SOC and ISO artifacts.
  • Track vendor remediation actions and reassessment schedules for higher-risk suppliers.
  • Partner with Procurement and Legal to support security obligations in vendor contracts.
RESILIENCE, BUSINESS CONTINUITY & AWARENESS
  • Support IT emergency response, disaster recovery, and business continuity planning and exercises.
  • Assist with security awareness initiatives and targeted training programs.
PERSON SPECIFICATION: (minimum education requirements, key skills and experience)
QUALIFICATIONS:
  • Bachelor’s degree in Computer Science, Information Technology, or equivalent professional experience.
  • Security or audit-related certifications preferred (CISSP, CISM, CISA, Security+, SSCP).
EXPERIENCE:
  • 3+ years of experience in cybersecurity operations, compliance, vulnerability management, or audit support.
  • Practical experience supporting incident response, vulnerability remediation, and audit evidence production.Experience working with third-party service providers and regulated environments is desirable.
SKILLS:
  • Strong understanding of information security controls and operational risk management.
  • Ability to translate security findings into clear remediation actions.
  • Strong documentation, analytical, and stakeholder communication skills.
  • Comfortable operating in regulated, mission-critical operational environments.

Bristow Group is an Equal Opportunity Employer, all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security and Compliance Analyst
IT Security and Compliance Analyst

Bristow Group, Inc. • Houston (TX)

On-site
USD 80,000 - 100,000
Security & Compliance Operations Analyst
Security & Compliance Operations Analyst

Bristow Group, Inc. • Houston (TX)

On-site
USD 80,000 - 100,000
Aviation IT Security & Compliance Specialist
Aviation IT Security & Compliance Specialist

Bristow Group • Georgia

On-site
USD 90,000 - 130,000
IT Security Analyst (USI5)
IT Security Analyst (USI5)

VSE Aviation • Bloomfield (CT), Town of Florida (NY)

On-site
USD 80,000 - 110,000
IT Security Analyst (USI5) (1512)
IT Security Analyst (USI5) (1512)

VSE Aviation • Bloomfield (CT), Town of Florida (NY)

On-site
USD 80,000 - 100,000
Sr. Security Analyst
Sr. Security Analyst

Motion Recruitment • Atlanta (GA)

Hybrid
USD 120,000 - 160,000
Cybersecurity Audit Analyst
Cybersecurity Audit Analyst

Applied Aerospace • Huntsville (AL)

On-site
USD 70,000 - 90,000
Senior Security Analyst
Senior Security Analyst

ACL Digital • Atlanta (GA)

On-site
USD 100,000 - 150,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Ampcus Inc • Washington

On-site
USD 90,000 - 120,000
Information Security Analyst - GRC & Operations
Information Security Analyst - GRC & Operations

WHSmith North America • Las Vegas (NV)

Hybrid
USD 70,000 - 110,000