Jobgether

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1 We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Senior Cybersecurity Analyst

Security AnalystSecurity AnalystFull TimeRemote

Location

United States

Posted

4 days ago

Salary

Not specified

SOC 2HIPAAISO 27001NIST CSFCISSPCISARisk ManagementAuditComplianceEnterprise SecuritySecurity FrameworksProject ManagementCustomer Security QuestionnairesHealthcare RegulationsDev Sec OpsCi/cd

Job Description

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more.

Role Description

We are seeking a skilled Senior Cybersecurity Analyst to play a pivotal role in securing enterprise systems, managing compliance programs, and mitigating risk across complex technical environments. This position offers the opportunity to impact critical business operations while collaborating with cross-functional teams, including Engineering, Product, Legal, and Customer Success. You will act as a trusted security advisor, helping translate technical and regulatory requirements into actionable strategies. The ideal candidate thrives in a fast-paced, innovative environment, combining technical expertise, project management skills, and strong communication abilities to ensure robust cybersecurity and compliance outcomes.

  • Leading SOC 2 Type II audit cycles from scoping through evidence collection to final reporting, serving as the main contact for auditors.
  • Coordinating HIPAA compliance assessments, including risk analyses, policy reviews, and BAA management.
  • Conducting gap analyses against security frameworks (SOC 2, HIPAA, ISO 42001, NIST CSF) and developing prioritized remediation plans.
  • Tracking risk mitigation progress and ensuring accountability for all corrective actions.
  • Responding to enterprise customer security questionnaires and collaborating with clients on security matters.
  • Supporting architecture and design reviews, ensuring systems meet security and compliance requirements before deployment.
  • Developing and maintaining reusable security documentation, including trust portals, standard responses, and technical diagrams.
  • Leveraging AI-assisted tools to enhance efficiency in threat analysis, evidence collection, and cybersecurity workflows.

Qualifications

  • Bachelor’s degree in Information Security, Computer Science, or a related field.
  • 6+ years of cybersecurity experience, including at least 2 years in compliance programs or audit processes.
  • Hands-on experience leading SOC 2 audits through the full lifecycle.
  • Practical knowledge of risk management frameworks (NIST RMF, ISO 42001, FAIR) and risk treatment procedures.
  • Experience responding to enterprise security questionnaires and interacting with customers.
  • Strong project management skills, capable of handling multiple priorities in a fast-moving environment.
  • Excellent communication skills for translating complex security topics to technical and non-technical audiences.
  • Active security certifications (CISSP and CISA preferred).

Requirements

  • Experience in the healthcare industry or familiarity with healthcare data regulations.
  • Knowledge of project management methodologies (PMP, Agile, Scrum).
  • Familiarity with additional compliance frameworks such as ISO 27001, NIST CSF, or HITRUST.
  • Understanding of DevSecOps practices and integrating security into CI/CD pipelines.

Benefits

  • Competitive salary and performance-based incentives.
  • Comprehensive Medical, Dental, Vision, and Life insurance.
  • HSA with employer match, FSA, and DCFSA options.
  • 401(k) plan.
  • Flexible PTO policy and 11 paid company holidays.
  • Remote-first location flexibility and annual company offsites.
  • Annual equipment stipend and periodic team events.

Job Requirements

  • Bachelor’s degree in Information Security, Computer Science, or a related field.
  • 6+ years of cybersecurity experience, including at least 2 years in compliance programs or audit processes.
  • Hands-on experience leading SOC 2 audits through the full lifecycle.
  • Practical knowledge of risk management frameworks (NIST RMF, ISO 42001, FAIR) and risk treatment procedures.
  • Experience responding to enterprise security questionnaires and interacting with customers.
  • Strong project management skills, capable of handling multiple priorities in a fast-moving environment.
  • Excellent communication skills for translating complex security topics to technical and non-technical audiences.
  • Active security certifications (CISSP and CISA preferred).
  • Experience in the healthcare industry or familiarity with healthcare data regulations.
  • Knowledge of project management methodologies (PMP, Agile, Scrum).
  • Familiarity with additional compliance frameworks such as ISO 27001, NIST CSF, or HITRUST.
  • Understanding of DevSecOps practices and integrating security into CI/CD pipelines.

Benefits

  • Competitive salary and performance-based incentives.
  • Comprehensive Medical, Dental, Vision, and Life insurance.
  • HSA with employer match, FSA, and DCFSA options.
  • 401(k) plan.
  • Flexible PTO policy and 11 paid company holidays.
  • Remote-first location flexibility and annual company offsites.
  • Annual equipment stipend and periodic team events.

Related Job Pages

More Security Analyst Jobs

Senior Information Security Analyst

Absolute Security

Absolute Security is the leader in enterprise Cyber Resilience

Security Analyst4 days ago
Full TimeRemoteTeam 501-1,000Since 1993H1B Sponsor

Senior Information Security Analyst defending enterprise assets against advanced threats

AWSAzureCloudCyber SecurityGoogle Cloud PlatformLinuxMacOSPythonSplunk
United States
Full TimeRemoteTeam 201-500

The Junior Information Security Analyst will assist in conducting security control assessments, collecting evidence, and supporting compliance reporting for IRS systems under FISMA requirements. This role involves hands-on support for vulnerability scanning, control validation, and POA&M tracking using tools like ServiceNow and Qmulos.

FISMANISTRisk Management FrameworkRMFISCM Plan developmentcloud systemsFedRAMPServiceNowQmulosSplunkSharePoint
United States
Security Analyst4 days ago
Full TimeRemoteTeam 5,001-10,000Since 1969

The Senior Cybersecurity Assessment & Authorization (A&A) Risk Analyst provides advanced governance, risk, and compliance (GRC) support to federal information systems in alignment with the Federal Information Security Modernization Act (FISMA) and the NIST Risk Management Framewo...

RMFNIST 800-37NIST 800-53NIST 800-30FISMAFedRAMPGRCRisk AssessmentSSOPOA&MCISSPCISMCAPMicrosoft 365
United States

Cybersecurity GRC Specialist

Metlife Legal Plans

MetLife Legal Plans is the country's largest provider of legal voluntary benefits. We have more than 40 years of experience in employee legal services and are committed to providing excellent care to our plan members, sponsors, and 18,000+ attorneys. Trusted by nearly 7 million families and more than 200 Fortune 500 companies who offer our service as an employee benefit. Growing quickly with a bold vision for our future as we evolve our company to dream bigger, move faster, and use creativity and technology to build products people love.

Security Analyst4 days ago
Full TimeRemote

The Cybersecurity GRC Specialist is responsible for managing and strengthening MetLife Legal Plans' Technology Governance, Risk, and Compliance (GRC) program. This role helps ensure the organization effectively identifies, assesses, and mitigates technology and cybersecurity risk...

GRCISO 27001Risk AssessmentPolicy DevelopmentThird-Party Risk ManagementIncident ResponseAudit SupportSecurity AwarenessRegulatory ComplianceVulnerability Assessment
United States