Senior Information Security Analyst

Vesync Co.

Tustin (CA)

On-site

USD 140,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical/Dental/Vision coverage
401K with employer match
Generous PTO
Life Insurance
Disability Insurance
Travel Assistance
EAP

Job summary

VeSync is seeking a highly skilled Senior Information Security Analyst to protect enterprise data, systems, and hybrid infrastructure in a on-site role in Tustin, CA. You will balance technical execution with strategic planning, develop security plans, establish compliance frameworks, and drive real-time monitoring and risk mitigation.

The role requires 8+ years of information security experience, cloud security expertise (AWS, Azure, GCP), and strong knowledge of NIST CSF, ISO 27001, and CIS.

Qualifications

  • Bachelor's degree in Information Security, Computer Science, or related field.
  • 8+ years of information security experience focusing on event analysis, incident response, vulnerability management, and risk assessment.
  • Hands-on experience with public cloud security and cloud-native tools.
  • Familiarity with NIST CSF, ISO 27001, CIS, GDPR.
  • AWS security suites and SIEM tools experience.
  • Knowledge of IDS/IPS, firewalls, and endpoint protection.
  • Security certifications such as CISSP, CISM, CEH are a plus.

Responsibilities

  • Develop and implement comprehensive information security plans for on‑premise and cloud environments.
  • Create security policies meeting ISO 27001, NIST, GDPR and regulatory requirements.
  • Maintain and enhance security for systems, networks, and cloud platforms (AWS/Azure/GCP).
  • Monitor security events in real‑time, respond to incidents, and mitigate risks.
  • Build and operate a security monitoring platform and run red/blue team exercises.
  • Develop and deliver security training programs for employees.
  • Oversee access controls and regular permission audits.
  • Conduct risk assessments using NIST CSF and define mitigation measures.
  • Document controls and mentor team members.

Skills

Information security
Cloud security
Regulatory compliance
Incident response
Mentoring

Education

Bachelor's degree in Information Security

Tools

AWS
Azure
GCP
Splunk
QRadar
OneTrust
Drata

Job description

The Company:

VeSync is a portfolio company with brands that cover different categories of health & wellness products. We wouldn’t be surprised if you have one of our Levoit air purifiers in your living room or a COSORI air fryer whipping up healthy and delicious meals for you every night.

We’re a young and energetic company, we’ve had tremendous success, and we are constantly growing our team. As we garner more industry attention – just check out our accomplishments and awards by CES Innovation, iF Design, IGA, and Red Dot – we also need driven and talented people to join our team.

That brings us to you, and what you’ll be joining. Our teams are smart and diligent and take ownership of their work – they’re confident in their work but know how to collaborate with open ears and a spirit of learning. If you’re down-to-earth, approachable, and easy to strike up a conversation with, this may be a great fit for you.

Check out our brands:

levoit.com|cosori.com|etekcity.com|pawsync.com

The Opportunity:

We are seeking a highly skilled and strategic Senior Information Security Analyst to spearhead the protection of our enterprise data, systems, and hybrid infrastructure (On-Premise and Multi-Cloud). In this role, you will balance technical execution with strategic planning—developing comprehensive security plans, establishing robust compliance frameworks, and engineering real-time monitoring solutions. As a senior member of the team, you will act as a defender, a strategist, and a mentor, utilizing advanced technologies to mitigate risk, drive security awareness, and foster a culture of continuous improvement.

What you will do at VeSync: Information Security Planning
  • Develop and implement comprehensive information security plans to safeguard the security of company data and assets, including on-premise and cloud environments.
  • Thoroughly analyze the company's business processes and data characteristics, and combine industry best practices and frameworks such as NIST Cybersecurity Framework (CSF)to create customized security plans, ensuring the confidentiality, integrity, and availability of information assets in various scenarios.
Policy Development and Compliance
  • Create security policies and ensure that the company's operations are in strict compliance with industry standards (e.g., ISO 27001, NIST, GDPR) and regulatory requirements.
  • Continuously monitor industry trends and regulatory changes, and adjust security policies in a timely manner to provide a solid security and compliance framework for the company's business operations.
System, Network and Cloud Security
  • Maintain and enhance security measures for systems, networks , and public cloud platforms (e.g., AWS, Azure, GCP) to prevent potential threats.
  • Utilize advanced technical means and tools to conduct real - time monitoring and risk early warning of systems, networks, and cloud environments, promptly detect and block various attack behaviors, and ensure the stable and secure operation of IT infrastructure.
Security Monitoring and Incident Response
  • Monitor security events in real - time, respond promptly to emergencies, and effectively mitigate risks.
  • Build an efficient security monitoring platform, use intelligent analysis technology to promptly capture abnormal behaviors, activate emergencyresponse plans, and minimize the impact of security incidents.
  • Conduct red/blue team exercise .
Security Awareness and Training
  • Develop and deliver security training programs to enhance employees' security awareness and encourage their adherence to best practices.
  • Design targeted training courses according to the needs of different positions and use diverse training methods to ensure that employees have a deep understanding of and implement security requirements.
Access Control and Identity Management
  • Oversee user access controls, regularly review permissions, and ensure secure identity management.
  • Implement a strict access control mechanism, Conduct regular audits of user permissions, and use reliable identity management systems to prevent unauthorized access and ensure the security of company resources.
Risk Assessment and Management
  • Conduct comprehensive risk assessments, identify vulnerabilities, and implement effective mitigation strategies.
  • Use scientific risk assessment methods and frameworks such as NIST CSF to evaluate potential threats and vulnerabilities, formulate corresponding mitigation measures based on the assessment results, and continuously improve the company's security defense capabilities.
  • Develop risk KPIs and metrics .
Documentation and Mentorship
  • Document Cyber Security controls, detection rules and playbooks.
  • Mentor team members .
What you bring to the role:
  • Bachelor’s degree in Information Security, Computer Science, or a related field.
  • 8+ years of experience in information security, with a strong background in security event analysis, incident response, vulnerability management, and risk assessment.
  • Hands-on experience with public cloud security (e.g., AWS, Azure, GCP), including cloud-native security tools and best practices.
  • Familiarity with security regulatory compliance standards and frameworks such as NIST CSF, ISO 27001, and CIS.
  • Familiar with AWS security suites
  • Familiar with security scorecards, SIEM tools and dashboards (Splunk, QRadar, Rapid7, Wazhu)
  • Experience with OneTrust, Drata or similiar tools
  • Knowledge of network security principles, intrusion detection/prevention systems (IDS/IPS), firewalls, and endpoint protection.
  • Understanding these aspects is essential for ensuring the company's security compliance and building a robust security defense system.
  • Strong analytical and problem - solving skills, with the ability to quickly identify and mitigate security threats.
  • Relevant security certifications such as CISSP, CISM, CEH are a plus.
Location:
  • This is an on-site, office-based role in Tustin, CA.
Salary:
  • Starting at $160K
Perks and Benefits:
  • 100% covered Medical/Dental/Vision insurance for employee AND spouse + dependents!
  • 401K with 4% employer match (eligible after 90 days of employment) and immediate 100% vesting
  • Generous PTO policy + paid holidays
  • Life Insurance
  • Voluntary Life Insurance
  • Disability Insurance
  • Critical Illness Coverage
  • Accident Insurance
  • Healthcare FSA
  • Dependent Care FSA
  • Travel Assistance Program
  • Employee Assistance Program (EAP)
  • Fully stocked kitchen
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security Analyst
Senior Information Security Analyst

Vesync • Tustin (CA)

On-site
100% covered Medical/Dental/Vision insurance
401K with 4% employer match
Generous PTO policy
+5
Information Security Analyst
Information Security Analyst

Vesync • Tustin (CA)

On-site
USD 120,000 - 144,000
Medical/Dental/Vision insurance for员工和
401K with employer match
Generous PTO
+5
Lead IT & Privacy Auditor - U.S. Privacy and Data Security Audit
Lead IT & Privacy Auditor - U.S. Privacy and Data Security Audit

Vesync • Tustin (CA)

On-site
USD 108,000 - 132,000
100% covered Medical/Dental/Vision for
401K with 4% employer match
Generous Sick + Vacation
+6
Manager of Marketing Analytics and Ops
Manager of Marketing Analytics and Ops

VeSync • Tustin (CA)

On-site
USD 150,000
100% covered Medical/Dental/Vision ins
401K with 4% employer match
Generous PTO policy + holidays
+10
Senior Product Counsel – Health
Senior Product Counsel – Health

Vesync • Tustin (CA)

On-site
100% covered Medical/Dental/Vision insurance
401K with 4% employer match
Generous PTO policy
+3
Manager of Marketing Analytics and Ops
Manager of Marketing Analytics and Ops

Socket.dev • Tustin (CA)

On-site
USD 150,000 - 173,000
Medical/Dental/Vision insurance for is
401K with employer match
Paid time off
+6
Account Manager – Target and Best Buy
Account Manager – Target and Best Buy

Vesync • Tustin (CA)

On-site
USD 68,000 - 83,000
Medical/Dental/Vision insurance
401K with company match
Generous PTO
+6
Sr. Product Marketing Manager (Retail)
Sr. Product Marketing Manager (Retail)

Vesync • Tustin (CA)

On-site
USD 148,500 - 181,500
100% covered Medical/Dental/Vision insurance for employee AND spouse + dependents
401K with 4% employer match
Generous PTO policy + paid holidays
+5
Senior Visual Designer
Senior Visual Designer

Vesync • Tustin (CA)

On-site
100% covered Medical/Dental/Vision insurances for employee and dependents
401K with 4% employer match
Generous PTO policy
+3
Senior UX Researcher
Senior UX Researcher

VeSync • Tustin (CA)

On-site
USD 120,000 - 138,000
100% covered Medical, Dental, and Vision insurance
401K with 4% employer match
Generous PTO policy
+1