Experienced Security Analyst
Job Description
Join iPipeline in Wayne, PA (onsite) as an Experienced Security Analyst, where you’ll help protect systems and data while strengthening the organization’s incident readiness and compliance posture. The role combines hands-on security monitoring, in-depth incident investigation, and security tool management, with opportunities to contribute to planning and reporting across teams. iPipeline offers a competitive compensation and benefits package, career growth opportunities, an employee stock purchase plan, 401(k), and company-matched retirement packages, plus generous time off and flexible work/life balance, an employee wellness program, and an awards and recognition program.
What you’ll do
- Monitor and assess security alerts and system events, identifying potential risks, threats, and vulnerabilities across systems and infrastructure.
- Implement and refine security controls to mitigate risk and continually improve the organization’s security posture.
- Perform regular security audits and assessments, including vulnerability scanning and penetration testing.
- Detect, analyze, and investigate security incidents to determine root cause, impact, and appropriate next steps.
- Develop and implement remediation strategies for confirmed incidents, ensuring breaches are documented, analyzed, and remediated.
- Manage in-scope security tools and continuously evaluate and upgrade them to address evolving threats and compliance requirements.
- Coordinate with external vendors or authorities during major incidents such as data breaches.
- Apply security frameworks and practices to meet industry regulations, laws, and standards related to data protection, privacy, and industry requirements.
- Keep current on regulatory changes and help adjust policies and practices accordingly.
- Partner with legal teams to ensure contracts and agreements (including third-party vendor arrangements) meet security and regulatory expectations.
- Coordinate with audit teams for internal and external audits, including maintaining audit schedules and tracking remediation efforts.
- Interpret and apply regulatory and audit standards (including SOC 2, SOX, and Cyber Essentials), identify compliance gaps, and propose corrective actions.
- Conduct risk assessments and evaluate control effectiveness, supporting ongoing governance and improvement.
- Assist with employee security training sessions and collaborate with legal, HR, and IT to support consistent security practices.
- Provide regular reporting to senior management on security and compliance posture.
- Create detailed documentation for audits and compliance reviews, and update and maintain security policies and procedures.
- Lead portions of internal audits and participate in external audits.
- All other duties as assigned.
What you bring
- Ability to assess and mitigate advanced threats such as malware, phishing, and APTs.
- Experience conducting forensic analysis on compromised systems and networks.
- Proficiency in handling and responding to security incidents and breaches.
- Understanding of regulatory frameworks including GDPR, HIPAA, SOC 2, PCI DSS, NIST, and ISO 27001.
- Proficiency with network security, cloud security, encryption techniques, firewalls, SIEM (Security Information and Event Management), vulnerability scanning tools, and other security technologies.
- Strong written and verbal communication skills for reporting findings and collaborating with teams.
Tools and standards you’ll work with
SIEM (Security Information and Event Management), vulnerability scanning tools, firewalls, network security, cloud security, encryption techniques, and the standards/frameworks including GDPR, HIPAA, SOC 2, PCI DSS, NIST, ISO 27001, SOX, and Cyber Essentials.