Information Security Analyst
Tuzla, Bosnia and Herzegovina
Now is the time to join us!
At Virgin Pulse we value and celebrate diversity and we are committed to creating an inclusive environment for all employees. We believe in creating teams made up of individuals with various backgrounds, experiences, and perspectives. Why? Because diversity inspires innovation, collaboration, and challenges us to produce better solutions. But more than this, diversity is our strength, and a catalyst in our ability to #changelivesforgood.
Who are you?
As Information Security Analyst for the industry leading employee wellbeing and engagement platform, you will Lead the team responsible for ongoing prevention, detection, and response to cyber threats across all of the company’s systems. This position will report directly to the Associate Director, InfoSec, and the core responsibilities will include working with our InfoSec, CyperSecOps, CyberSecEng, Fraud Prevention, and Corporate Systems teams to ensure technical security controls are deployed and performing optimally.
Key responsibilities will include implementing and maintaining effective logging tools, monitoring tools and ensuring the security of data and systems through preventing, identifying and remediating weaknesses and vulnerabilities across our technical infrastructure, applications and platforms.
This is a hands-on roll involving maintenance and management of production and corporate security tools in addition to actively working on ticket backlogs and project management.
In this role you will wear many hats, but your knowledge will be essential in the following:
- Assist a team of CyberSecOps Engineers and Cyber Security Analysts
- Participate and lead internal and external audit efforts such as PCI, SOC2, ISO-27001, HITRUST.
- Monitor AWS and Azure security dashboards (Guard Duty, Security Hub, VPC Flow Logs, Sentinel, etc).
- Continuously assess endpoint security control coverage, escalating gaps to appropriate teams for corrective action where required.
- Create and manage security metric dashboards for use within the team and provide management reporting.
- Lead event analysis for network and system alerts in addition to anomalous platform activity, supporting internal and customer facing teams with accurate and timely log review and follow up.
- Coordinate ongoing web application scanning and PCI compliance requirements.
- Participate Red / Blue Team and CSIRT exercises, involving stakeholders across the business.
- Regularly audit public IP space and DNS records including cloud hosting resources.
- Manage cyber reputation tools to ensure findings are reviewed and resolved efficiently.
- Deliver weekly reporting on core security metrics to applicable stakeholders.
- Support business teams to interpret governance requirements into technical controls.
- Manage relationships with security vendors and consultants.
- Guide complex problems from identification to resolution, providing subject expertise to colleagues across the business.
- Investigate, recommend, and install security enhancements and operating procedures to enhance security posture and optimize workflows.
- Ensure the confidentiality, integrity and availability of information being processed, stored, accessed or transmitted within systems and networks.
- Support the planning and execution of business continuity and disaster recovery tests.
- Serve as lead and escalation point for security events.
- Coordinate with stakeholders across the business for mitigations pertaining to ongoing security threats to the organization as needed.
You’ll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in.
What you bring to the Virgin Pulse team
In order to represent the best of what we have to offer you come to us with a multitude of positive attributes including:
- BS degree and/or Security specific certifications preferred, with focus on auditing related experience.
- Interest in SaaS Cyber Security / SecOps roles.
- Ability to prioritize and execute tasks in a high-pressure environment and take direct instruction during emergency situations.
- In depth experience with SIEM, Endpoint Protection, Data Loss Prevention, Intrusion Detection and Cloud Security management.
- Previous responsibility in management of security vendors and budgets
- Demonstrated ability to prioritize and treat technical risks.
- Previous work supporting of SOC, ISO, PCI, and HITRUST certification and compliance programs.
- Experience in vulnerability management programs and patch management.
- Able to provide technical and professional leadership, guidance, and training to others.
- Ability to build relationships and communicate effectively with peers across all business functions.
You also take pride in offering the following Core Skills, Competencies, and Characteristics:
- Motivated, efficient and high functioning team.
- Developing excellent relationships across business units.
- Ongoing reduction in risk across corporate and SaaS platform to technical footprint.
- Documented reductions in pen test and vulnerability findings.
- Metrics based evidence relating to improvements in security posture over time.
No candidate will meet every single desired qualification. If your experience looks a little different from what we’ve identified and you think you can bring value to the role, we’d love to learn more about you!
Why work at Virgin Pulse???
We believe a career should provide competitive pay and benefits, a collaborative and supportive culture and cutting-edge technology and services. Virgin Pulse is an equal opportunity organization and is committed to diversity, inclusion, equity and social justice. To that end, we make a particular effort to recruit candidates from minoritized backgrounds to apply for open positions.