Information Security Analyst
$100,000–$100,000 year
On-siteTustin, California, United States
Job Summary
Implement and maintain security controls across on-premise, cloud, and network environments to protect company data and assets. Analyze business processes and data flows to identify security gaps, then apply industry best practices like the NIST Cybersecurity Framework to ensure confidentiality, integrity, and availability. Support compliance with standards such as ISO 27001 and GDPR by tracking evidence using GRC tools and assisting in policy development. Monitor SIEM alerts and participate in incident response activities, including investigation, containment, and post-incident analysis. Assist with vulnerability management, access reviews, and security awareness training while documenting lessons learned and maintaining accurate security procedures. This role works closely with senior security team members to improve readiness through tabletop exercises and response drills.
Required Qualifications
- Bachelor's degree in Information Security, Computer Science, or a related field (or equivalent experience)
- 3–6 years of experience in information security or a related IT/security role
- Hands-on experience with security monitoring, incident response, vulnerability management, or risk assessment
- Familiarity with cloud environments (AWS, Azure, or GCP) and basic cloud security concepts
- Working knowledge of security frameworks and standards such as NIST CSF, ISO 27001, and CIS
- Understanding of network security fundamentals, including firewalls, IDS/IPS, endpoint protection, and logging
- Experience with SIEM or security monitoring tools such as Splunk, QRadar, Rapid7, or Wazuh
- Strong analytical, troubleshooting, and communication skills
- This is an on-site, office-based role in Tustin, CA
Desired Qualifications
- Experience supporting compliance or audit activities
- Familiarity with GRC or compliance automation tools (OneTrust, Drata, or similar)
- Relevant security certifications such as Security+, CEH, GSEC, or progress toward CISSP/CISM
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.