Job Title: Senior Information Security Analyst
Location: Woburn, MA
Work Arrangement: Hybrid / On-site as required
Duration: Temp-to-Perm
Experience: 6 9 years
Candidate Preference: Local candidates preferred; relocation candidates will be considered
Job Summary
Seeking a
Senior Information Security Analyst with 6 9 years of experience in
information security, cybersecurity risk management, security engineering, or IT risk management, preferably within a regulated industry.
The ideal candidate will have strong expertise in
cybersecurity risk, governance, security frameworks, architecture reviews, and risk assessments, along with hands-on experience with
Microsoft Purview and Microsoft Defender.
This role is ideal for someone who is naturally
curious, hands-on, proactive, and comfortable identifying security gaps, evaluating new technologies, and solving evolving cybersecurity challenges.
Key Responsibilities
- Perform cybersecurity risk assessments, risk analysis, and control evaluations.
- Act as a Subject Matter Expert (SME) for cybersecurity standards, frameworks, policies, and controls.
- Conduct security architecture reviews when onboarding new applications, technologies, and systems.
- Perform threat modeling and evaluate security risks associated with new applications and technologies.
- Identify security gaps and provide practical, risk-based recommendations for remediation.
- Partner with IT, security, business, and leadership teams to improve the organization's security posture.
- Support the adoption and implementation of Microsoft Purview for data governance, protection, compliance, and security.
- Work with Microsoft Defender and related security capabilities.
- Support cloud security, endpoint protection, and Data Loss Prevention (DLP) initiatives.
- Work with SIEM solutions, vulnerability management platforms, and incident response processes.
- Support and enhance the organization's in-house GRC platform, particularly from the IT/security perspective.
- Help enhance existing GRC modules, workflows, controls, and processes.
- Work with GRC platforms such as Archer, ServiceNow IRM, RiskConnect, or similar solutions.
- Evaluate the cybersecurity implications of Artificial Intelligence (AI) tools and technologies, including data protection, threat detection, automation, and third-party risks.
- Stay current with emerging technologies and evolving cybersecurity threats.
- Collaborate with technical teams and business stakeholders to implement effective security controls and governance practices.
Must-Have Skills
- 6 9 years of experience in information security, cybersecurity risk, security engineering, IT risk, or a related discipline.
- Strong experience with Microsoft Purview.
- Strong experience with Microsoft Defender.
- Strong understanding of cybersecurity risk management and governance.
- Experience with security assessments, risk analysis, threat modeling, and/or architecture reviews.
- Experience working with GRC platforms or GRC environments.
- Strong knowledge of cybersecurity standards and frameworks.
- Excellent communication and stakeholder-management skills.
- Ability to identify gaps independently and provide practical security recommendations.
- Strong curiosity and willingness to learn new technologies.
Security Frameworks
Strong understanding of one or more of the following:
- NIST Cybersecurity Framework (CSF)
- ISO 27001
- COBIT
- FFIEC
- PCI DSS
Preferred Technical Experience
- Microsoft Purview
- Microsoft Defender
- SIEM platforms
- Vulnerability management tools
- Data Loss Prevention (DLP)
- Cloud security
- Endpoint protection
- GRC platforms such as: Archer, ServiceNow IRM, RiskConnect, Other enterprise GRC platforms.
GRC Experience
The client is open to candidates with experience in
any enterprise GRC platform. Specific experience with Archer, ServiceNow IRM, or RiskConnect is preferred but not mandatory.
The candidate should be able to work from the
IT/security side of GRC, including enhancing existing modules, workflows, controls, and processes within an in-house GRC environment.
AI & Emerging Technology
- Familiarity with AI tools and their cybersecurity implications.
- Understanding of AI-related data protection and privacy risks.
- Awareness of AI-enabled threat detection and security automation.
- Understanding of third-party and vendor risks associated with AI technologies.
- Ability to evaluate emerging technologies and identify potential security gaps.
Education & Certifications
- Bachelor's degree in Information Security, Computer Science, Cybersecurity, or a related field preferred.
- Master's degree is a plus.
- Relevant certifications are strongly preferred, such as: CISSP, CISM, CRISC, CISA.
Teamware Solutions, a business division of Quantum Leap Consulting Private Limited, offers cutting edge industry solutions for deriving business value for our clients'? IT initiatives. Offering deep domain expertise in Banking, Financial Services and Insurance, Oil and Gas, Infrastructure, Manufacturing, Retail, Telecom and Healthcare industries, Teamware leads its service in offering skills augmentation and professional consulting services. With over 1700 professionals deputed across India, USA, Middle East and APAC, our major clients include Captive IT units in North America, India, Product Companies and IT Services firms. Our Vision Our Vision is to be among the top 10 largest global Professional Services firm in the Information Technology Space; we aim to achieve this by 2023, when we complete 20 years.