Senior Security Analyst positions focus on delivering results in their domain. This page aggregates open Senior Security Analyst roles and what employers typically expect.
Senior Security Analyst Your Mission as Senior Security Analyst The Senior Security Analyst is responsible for advancing Energage's information security, privacy, and compliance programs by implementing and continuously improving technical controls, governance processes, and risk management practices. This role serves as a senior technical and operational resource responsible for protecting company systems, customer data, and business operations while enabling the organization's continued growth. The position partners closely with Engineering, Product, IT, Legal, HR, and business leaders to embed security and privacy into company operations, ensuring compliance with regulatory requirements and industry best practices while maintaining a practical, business-focused approach to risk management. The position reports to the Director of Information Security & Data Privacy. Accountability & Impact: In this role, you’ll... Support the integration of security throughout the Secure Software Development Lifecycle (SSDLC). Partner with Engineering teams to implement secure coding standards, code scanning, dependency management, and application security testing. Perform application security reviews, threat modeling, and architecture assessments. Evaluate new technologies and software solutions for security risks before implementation. Support vulnerability remediation efforts within internally developed applications. Network, Infrastructure & Cloud Security Continuously monitor the organization's security posture using security monitoring platforms, endpoint protection, cloud security tools, SIEM, and vulnerability management solutions. Investigate security alerts, suspicious activity, and potential incidents and escalate or coordinate response activities as appropriate. Implement and maintain cloud security controls across SaaS and cloud infrastructure. Manage encryption, key management, secure storage, identity management, and Data Loss Prevention (DLP) technologies. Evaluate and recommend improvements to network, endpoint, identity, and cloud security architecture. Governance, Risk & Compliance (GRC) Execute and coordinate external security audits and assurance activities, including ISO 27001 certification and surveillance audits, SOC 2 examinations, customer security assessments, and other applicable compliance reviews. Support organizational alignment with security frameworks and standards, including the NIST Cybersecurity Framework (NIST CSF) and other applicable industry frameworks. Serve as the primary Information Security point of contact for external auditors and customer security questionnaires. Own evidence collection, audit preparation, remediation tracking, and continuous compliance activities. Maintain and mature the organization's Integrated Management System (IMS). Develop, maintain, and improve security policies, standards, procedures, and supporting documentation. Perform enterprise security risk assessments and maintain the organizational risk register. Conduct comprehensive third-party/vendor security assessments and ongoing vendor risk monitoring. Track remediation activities and ensure timely resolution of audit findings and identified risks. Data Privacy & Governance Work directly with Product and Engineering to implement application and cloud security and privacy requirements and address identified risks. Conduct Data Protection Impact Assessments (DPIAs) and privacy risk assessments in collaboration with Legal and appropriate business stakeholders. Coordinate enterprise data mapping and data flow documentation initiatives. Maintain data retention, deletion, and classification standards in collaboration with Legal and applicable data owners. Support organizational compliance efforts related to applicable privacy and data protection requirements, including GDPR, CCPA/CPRA, and other relevant regulations. Support Legal, leadership, and appropriate stakeholders in privacy incident assessment, investigation, and regu…