Security Analyst

Perfict

Massachusetts

On-site

USD 120,000 - 170,000

Full time

16 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Perfict in Massachusetts seeks an experienced cybersecurity risk leader to conduct assessments across cloud, applications, infrastructure, and AI systems, coordinating remediation with IT and business teams. You will evaluate controls, incidents, and threats, and document risk-based mitigation plans aligned with established frameworks.

The role supports audits, reporting, and governance activities, leveraging Purview and Defender tools to enforce data protection and compliance.

Qualifications

  • Knowledge of vulnerability management, incident response, SIEM, DLP, and GRC platforms.
  • Experience evaluating security controls and developing remediation or risk mitigation plans.
  • Strong understanding of cloud security principles and enterprise cybersecurity practices.
  • Excellent analytical, written, verbal, and stakeholder communication skills.
  • Ability to work effectively with both technical and non-technical teams.
  • 6+ years of experience in cybersecurity, IT risk, security engineering, information security, or a related discipline.
  • Strong understanding of cybersecurity risk management and security governance.
  • Hands-on experience with frameworks and standards such as NIST, ISO 27001, FFIEC, and PCI DSS.
  • Experience performing security and risk assessments across applications, infrastructure, cloud environments, and third-party vendors.

Responsibilities

  • Perform cybersecurity risk assessments covering cloud environments, applications, infrastructure, AI technologies, and third-party vendors.
  • Assess security controls, vulnerabilities, incidents, and emerging threats and develop risk-based mitigation recommendations.
  • Support vulnerability management, incident response, security audits, regulatory compliance, and cybersecurity risk reporting.
  • Partner with IT and business stakeholders to identify security gaps and recommend governance and control improvements.
  • Apply established cybersecurity frameworks and industry standards to evaluate and document security risks.
  • Assist with GRC activities, including risk tracking, control assessments, remediation monitoring, and compliance documentation.
  • Leverage Microsoft Purview and Microsoft security technologies to support data protection, compliance, and risk management initiatives.
  • Review security findings and translate technical risks into clear business-level recommendations.
  • Collaborate with internal teams and third-party partners to monitor remediation activities and ensure security requirements are addressed.
  • Stay informed on emerging cybersecurity threats, regulatory requirements, and industry best practices.

Skills

Vulnerability management
Incident response
GRC platforms
Cloud security
Stakeholder communication
Risk assessment
Frameworks & standards

Education

CISSP
CISM
CRISC
CISA

Tools

SIEM
DLP
GRC platforms
Microsoft Purview
Microsoft Defender

Job description

  • Perform cybersecurity risk assessments covering cloud environments, applications, infrastructure, AI technologies, and third-party vendors.
  • Assess security controls, vulnerabilities, incidents, and emerging threats and develop risk-based mitigation recommendations.
  • Support vulnerability management, incident response, security audits, regulatory compliance, and cybersecurity risk reporting.
  • Partner with IT and business stakeholders to identify security gaps and recommend appropriate governance and control improvements.
  • Apply established cybersecurity frameworks and industry standards to evaluate and document security risks.
  • Assist with GRC activities, including risk tracking, control assessments, remediation monitoring, and compliance documentation.
  • Leverage Microsoft Purview and Microsoft security technologies to support data protection, compliance, and risk management initiatives.
  • Review security findings and translate technical risks into clear business-level recommendations.
  • Collaborate with internal teams and third-party partners to monitor remediation activities and ensure security requirements are addressed.
  • Stay informed on emerging cybersecurity threats, regulatory requirements, and industry best practices.
Required Qualifications
  • Knowledge of vulnerability management, incident response, SIEM, DLP, and GRC platforms.
  • Experience evaluating security controls and developing remediation or risk mitigation plans.
  • Strong understanding of cloud security principles and enterprise cybersecurity practices.
  • Excellent analytical, written, verbal, and stakeholder communication skills.
  • Ability to work effectively with both technical and non-technical teams.
  • 6+ years of experience in cybersecurity, IT risk, security engineering, information security, or a related discipline.
  • Strong understanding of cybersecurity risk management and security governance.
  • Hands-on experience with frameworks and standards such as NIST, ISO 27001, FFIEC, and PCI DSS.
  • Experience performing security and risk assessments across applications, infrastructure, cloud environments, and third-party vendors.
Preferred Qualifications
  • Experience with Microsoft Purview and Microsoft Defender.
  • Experience supporting cybersecurity compliance and audit programs.
  • Familiarity with AI security and emerging technology risk.
  • Certifications such as CISSP, CISM, CRISC, or CISA.
  • Experience working in regulated environments or highly controlled enterprise organizations.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer
Senior Cloud Security Engineer

Maestro Technologies, Inc. • Santa Monica (CA)

Hybrid
USD 150,000 - 210,000
Application Security Engineer
Application Security Engineer

Xforia Global Talent & Technology Solutions • Town of Texas (WI)

On-site
USD 140,000 - 180,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Eleven Recruiting • Santa Monica (CA)

On-site
USD 140,000 - 190,000
Information Technology Security Analyst
Information Technology Security Analyst

The Phoenix Group • New York (NY)

On-site
USD 80,000 - 120,000
Data Privacy and Compliance Analyst
Data Privacy and Compliance Analyst

Comtech LLC • Atlanta (GA)

On-site
USD 80,000 - 100,000
Information Security Analyst
Information Security Analyst

Cobalt Benefits Group LLC • Manchester (NH)

On-site
USD 85,000 - 110,000
Senior Information Security Analyst
Senior Information Security Analyst

Teamware Solutions Inc • Woburn (MA)

Hybrid
USD 120,000 - 170,000
Cyber Security Analyst
Cyber Security Analyst

Green Key Resources • Melville (NY)

On-site
USD 70,000 - 95,000
Cyber Security Engineer
Cyber Security Engineer

FutureRecruit.net • New York (NY)

On-site
USD 90,000 - 130,000
IT Security Analyst
IT Security Analyst

Cache Valley Electric • Salt Lake City (UT)

On-site
USD 75,000 - 115,000