{"schemaVersion":"jobsearcher.job.v1","id":"7d5a7767f5c35830b8428071","url":"https://jobsearcher.com/jobs/7d5a7767f5c35830b8428071","canonicalUrl":"https://jobsearcher.com/jobs/7d5a7767f5c35830b8428071","title":"Senior Security Analyst","description":"Senior Security Analyst\r\nYour Mission as Senior Security Analyst\r\nThe Senior Security Analyst is responsible for advancing Energage's information security, privacy, and compliance programs by implementing and continuously improving technical controls, governance processes, and risk management practices. This role serves as a senior technical and operational resource responsible for protecting company systems, customer data, and business operations while enabling the organization's continued growth.\r\nThe position partners closely with Engineering, Product, IT, Legal, HR, and business leaders to embed security and privacy into company operations, ensuring compliance with regulatory requirements and industry best practices while maintaining a practical, business-focused approach to risk management.\r\nThe position reports to the Director of Information Security & Data Privacy.\r\nAccountability & Impact:Support the integration of security throughout the Secure Software Development Lifecycle (SSDLC).\r\nPartner with Engineering teams to implement secure coding standards, code scanning, dependency management, and application security testing.\r\nPerform application security reviews, threat modeling, and architecture assessments.\r\nEvaluate new technologies and software solutions for security risks before implementation.\r\nSupport vulnerability remediation efforts within internally developed applications.\r\nNetwork, Infrastructure & Cloud Security\r\nContinuously monitor the organization's security posture using security monitoring platforms, endpoint protection, cloud security tools, SIEM, and vulnerability management solutions.\r\nInvestigate security alerts, suspicious activity, and potential incidents and elevate or coordinate response activities as appropriate.\r\nImplement and maintain cloud security controls across SaaS and cloud infrastructure.\r\nManage encryption, key management, secure storage, identity management, and Data Loss Prevention (DLP) technologies.\r\nEvaluate and recommend improvements to network, endpoint, identity, and cloud security architecture.Governance, Risk & Compliance (GRC)Execute and coordinate external security audits and assurance activities, including ISO 27001 certification and surveillance audits, SOC 2 examinations, customer security assessments, and other applicable compliance reviews.\r\nSupport organizational alignment with security frameworks and standards, including the NIST Cybersecurity Framework (NIST CSF) and other applicable industry frameworks.\r\nServe as the primary Information Security point of contact for external auditors and customer security questionnaires.\r\nOwn evidence collection, audit preparation, remediation tracking, and continuous compliance activities.\r\nMaintain and mature the organization's Integrated Management System (IMS).\r\nDevelop, maintain, and improve security policies, standards, procedures, and supporting documentation.\r\nPerform enterprise security risk assessments and maintain the organizational risk register.\r\nConduct comprehensive third-party/vendor security assessments and ongoing vendor risk monitoring.\r\nTrack remediation activities and ensure timely resolution of audit findings and identified risks.Data Privacy & GovernanceWork directly with Product and Engineering to implement application and cloud security and privacy requirements and address identified risks.\r\nConduct Data Protection Impact Assessments (DPIAs) and privacy risk assessments in collaboration with Legal and appropriate business stakeholders.\r\nCoordinate enterprise data mapping and data flow documentation initiatives.\r\nMaintain data retention, deletion, and classification standards in collaboration with Legal and applicable data owners.\r\nSupport organizational compliance efforts related to applicable privacy and data protection requirements, including GDPR, CCPA/CPRA, and other relevant regulations.\r\nSupport Legal, leadership, and appropriate stakeholders in privacy incident assessment, investigation, and regulatory notification activities.\r\nMaintain privacy-related policies, procedures, notices, and supporting documentation in collaboration with Legal and appropriate stakeholders.Vulnerability & Threat ManagementAdminister vulnerability management platforms and coordinate enterprise vulnerability scanning.\r\nAnalyze vulnerability intelligence and emerging threats.\r\nPrioritize remediation efforts based on business risk.\r\nCoordinate with infrastructure, engineering, and application teams to ensure timely remediation.\r\nTrack remediation metrics and provide regular reporting to leadership.Security Architecture & Technical RiskParticipate in architecture reviews for new technologies, cloud services, integrations, and business initiatives.\r\nIdentify security risks during project planning and recommend appropriate mitigations.\r\nReview identity, authentication, authorization, and access control designs.\r\nEvaluate technical solutions against security standards and organizational risk tolerance.\r\nSupport Zero Trust, Identity and Access Management (IAM), and security architecture initiatives.Security Operations & Incident ResponseParticipate in and support the organization's incident response program.\r\nInvestigate security events and coordinate incident response activities, including investigation, containment, remediation, and recovery.\r\nAssist with the development and maintenance of incident response procedures and playbooks.\r\nConduct and facilitate root cause analysis and post-incident reviews.\r\nRecommend process and technology improvements based on lessons learned.\r\nAssist with disaster recovery and business continuity planning from a security perspective.Security Awareness & LeadershipPromote a culture of security awareness throughout the organization.\r\nDevelop and deliver security awareness training.\r\nMentor junior security analysts and provide technical guidance.\r\nAssist with strategic security improvement initiatives.\r\nStay current on emerging threats, technologies, regulatory developments, and industry best practices.\r\nRepresent Information Security on cross‑functional projects and steering committees.Cross-Functional CollaborationWork directly with Product and Engineering to implement application and cloud security requirements and address identified risks.\r\nCollaborate with third‑party vendors to ensure adherence to Energage security requirements.\r\nSupport customer security assessments and due diligence activities.\r\nProvide security guidance during the procurement and implementation of new technologies.What You Bring to the Role:Bachelor's degree in Information Security, Computer Science, Information Technology, or equivalent professional experience.\r\n3+ years of progressive experience in Information Security, Cybersecurity, Security Engineering, or a related discipline.\r\nExperience supporting security and compliance programs involving ISO 27001, SOC 2, NIST CSF, or similar standards and frameworks.\r\nExperience performing security risk assessments and vulnerability management.\r\nWorking knowledge of cloud security principles and technologies in environments such as AWS, Azure, or Google Cloud.\r\nExperience with SIEM, endpoint security, vulnerability management, identity management, and security monitoring tools.\r\nStrong understanding of networking, authentication, encryption, access control, and security architecture principles.\r\nExperience supporting privacy compliance initiatives involving regulations such as GDPR and CCPA/CPRA.\r\nStrong written and verbal communication skills, including the ability to communicate security risks and recommendations to technical and non‑technical stakeholders.Nice to haves:\r\nOne or more relevant information security, privacy, audit, or cloud certifications are preferred, such as:Certified Information Systems Security Professional (CISSP)\r\nCertified Information Security Manager (CISM)\r\nCertified Cloud Security Professional (CCSP)\r\nGlobal Information Assurance Certification (GIAC)\r\nCertified Information Privacy Professional (CIPP)\r\nCompTIA Security+\r\nISO 27001 Lead Implementer or Lead AuditorEquivalent or comparable industry-recognized certifications will also be considered.\r\nCompensation and Benefits:\r\nThe base pay range for this role is $77,000 - $82,000. The base pay range is dependent on factors including, but not limited to, experience, skills, qualifications, relevant education, certifications, seniority, and location. The range listed is just one component of the total compensation package for employees. This role is also bonus eligible.\r\nIn addition to base pay, our total rewards package includes:PTO policy includes company holidays, sick time, vacation time, and floating holidays\r\nRemote\r\nCompany pays a portion of individual health care premium\r\nOption to participate in a company-sponsored 401(k)\r\nTraining and education\r\nProfessional development; all employees have access to a third party professional coach\r\nTuition reimbursement program\r\nOpportunity to work for a purpose-driven organization using business as a force for good (https://www.bcorporation.net/)Energage is a remote workplace with employees in various US locations. While our employees enjoy the flexibility of daily remote work, they are also given the occasional opportunity for in‑person interaction. This includes in our office in Exton Pa, or in a coworking space/out in their local area. This role is available for remote work in the following states:Arizona\r\nDelaware\r\nFlorida\r\nGeorgia\r\nMaryland\r\nMichigan\r\nNorth Carolina\r\nNebraska\r\nNew Jersey\r\nNew York STATE (NYC residents excluded)\r\nPennsylvania\r\nSouth Carolina\r\nTennessee\r\nTexas\r\nWisconsinIf you reside outside of the above locations, you will not be considered for this role.\r\nAbout Energage:\r\nEnergage is a purpose-driven company that helps organizations turn employee feedback into useful business intelligence and credible employer recognition through Top Workplaces. Built on 19 years of culture research and the results from 23 million employees surveyed across more than 70,000 organizations, Energage delivers the most accurate competitive benchmark available. With access to a unique combination of patented analytic tools and expert guidance, Energage customers lead the competition with an engaged workforce and an opportunity to gain recognition for their people‑first approach to culture. For more information or to nominate your organization, visit energage.com or topworkplaces.com.\r\nEnergage is committed to fostering a diverse and inclusive environment. We are proud to be an equal opportunity employer. Energage encourages all qualified candidates to apply, including those of any race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.\r\n#J-18808-Ljbffr","company":"Socket","rawCompany":"socket","city":"Exton","state":"PA","isRemote":false,"isActive":false,"createdAt":"2026-09-11T01:24:10.657Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Senior Security Analyst","description":"Senior Security Analyst\r\nYour Mission as Senior Security Analyst\r\nThe Senior Security Analyst is responsible for advancing Energage's information security, privacy, and compliance programs by implementing and continuously improving technical controls, governance processes, and risk management practices. This role serves as a senior technical and operational resource responsible for protecting company systems, customer data, and business operations while enabling the organization's continued growth.\r\nThe position partners closely with Engineering, Product, IT, Legal, HR, and business leaders to embed security and privacy into company operations, ensuring compliance with regulatory requirements and industry best practices while maintaining a practical, business-focused approach to risk management.\r\nThe position reports to the Director of Information Security & Data Privacy.\r\nAccountability & Impact:Support the integration of security throughout the Secure Software Development Lifecycle (SSDLC).\r\nPartner with Engineering teams to implement secure coding standards, code scanning, dependency management, and application security testing.\r\nPerform application security reviews, threat modeling, and architecture assessments.\r\nEvaluate new technologies and software solutions for security risks before implementation.\r\nSupport vulnerability remediation efforts within internally developed applications.\r\nNetwork, Infrastructure & Cloud Security\r\nContinuously monitor the organization's security posture using security monitoring platforms, endpoint protection, cloud security tools, SIEM, and vulnerability management solutions.\r\nInvestigate security alerts, suspicious activity, and potential incidents and elevate or coordinate response activities as appropriate.\r\nImplement and maintain cloud security controls across SaaS and cloud infrastructure.\r\nManage encryption, key management, secure storage, identity management, and Data Loss Prevention (DLP) technologies.\r\nEvaluate and recommend improvements to network, endpoint, identity, and cloud security architecture.Governance, Risk & Compliance (GRC)Execute and coordinate external security audits and assurance activities, including ISO 27001 certification and surveillance audits, SOC 2 examinations, customer security assessments, and other applicable compliance reviews.\r\nSupport organizational alignment with security frameworks and standards, including the NIST Cybersecurity Framework (NIST CSF) and other applicable industry frameworks.\r\nServe as the primary Information Security point of contact for external auditors and customer security questionnaires.\r\nOwn evidence collection, audit preparation, remediation tracking, and continuous compliance activities.\r\nMaintain and mature the organization's Integrated Management System (IMS).\r\nDevelop, maintain, and improve security policies, standards, procedures, and supporting documentation.\r\nPerform enterprise security risk assessments and maintain the organizational risk register.\r\nConduct comprehensive third-party/vendor security assessments and ongoing vendor risk monitoring.\r\nTrack remediation activities and ensure timely resolution of audit findings and identified risks.Data Privacy & GovernanceWork directly with Product and Engineering to implement application and cloud security and privacy requirements and address identified risks.\r\nConduct Data Protection Impact Assessments (DPIAs) and privacy risk assessments in collaboration with Legal and appropriate business stakeholders.\r\nCoordinate enterprise data mapping and data flow documentation initiatives.\r\nMaintain data retention, deletion, and classification standards in collaboration with Legal and applicable data owners.\r\nSupport organizational compliance efforts related to applicable privacy and data protection requirements, including GDPR, CCPA/CPRA, and other relevant regulations.\r\nSupport Legal, leadership, and appropriate stakeholders in privacy incident assessment, investigation, and regulatory notification activities.\r\nMaintain privacy-related policies, procedures, notices, and supporting documentation in collaboration with Legal and appropriate stakeholders.Vulnerability & Threat ManagementAdminister vulnerability management platforms and coordinate enterprise vulnerability scanning.\r\nAnalyze vulnerability intelligence and emerging threats.\r\nPrioritize remediation efforts based on business risk.\r\nCoordinate with infrastructure, engineering, and application teams to ensure timely remediation.\r\nTrack remediation metrics and provide regular reporting to leadership.Security Architecture & Technical RiskParticipate in architecture reviews for new technologies, cloud services, integrations, and business initiatives.\r\nIdentify security risks during project planning and recommend appropriate mitigations.\r\nReview identity, authentication, authorization, and access control designs.\r\nEvaluate technical solutions against security standards and organizational risk tolerance.\r\nSupport Zero Trust, Identity and Access Management (IAM), and security architecture initiatives.Security Operations & Incident ResponseParticipate in and support the organization's incident response program.\r\nInvestigate security events and coordinate incident response activities, including investigation, containment, remediation, and recovery.\r\nAssist with the development and maintenance of incident response procedures and playbooks.\r\nConduct and facilitate root cause analysis and post-incident reviews.\r\nRecommend process and technology improvements based on lessons learned.\r\nAssist with disaster recovery and business continuity planning from a security perspective.Security Awareness & LeadershipPromote a culture of security awareness throughout the organization.\r\nDevelop and deliver security awareness training.\r\nMentor junior security analysts and provide technical guidance.\r\nAssist with strategic security improvement initiatives.\r\nStay current on emerging threats, technologies, regulatory developments, and industry best practices.\r\nRepresent Information Security on cross‑functional projects and steering committees.Cross-Functional CollaborationWork directly with Product and Engineering to implement application and cloud security requirements and address identified risks.\r\nCollaborate with third‑party vendors to ensure adherence to Energage security requirements.\r\nSupport customer security assessments and due diligence activities.\r\nProvide security guidance during the procurement and implementation of new technologies.What You Bring to the Role:Bachelor's degree in Information Security, Computer Science, Information Technology, or equivalent professional experience.\r\n3+ years of progressive experience in Information Security, Cybersecurity, Security Engineering, or a related discipline.\r\nExperience supporting security and compliance programs involving ISO 27001, SOC 2, NIST CSF, or similar standards and frameworks.\r\nExperience performing security risk assessments and vulnerability management.\r\nWorking knowledge of cloud security principles and technologies in environments such as AWS, Azure, or Google Cloud.\r\nExperience with SIEM, endpoint security, vulnerability management, identity management, and security monitoring tools.\r\nStrong understanding of networking, authentication, encryption, access control, and security architecture principles.\r\nExperience supporting privacy compliance initiatives involving regulations such as GDPR and CCPA/CPRA.\r\nStrong written and verbal communication skills, including the ability to communicate security risks and recommendations to technical and non‑technical stakeholders.Nice to haves:\r\nOne or more relevant information security, privacy, audit, or cloud certifications are preferred, such as:Certified Information Systems Security Professional (CISSP)\r\nCertified Information Security Manager (CISM)\r\nCertified Cloud Security Professional (CCSP)\r\nGlobal Information Assurance Certification (GIAC)\r\nCertified Information Privacy Professional (CIPP)\r\nCompTIA Security+\r\nISO 27001 Lead Implementer or Lead AuditorEquivalent or comparable industry-recognized certifications will also be considered.\r\nCompensation and Benefits:\r\nThe base pay range for this role is $77,000 - $82,000. The base pay range is dependent on factors including, but not limited to, experience, skills, qualifications, relevant education, certifications, seniority, and location. The range listed is just one component of the total compensation package for employees. This role is also bonus eligible.\r\nIn addition to base pay, our total rewards package includes:PTO policy includes company holidays, sick time, vacation time, and floating holidays\r\nRemote\r\nCompany pays a portion of individual health care premium\r\nOption to participate in a company-sponsored 401(k)\r\nTraining and education\r\nProfessional development; all employees have access to a third party professional coach\r\nTuition reimbursement program\r\nOpportunity to work for a purpose-driven organization using business as a force for good (https://www.bcorporation.net/)Energage is a remote workplace with employees in various US locations. While our employees enjoy the flexibility of daily remote work, they are also given the occasional opportunity for in‑person interaction. This includes in our office in Exton Pa, or in a coworking space/out in their local area. This role is available for remote work in the following states:Arizona\r\nDelaware\r\nFlorida\r\nGeorgia\r\nMaryland\r\nMichigan\r\nNorth Carolina\r\nNebraska\r\nNew Jersey\r\nNew York STATE (NYC residents excluded)\r\nPennsylvania\r\nSouth Carolina\r\nTennessee\r\nTexas\r\nWisconsinIf you reside outside of the above locations, you will not be considered for this role.\r\nAbout Energage:\r\nEnergage is a purpose-driven company that helps organizations turn employee feedback into useful business intelligence and credible employer recognition through Top Workplaces. Built on 19 years of culture research and the results from 23 million employees surveyed across more than 70,000 organizations, Energage delivers the most accurate competitive benchmark available. With access to a unique combination of patented analytic tools and expert guidance, Energage customers lead the competition with an engaged workforce and an opportunity to gain recognition for their people‑first approach to culture. For more information or to nominate your organization, visit energage.com or topworkplaces.com.\r\nEnergage is committed to fostering a diverse and inclusive environment. We are proud to be an equal opportunity employer. Energage encourages all qualified candidates to apply, including those of any race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.\r\n#J-18808-Ljbffr","datePosted":"2026-09-11T01:24:10.657Z","dateModified":"2026-09-11T01:24:10.657Z","hiringOrganization":{"@type":"Organization","name":"Socket","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Exton","addressRegion":"PA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"7d5a7767f5c35830b8428071"},"url":"https://jobsearcher.com/jobs/7d5a7767f5c35830b8428071"}}