Назад
Company hidden
2 дня назад

Security Analyst

Формат работы
hybrid
Тип работы
fulltime
Грейд
junior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Analyst (GRC/Risk): Protecting corporate assets and web applications by identifying security risks, maintaining compliance programs, and improving security controls with an accent on third-party risk management, security frameworks, and cross-functional collaboration. Focus on analyzing vulnerabilities and vendor assessments, developing risk mitigation solutions, and designing measurable security improvements.

Location: Salt Lake City, UT, United States; hybrid workplace

Company

hirify.global develops visual collaboration and work acceleration products that help teams turn ideas into reality.

What you will do

  • Identify and report security risks from third-party vendor assessments, vulnerability scans, and internal risk discussions.
  • Identify threats to business assets and help develop risk mitigation solutions.
  • Develop, maintain, and coordinate security and compliance policies and training.
  • Support compliance with external regulations and answer internal and external questions about security practices.
  • Manage impactful security metrics and collaborate with Legal, Engineering, IT, Finance, and HR.
  • Lead the design and implementation of improvements to security controls and operational efficiency.

Requirements

  • Bachelor’s degree in information security assurance, business management, or a related field.
  • At least 1 year of experience with third-party risk management, GRC, or customer due diligence.
  • Understanding of security frameworks and principles, including NIST 800-53, ISO 27001, or SOC 2.
  • Security certification such as SSCP, CC, Security+, or CySA+.
  • Ability to manage tasks independently, meet deadlines, and work effectively across internal teams.
  • Strong verbal, written, and technical writing skills with close attention to detail.

Nice to have

  • Knowledge of risk management principles and practices.
  • CRISC, CISSP, or CISA certification.
  • Understanding of AWS, GCP, Azure, or other common cloud computing solutions.
  • Recent information system security risk management experience.
  • Experience thriving in a fast-paced, start-up-like environment.

Culture & Benefits

  • Hybrid work is available through remote work, office work, or a combination depending on role and team needs.
  • Values include teamwork, innovation, individual empowerment, initiative, ownership, and excellence.
  • Inclusive workplace focused on respectful collaboration and diverse perspectives.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →