Senior InfoSec Analyst

Kforce Inc

Woburn (MA)

On-site

USD 120,000 - 180,000

Full time

9 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Kforce Inc. in Woburn, MA, seeks a Senior Information Security Analyst to bolster a regulated cybersecurity program. You will lead enterprise risk assessments, evaluate controls, and advise on governance across IT, Legal, and Compliance teams.

Ideal candidates have 6–9 years in information security, hands-on Purview/Defender experience, and familiarity with NIST CSF, PCI DSS, and ISO 27001. This role offers growth within a mature GRC environment.

Qualifications

  • 6–9 years of experience in information security or IT risk management.
  • Hands-on with Microsoft Purview and Defender.
  • Knowledge of NIST CSF, FFIEC, PCI DSS, ISO 27001, COBIT.

Responsibilities

  • Lead and execute enterprise-wide risk assessments across applications, infrastructure, cloud services, and business processes.
  • Evaluate and challenge the effectiveness of security controls and recommend risk-based improvements.
  • Serve as a subject matter expert on cybersecurity frameworks, standards, and regulatory requirements.
  • Conduct security and architecture reviews for new applications, technologies, and third-party solutions.
  • Support the adoption, optimization, and governance of Microsoft Purview and Microsoft Defender capabilities.
  • Analyze security events, threat intelligence, and risk indicators to identify emerging security concerns.
  • Assist with incident response, vulnerability management, and remediation tracking activities.
  • Support the development and enhancement of security policies, standards, procedures, and governance processes.
  • Collaborate with IT, Legal, Compliance, Audit, and business teams to assess and manage cybersecurity risk.
  • Contribute to ongoing improvements within Governance, Risk, and Compliance (GRC) programs and supporting platforms.
  • Research emerging threats, technologies, and industry trends to proactively identify and address security gaps.

Skills

Risk assessment
Security governance
Stakeholder influence
Threat intelligence

Education

CISSP / CISM / CRISC / CISA preferred

Tools

SIEM
GRC tools (Archer, ServiceNow IRM, RiskConnect)

Job description

Responsibilities

Kforce's client in Woburn, MA is seeking a Senior Information Security Analyst to join a growing cybersecurity and risk management team within a highly regulated environment. This individual will serve as a trusted advisor on information security risk, governance, and compliance initiatives while helping strengthen the organization's overall security posture. The ideal candidate will combine strong technical security knowledge with risk management expertise and the ability to influence stakeholders across the organization. This role will support enterprise risk assessments, security architecture reviews, governance initiatives, and the continued evolution of security technologies and processes.

  • Lead and execute enterprise-wide risk assessments across applications, infrastructure, cloud services, and business processes
  • Evaluate and challenge the effectiveness of security controls and recommend risk-based improvements
  • Serve as a subject matter expert on cybersecurity frameworks, standards, and regulatory requirements
  • Conduct security and architecture reviews for new applications, technologies, and third-party solutions
  • Support the adoption, optimization, and governance of Microsoft Purview and Microsoft Defender capabilities
  • Analyze security events, threat intelligence, and risk indicators to identify emerging security concerns
  • Assist with incident response, vulnerability management, and remediation tracking activities
  • Support the development and enhancement of security policies, standards, procedures, and governance processes
  • Collaborate with IT, Legal, Compliance, Audit, and business teams to assess and manage cybersecurity risk
  • Contribute to ongoing improvements within Governance, Risk, and Compliance (GRC) programs and supporting platforms
  • Research emerging threats, technologies, and industry trends to proactively identify and address security gaps
Requirements
  • CISSP, CISM, CRISC, or CISA preferred
  • 6-9 years of experience in Information Security, IT Risk Management, or Security Engineering
  • Hands-on experience with Microsoft Purview and Microsoft Defender
  • Experience conducting risk assessments, security reviews, and control evaluations
  • Knowledge of NIST CSF, FFIEC, PCI DSS, ISO 27001, COBIT, or similar frameworks
  • Experience with SIEM and GRC platforms (Archer, ServiceNow IRM, RiskConnect, etc.)

The pay range is the lowest to highest compensation we reasonably in good faith believe we would pay at posting for this role. We may ultimately pay more or less than this range. Employee pay is based on factors like relevant education, qualifications, certifications, experience, skills, seniority, location, performance, union contract and business needs. This range may be modified in the future.

We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees.

Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.

Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce's sole discretion unless and until paid and may be modified in its discretion consistent with the law.

This job is not eligible for bonuses, incentives or commissions.

Kforce is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Engineer
Product Security Engineer

Kforce Inc • Boston (MA)

On-site
USD 140,000 - 200,000
Product Security Engineer
Product Security Engineer

Kforce Inc • New York (NY)

On-site
USD 140,000 - 190,000
Network Security Engineer II
Network Security Engineer II

Kforce Inc • Irving (TX)

On-site
USD 110,000 - 140,000
Medical/dental/vision insurance
401(k)
HSA/FSA
+1
Information Security Analyst
Information Security Analyst

Talener • Boston (MA)

On-site
USD 125,000 - 175,000
Comprehensive benefits
Senior Cloud Engineer
Senior Cloud Engineer

Kforce Inc • Virginia (MN)

On-site
USD 120,000 - 160,000
IAM Manager
IAM Manager

Kforce Inc • Manhattan Beach (CA)

On-site
USD 150,000 - 230,000
Medical, dental, vision insurance
HSA/FSA
401(k) plan
+2
Cybersecurity Automation Engineer III
Cybersecurity Automation Engineer III

Kforce Inc • Fort Lauderdale (FL)

On-site
USD 120,000 - 160,000
Technology Business Management and Analytics
Technology Business Management and Analytics

Kforce Inc • Boston (MA)

On-site
USD 110,000 - 150,000
System Analyst
System Analyst

Kforce Inc • Hopkins (MN)

On-site
USD 85,000 - 120,000
DevSecOps Architect
DevSecOps Architect

Kforce Inc • Fort Lauderdale (FL)

On-site
USD 120,000 - 180,000
Medical insurance
Dental insurance
Vision insurance
+1