Role overview
Employment type: Full-time
Pay: $121,000 - $132,000
Work model: Remote
About the position
The Information Security Analyst supports security assurance activities, including customer security reviews, third-party risk assessments, vendor reviews, Trust Center operations, documentation, evidence management, and reporting. Reporting to the Manager, Security Trust, this role works across teams to communicate security information clearly, evaluate risks, and improve processes through automation and approved AI tools.
Key responsibilities
- Respond to customer security questionnaires, vendor assessments, due diligence requests, and requests for security documentation.
- Ensure responses are accurate, supported by evidence, and consistent with approved security, legal, privacy, product, and compliance positions.
- Translate technical security, privacy, compliance, and product information into clear responses for customers, vendors, and internal stakeholders.
- Review SOC 1 and SOC 2 reports, ISO 27001 certifications, PCI DSS attestations, HIPAA security documentation, penetration testing reports, risk assessments, policies, and procedures.
- Evaluate security risks, document findings, and recommend remediation or risk treatment options.
- Maintain Trust Center materials, standard responses, knowledge articles, playbooks, evidence repositories, internal documentation, and AI-enabled knowledge bases.
- Coordinate security reviews with sales, customer success, procurement, legal, privacy, engineering, product security, security operations, and governance, risk, and compliance teams.
- Track review status, remediation activities, evidence requests, operational metrics, and workflow performance.
- Organize evidence and maintain documentation to support internal and external audit readiness.
- Improve self-service resources, reduce turnaround times, and contribute to more efficient global security assurance processes.
AI and automation
- Use approved AI tools to support questionnaire completion, vendor assessments, evidence collection, document creation, content maintenance, and security analysis.
- Develop reusable prompts, workflows, and knowledge resources that improve consistency and reduce manual work.
- Validate AI-generated outputs for technical accuracy, completeness, consistency, and appropriate handling of sensitive information.
- Measure and improve AI-assisted workflows while maintaining human oversight and accountability.
- Help teams adopt automated processes that improve the experience of customers, vendors, and internal stakeholders.
Required qualifications
- Bachelor's degree or equivalent experience.
- 2 to 5 years of experience in information security, security assurance, customer trust, third-party risk management, governance, risk, and compliance, or a related discipline.
- Experience reviewing or responding to security questionnaires, due diligence requests, or vendor assessments.
- Knowledge of SOC 2, ISO 27001, NIST CSF, NIST SP 800-53, PCI DSS, and the HIPAA Security Rule.
- Strong written and verbal communication, analytical, and organizational skills.
- Demonstrated interest in using AI and automation to improve security operations.
Preferred experience
- SaaS security experience.
- Experience with Trust Center and third-party risk management platforms.
- Familiarity with public cloud platforms.
- Experience applying AI and workflow automation to security operations.
- Relevant certifications, such as CISSP, CISM, CISA, CCSK, or CTPRP.
Compensation and benefits
Final compensation depends on relevant experience, education, certifications, skills, and geographic location.
Employees may also be eligible for a bonus or commission, medical benefits, retirement benefits, financial and wellness benefits, time off, and employee discounts.
Employment conditions
This position involves access to software or technology subject to U.S. export controls. Any employment offer is contingent on the applicant's ability to work in compliance with these requirements.