Job Description
We are seeking a Security Analyst to support one of our clients' enterprise information security program by translating technical security risks into business impacts and advising stakeholders on risk treatments.
Responsibilities:
Support our enterprise information security program
Translate technical security risks into clear business impacts
Advise stakeholders on pragmatic risk treatments
Help implement and validate security controls across networks, endpoints, and cloud environments
Partner with IT, product, and business teams to assess threats
Identify control gaps
Recommend remediation options
Communicate effectively with both technical and non-technical audiences
Help the business make informed, risk-based decisions
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.
Skills and Requirements
2+ years of professional experience in cybersecurity with emphasis in network security and/or security engineering (e.g., cloud, firewalls, IDS/IPS, endpoint protection, vulnerability management, logging/monitoring).
Demonstrated experience conducting or supporting risk assessments (e.g., asset/context discovery, threat & likelihood analysis, control gap identification, residual risk estimation) and documenting outcomes in clear, actionable language.
Familiarity with common security frameworks/controls (e.g., NIST CSF/800-53/800-30, ISO 27001/27002, CIS Critical Security Controls) and ability to map findings to these references.
Working knowledge of network fundamentals (TCP/IP, routing, segmentation, DNS, TLS), identity and access management, and secure configuration baselines.
Ability to write clear advisory reports and present risk/controls to stakeholders; strong documentation habits (runbooks, diagrams, tickets).
Experience collaborating with IT or engineering teams to implement and validate controls (e.g., compensating controls, segmentation changes, logging enrichment). - Experience facilitating or contributing to risk registers, exception/acceptance processes, and risk treatment plans with measurable milestones.
Familiarity with privacy & data protection concepts (e.g., data classification, retention, DLP controls) and regulatory drivers (e.g., SOX/PCI/HIPAA/GLBA as applicable).
Knowledge of DevSecOps practices (e.g., secrets management, SAST/DAST, SBOMs, CI/CD guardrails).
Contribution to security awareness or secure-by-design initiatives.
Relevant certifications (e.g., Security+, Network+, Cloud Fundamentals) or equivalent practical experience.