Senior Cybersecurity Analyst

ISO New England

Holyoke (MA)

Hybrid

USD 135,000 - 168,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Stable workplace
Competitive salary
401(k) plan
Tuition reimbursement
Wellness program
Flexible hours
Employee networks
Onsite coffee
Hybrid work 3 days onsite
Relocation assistance

Job summary

ISO New England is seeking an experienced Cybersecurity Analyst to support and enhance enterprise cloud, infrastructure, AI, and DevSecOps security initiatives. This role advances the organization’s cybersecurity strategy through cross-functional collaboration, strengthening governance, risk management, and regulatory compliance.

The ideal candidate has strong experience in cloud security, vulnerability management, DevSecOps, AI security, network security, and security compliance, with the

Qualifications

  • 5+ years of experience in cybersecurity, security engineering, or AI security roles.
  • 3+ years of security experience in AWS and/or Azure cloud platforms.
  • Experience designing and implementing enterprise security solutions across cloud, infrastructure, applications, and hybrid environments.
  • Hands-on experience with AWS and/or Azure cloud platforms, including IAM, CSPM, CIEM, container security, and cloud security best practices.
  • Experience integrating security controls into CI/CD pipelines and DevSecOps environments.
  • Knowledge of AI security concepts, including Generative AI, LLM security, AI governance, and AI risk management.
  • Experience performing vulnerability management, security assessments, configuration reviews, threat modeling, and cybersecurity risk assessments.
  • Knowledge of enterprise security technologies including SIEM, EDR/XDR, CNAPP, DSPM, vulnerability management, identity and access management, encryption, and security monitoring platforms.
  • Familiarity with cybersecurity frameworks and regulatory standards including NERC CIP, NIST Cybersecurity Framework, NIST Special Publication 800 Series, ISO 27001, CIS Controls, and applicable regulatory requirements.
  • Strong analytical, troubleshooting, communication, documentation, and cross-functional collaboration skills.
  • Ability to manage multiple priorities independently while providing technical leadership and driving continuous security improvements.
  • Experience with API security practices, including secure API design, authentication and authorization mechanisms, access control, encryption, and protection against API-based threats.

Responsibilities

  • Develop and implement enterprise cybersecurity strategies aligned with business objectives, regulatory requirements, and industry best practices.
  • Ensure compliance with cybersecurity frameworks and regulations including NERC CIP, NIST frameworks, CIS controls, FERC regulations, and SOC1/SOC2 requirements.
  • Implement enterprise security controls across cloud, infrastructure, applications, AI/ML environments, and regulated OT systems.
  • Conduct cloud security assessments across AWS and Azure environments, including IAM, CSPM, CIEM, container security, and configuration management.
  • Integrate security controls throughout CI/CD pipelines and DevSecOps processes, including automated vulnerability scanning, IaC validation, and policy enforcement.
  • Assess and secure AI/ML systems, Generative AI applications, and LLM integrations through governance, access controls, data protection, prompt security, and AI threat modeling.
  • Perform vulnerability assessments, network security assessments, configuration reviews, compliance validation, risk assessments, and remediation tracking across enterprise and cloud environments.
  • Support enterprise security monitoring, logging, threat detection, incident response, and audit evidence collection using SIEM, EDR/XDR, CNAPP, DSPM, vulnerability management, and related security platforms.
  • Collaborate with cloud, infrastructure, application development, enterprise architecture, IAM, network, compliance, and business teams to integrate security into system design and operational processes.
  • Identify, assess, prioritize, and communicate cybersecurity risks while developing effective mitigation strategies.
  • Develop and maintain security policies, standards, governance documentation, compliance reporting, and security best practices.
  • Monitor emerging cybersecurity threats, AI security risks, industry trends, and regulatory changes to continuously enhance the organization’s security posture.
  • Provide technical mentorship, and cross-functional guidance while promoting cybersecurity awareness, operational excellence, and secure technology adoption.

Skills

Cloud security
Vulnerability management
DevSecOps
AI security
Network security
Regulatory compliance
Security governance
Threat modeling
Cross-functional collaboration
Incident response

Tools

AWS
Azure
CIEM
CSPM
EDR/XDR
CNAPP
DSPM

Job description

ISO New England is seeking an experienced Cybersecurity Analyst to support and enhance enterprise cloud, infrastructure, AI, and DevSecOps security initiatives. This role is responsible for advancing the organization’s cybersecurity strategy by facilitating cross-functional collaboration to strengthen technical security, governance, risk management, and regulatory compliance. The position provides technical leadership and cybersecurity expertise to support evolving business objectives while addressing emerging cyber threats across enterprise, cloud, AI, DevSecOps, and regulated environments. Working closely with internal stakeholders, the role drives security initiatives, influences technical decisions, and promotes a culture of security, resilience, and continuous improvement.


The ideal candidate will have strong experience in cloud security, vulnerability management, DevSecOps, AI security, network security and security compliance, with the ability to collaborate across technical teams to implement and maintain enterprise security standards


What we offer you:


  • A stable, mission-driven workplace where your impact truly matters

  • A highly engaged work environment that values inclusion, collaboration, and employee safety and wellbeing

  • Competitive compensation with a base salary + performance bonus

  • Robust benefits package, including:

    • Enhanced 401(k) and financial planning support

    • Tuition reimbursement and professional development

    • Wellness programs, including an onsite gym

    • Flexible work hours

    • Employee Business Networks



  • Free coffee at our onsite café

  • Hybrid work environment (3 days/week onsite)

  • Distance-based relocation assistance available


How you will make an Impact


  • Develop and implement enterprise cybersecurity strategies aligned with business objectives, regulatory requirements, and industry best practices.

  • Ensure compliance with cybersecurity frameworks and regulations including NERC CIP, NIST frameworks, CIS controls, FERC regulations, and SOC1/SOC2 requirements.

  • Implement enterprise security controls across cloud, infrastructure, applications, AI/ML environments, and regulated operational technology (OT) systems.

  • Conduct cloud security assessments across AWS and Azure environments, including IAM, CSPM, CIEM, container security, and configuration management.

  • Integrate security controls throughout CI/CD pipelines and DevSecOps processes, including automated vulnerability scanning, Infrastructure-as-Code (IaC) validation, and policy enforcement.

  • Assess and secure AI/ML systems, Generative AI applications, and Large Language Model (LLM) integrations through governance, access controls, data protection, prompt security, and AI threat modeling.

  • Perform vulnerability assessments, network security assessments, configuration reviews, compliance validation, risk assessments, and remediation tracking across enterprise and cloud environments.

  • Support enterprise security monitoring, logging, threat detection, incident response, and audit evidence collection using SIEM, EDR/XDR, CNAPP, DSPM, vulnerability management, and related security platforms.

  • Collaborate with cloud, infrastructure, application development, enterprise architecture, IAM, network, compliance, and business teams to integrate security into system design and operational processes.

  • Identify, assess, prioritize, and communicate cybersecurity risks while developing effective mitigation strategies.

  • Develop and maintain security policies, standards, governance documentation, compliance reporting, and security best practices.

  • Monitor emerging cybersecurity threats, AI security risks, industry trends, and regulatory changes to continuously enhance the organization’s security posture.

  • Provide technical mentorship, and cross-functional guidance while promoting cybersecurity awareness, operational excellence, and secure technology adoption.


What we are looking for


  • 5+ years of experience in cybersecurity, security engineering, or AI security roles.

  • 3+ years of security experience in AWS and/or Azure cloud platforms.

  • Experience designing and implementing enterprise security solutions across cloud, infrastructure, applications, and hybrid environments.

  • Hands-on experience with AWS and/or Azure cloud platforms, including IAM, CSPM, CIEM, container security, and cloud security best practices.

  • Experience integrating security controls into CI/CD pipelines and DevSecOps environments.

  • Knowledge of AI security concepts, including Generative AI, LLM security, AI governance, and AI risk management.

  • Experience performing vulnerability management, security assessments, configuration reviews, threat modeling, and cybersecurity risk assessments.

  • Knowledge of enterprise security technologies including SIEM, EDR/XDR, CNAPP, DSPM, vulnerability management, identity and access management, encryption, and security monitoring platforms.

  • Familiarity with cybersecurity frameworks and regulatory standards including NERC CIP, NIST Cybersecurity Framework, NIST Special Publication 800 Series, ISO 27001, CIS Controls, and applicable regulatory requirements.

  • Strong analytical, troubleshooting, communication, documentation, and cross-functional collaboration skills.

  • Ability to manage multiple priorities independently while providing technical leadership and driving continuous security improvements.

  • Experience with API security practices, including secure API design, authentication and authorization mechanisms, access control, encryption, and protection against API-based threats.


Desired not required


  • 5+ years of cybersecurity experience.

  • Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related field.

  • Advanced degree such as a Master’s in Cybersecurity Management, Information Assurance, Artificial Intelligence, or related field.

  • Industry cybersecurity, cloud security, and AI security certifications, including:

    • ISC2 Certified Information Systems Security Professional (CISSP)

    • ISACA Certified Information Security Manager (CISM)

    • Amazon Web Services Certified Security – Specialty

    • Microsoft Azure Security Engineer Associate (AZ-500)

    • ISC2 Certified in AI Security (when available)

    • OWASP AI Security and LLM Security knowledge/training




This employer will not sponsor applicants for work visas for this position (ex: H-1B, F-1/CPT/OPT, O-1, E-3, TN, J, etc.).


The expected salary range for this position is $135,000 - $168,000per year. This role is also eligible for an annual performance bonus, comprehensive health insurance (medical, dental and vision), flexible spending and health savings accounts, a 401(k) plan with generous employer contributions and a student debt benefit, life and AD&D insurance, disability insurance, critical illness and hospital indemnity benefits, paid time off, paid leave, a wellness program, an employee assistance program and other great company perks.


#LI-HYBRID

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

ISO New England Inc. • Holyoke (MA)

Hybrid
USD 135,000 - 168,000
Performance bonus
Enhanced 401(k) and financial planning
Tuition reimbursement
+6
Senior Cyber Security Analyst – Cloud, DevSecOps & AI Security
Senior Cyber Security Analyst – Cloud, DevSecOps & AI Security

ISO New England Inc. • Holyoke (MA)

Hybrid
USD 127,000 - 150,000
Hybrid work arrangement (3 days onsite
Relocation assistance
Onsite gym and wellness programs
+1
Cloud Engineer
Cloud Engineer

Tata Consultancy Services • New London (NH)

On-site
USD 150,000 - 180,000
Annual incentive
Medical coverage
Parental leave
+6
Senior Security Engineer – Hybrid (4649)
Senior Security Engineer – Hybrid (4649)

Hireclout • Los Angeles (CA)

On-site
USD 180,000 - 200,000
Competitive compensation package
Equity participation
100% covered medical, dental, and vision coverage
+5
Cybersecurity Analyst
Cybersecurity Analyst

TurnPoint Services • Louisville (KY)

On-site
USD 70,000 - 100,000
Senior Staff Engineer - DevSecOps
Senior Staff Engineer - DevSecOps

Exelixis Inc • Alameda (CA)

On-site
USD 154,500 - 220,500
401(k) plan with company contributions
Group medical, dental, and vision coverage
Flexible spending accounts
+1
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Leeds Professional Resources • Chicago (IL)

On-site
USD 110,000 - 150,000
Cybersecurity Engineer (DevSecOps)
Cybersecurity Engineer (DevSecOps)

STC, an Arcfield Company • Home Creek (VA)

On-site
USD 101,000 - 199,000
Security / AI Cloud Engineer
Security / AI Cloud Engineer

Cyber 74, LLC • Connecticut

Hybrid
USD 110,000 - 130,000
Remote work option
Flexible schedules
Company provided training
+3
Cybersecurity Engineer (DevSecOps)
Cybersecurity Engineer (DevSecOps)

Arcfield • Home Creek (VA)

On-site
USD 120,000 - 170,000
Health Insurance
Life Insurance
Paid Time Off
+6