Sr. Information Security Analyst

STAAR Surgical

Lake Forest (CA)

On-site

USD 125,000 - 160,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

STAAR Surgical is seeking a Sr. Information Security Analyst to join its Information Technology team. You will define, deliver and support information security solutions, collaborate with engineering and business stakeholders, and contribute to roadmaps and security programs.

You will analyze complex security issues, implement controls across Linux/Unix, Windows and Mac environments, and mentor junior staff while working on high-impact security initiatives.

Qualifications

  • Applies research, information gathering and analytical skills to problems of diverse scope.
  • Develops solutions to moderately complex problems.
  • Screens, categorizes, evaluates, reconciles, reports and resolves data integrity issues.
  • Interprets generally defined practices and methods.
  • Identifies issues beyond the stated situation.
  • Exercises discretion and independent judgment on business matters.
  • Mentors junior information security personnel.
  • Proficient with security across Linux/Unix, Windows and Mac platforms.
  • Familiar with cloud, IAM, PAM, and vulnerability management practices.
  • Experience with incident handling, intrusion detection and log analysis.

Responsibilities

  • Defines and implements information security strategies and procedures.
  • Works with engineering teams to define security policies and settings.
  • Monitors vendor and 3rd party security reports.
  • Evaluates new products and technologies and makes leadership recommendations.
  • Manages access control systems, IDS/IPS Tools and security monitoring.
  • Integrates security controls to identify risks and reduce impact.
  • Analyzes potential risk and recommends solutions.
  • Creates and maintains security documentation.
  • Communicates security procedures to users.
  • Reviews and updates security policies and data protection policies.
  • Provides complex risk analysis and innovative solutions.
  • Mentors information security personnel and leads projects.

Education

Undergraduate degree + 2-6 years experience
Graduate degree + 0-4 years experience
Security certifications (CISSP, CySA+, GCIH, GSEC, Security+)
6-8 years relevant experience or equivalent mix of education/work

Job description

MAIN JOB RESPONSIBILITIES / COMPETENCIES

As a Sr. Information Security Analyst within STAAR Surgical's Information Technology team, this individual plays a critical role working closely with the business and across the Information Technology organization defining, delivering and supporting information security solutions and supporting roadmaps. In summary this position: works on information security problems that are diverse and highly complex; selects methods and techniques for identifying and advocating effective security solutions; develops approaches to address critical information security issues; and develops and administers schedules and performance requirements.

  • Defines and implements information security strategies and procedures.
  • Works with engineering teams to define and refine information security and systems management policies and settings.
  • Monitors and assesses vendor and 3rd party information security reports/lists.
  • Evaluates new and emerging products, technologies and makes recommendations to leadership concerning introduction of new technologies.
  • Coordinates, administers, manages and monitors the use of access control systems security tools and intrusion detection systems to identify anomalous events and security infractions that exploit system vulnerabilities.
  • Integrates information security controls into an environment to identify risks and reduce their impact.
  • Provides analysis of potential risk to information security and recommends solutions.
  • Creates and maintains information security documentation.
  • Communicates information security procedures to users.
  • Reviews and recommends changes to information security policies, including STAAR Surgical IT use policies, Data Sensitivity and Personally Identifiable Information Security Policies and procedures.
  • Understands and applies principles, concepts, theories, technologies and standards of professional field.
  • Develops and applies specialized knowledge within own discipline.
  • Deepens knowledge through exposure to new assignments and continuous learning.
  • Knowledge of related industry considerations.
  • Good working knowledge and demonstrated ability utilizing systems, tools and procedures to accomplish a job.
  • Builds a deeper understanding of processes, procedures, customers and organization.
  • Assists program or process development and implementation.
  • Coordinates activities and processes.
  • Leads or provides direction for information security projects.
  • Provides complex analysis of potential risk to information security and recommends innovative solutions.
  • Recommends and implements changes to procedures and systems to enhance information systems security.
  • Mentor junior information security personnel.
  • Works on assignments where considerable judgment and initiative are required in resolving problems and making choices, recommendations, or decisions.
  • Regularly exercises discretion and independent judgment on business matters.
  • Performs other duties as assigned.
REQUIREMENTS
EDUCATION & TRAINING
  • Preferred: Undergraduate degree and 2-6 years relevant experience or Graduate degree and 0-4 years relevant experience.
  • Highly desirable: Security certifications such as CISSP, CySA+, GCIH, GSEC, Security+
EXPERIENCE
  • Preferred: 6-8 years of relevant experience or equivalent combination of education and work experience.
SKILLS
  • Applies research, information gathering and analytical and interpretation skills to problems of diverse scope.
  • Develops solutions to a variety of problems of moderate complexity.
  • Screens, categorizes, evaluates, reconciles, reports and resolves data integrity issues.
  • Interprets generally defined practices and methods.
  • Recognizes and acts on inconsistencies in data or results and escalates unusual problems.
  • Identifies issues beyond the stated situation.
  • Works on assignments where considerable judgment and initiative are required in resolving problems and making choices, recommendations, or decisions.
  • Regularly exercises discretion and independent judgment on business matters.
  • Involved with local or business specific engagement initiatives in support of broader programs.
  • Competent in security best practices and defense in depth strategies for multiple platforms (i.e., Linux/Unix, Windows, Mac).
  • Competent in staying up to date on common cybersecurity threats, attacks, and TTPs.
  • Competent in intrusion detection and investigations.
  • Competent in incident handling and reporting.
  • Competent in analyzing host-based and network logs.
  • Competent in analyzing firewalls rules and configuration.
  • Competent in public cloud computing platforms.
  • Competent in standard cybersecurity frameworks and implementing security controls.
  • Competent in managing privileged account management (PAM) solutions.
  • Competent in managing vulnerability scanning solutions.
  • Competent in methods of data protection, encryption, and data loss prevention (DLP) solutions.
  • Competent in identity and access management methodology.
  • Competent in automation scripting languages (i.e., PowerShell, Python, Bash).
  • Proficient in developing and managing a security awareness training program.
  • Proficient in managing endpoint protection solutions (EDR/XDR).
  • Proficient in multifactor authentication (MFA) technologies.
  • Proficient in managing email security gateway solutions.
  • Ability to analyze more complex security issues, determine its cause and impact to the business and identify the corrective action needed to eliminate and prevent the event for the future.
  • Familiar with database technology and query analysis.
  • Ability to recommend security standards and procedures.
  • Must possess strong verbal and written communication skills and be able to adapt to the level and nature of their audience.

Pay range is $125k - $160k - Final compensation/salary will depend on experience.

STAAR Surgical is an Equal Opportunity/Affirmative Action employer and all qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran or disability status, or any other characteristic protected by law. USA

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Systems / Cloud Engineer I
Sr. Systems / Cloud Engineer I

STAAR Surgical • Lake Forest (CA)

On-site
USD 135,000 - 175,000
Sr Systems / Cloud Engineer
Sr Systems / Cloud Engineer

International Executive Service Corps • Lake Forest (CA)

On-site
USD 135,000 - 175,000
Sr. Business Analyst IT –Sales & Commerce Applications
Sr. Business Analyst IT –Sales & Commerce Applications

STAAR Surgical • Lake Forest (CA)

On-site
USD 135,000 - 165,000
Senior InfoSec Analyst: Strategic Defender of Systems
Senior InfoSec Analyst: Strategic Defender of Systems

STAAR Surgical • Lake Forest (CA)

On-site
USD 125,000 - 160,000
Director, Business Intelligence & Data Analytics
Director, Business Intelligence & Data Analytics

STAAR Surgical • Lake Forest (CA)

On-site
USD 170,000 - 245,000
Manufacturing Science &Technology Engineer II
Manufacturing Science &Technology Engineer II

International Executive Service Corps • Monrovia (CA)

On-site
USD 85,000 - 110,000
Director, Software Quality V&V CSV/CSA
Director, Software Quality V&V CSV/CSA

STAAR Surgical • Lake Forest (CA)

On-site
USD 200,000 - 240,000
Senior Analyst Information Security
Senior Analyst Information Security

StandardAero • Maryville (TN)

Hybrid
USD 80,000 - 120,000
Comprehensive Healthcare
401(k) with company match
Paid Time Off starting on day one
+1
Sr. Director, Product Security
Sr. Director, Product Security

abbott • Saint Paul (MN)

On-site
USD 190,000 - 380,000
Leader Software Quality V&V CSV/CSA
Leader Software Quality V&V CSV/CSA

STAAR Surgical • Lake Forest (CA)

On-site
USD 200,000 - 240,000