Senior Information Security Analyst (ASM/VM)
Austin, Texas
Cirrus Logic
We are seeking a highly motivated, seasoned security professional to join Information Security as a Senior Attack Surface Management / Vulnerability Management Information Security Analyst. You will be responsible for managing the scanning architecture, as well as the program to identify, analyze, prioritize, and mitigate security vulnerabilities in our digital assets to enhance cybersecurity and protect sensitive data. This role supports business strategy in a dynamic environment.
Responsibilities:
- Vulnerability Assessment: Conduct regular vulnerability assessments to identify security weaknesses in our systems, applications, and network infrastructure.
- Risk Analysis: Analyze and prioritize vulnerabilities based on risk level and potential impact on the organization.
- Mitigation Strategies: Develop and implement effective mitigation strategies to address identified vulnerabilities and reduce attack surfaces.
- Incident Response: Collaborate with the incident response team to investigate and respond to security incidents, ensuring swift resolution and minimizing damage.
- Security Tools: Manage and maintain security tools and technologies used for vulnerability management, including scanning tools.
- Security Policies: Develop and enforce security policies, standards, and best practices to ensure compliance with industry regulations and internal security requirements.
- Reporting: Prepare detailed reports on vulnerability assessment findings, mitigation efforts, and overall security posture for senior management.
- Security: Engage in the design and support of all aspects of an information security program, including Governance Risk & Compliance, Security Operations, and Security Engineering with hands on engineering and administration of security tools, such as CrowdStrike, Qualys, and Splunk in collaboration with fellow security and IT professionals.
Required Skills and Qualifications:
- Demonstrable experience across multiple cybersecurity domains including vulnerability management, risk management, network security, Splunk engineering, and incident response.
- Experience analyzing impact of vulnerabilities and designing solutions across Windows, Mac, Linux, Cloud, Network, Labs, and OT.
- Technical experience designing solutions across Linux, Mac, and Windows platforms.
- Strong knowledge of common vulnerabilities and attack vectors, as well as security best practices.
- One or more of the following certifications is preferred: Certified Information Systems Security Professional (CISSP); Systems Security Certified Practitioner (SSCP); GIAC Certified Intrusion Analyst (GCIA).
- Bachelor’s degree in cybersecurity or have demonstrated ability as a security professional in a globally dispersed enterprise.
- Experience working in high-tech, engineering, or semiconductor industry is beneficial.
- Effective working with a globally dispersed team across multiple time zones to deliver solutions on time.
- Experience with security industry frameworks, such as NIST CSF, ISO 27000 series, FAIR risk analysis, and privacy regulations.
- Proficiency with security tools such as Qualys, Crowdstrike, and Splunk.
- Experience with incident response and threat hunting.
- Excellent analytical and problem-solving skills.
- Effective communication and interpersonal skills, with the ability to effectively convey technical information to both technical and non-technical stakeholders.
- Executive presence and comfortable engaging with leaders across the company to facilitate balanced risk discussions and decision making.
This is a hybrid on-site position and will follow a 2+ day in-office work schedule, with in-office days based on business needs and team preference. You must be based within commutable distance of the work location listed on the job posting, or willing to relocate prior to beginning employment with Cirrus Logic.
#LI-CC1#LI-CJ1#LI-Hybrid
Cirrus Logic strives to select the best qualified applicant for any opening. Different approaches, ideas and points of view are both valued and respected. Employment decisions are made on the basis of job-related criteria without regard to race, color, religion, sex, national origin, age, protected veteran or disabled status, genetic information, or any other classification protected by applicable law.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: ASM CISSP Cloud Compliance CrowdStrike GCIA GIAC Governance Incident response ISO 27000 Linux Network security NIST Privacy Qualys Risk analysis Risk management Splunk SSCP Strategy Vulnerabilities Vulnerability management Windows
Perks/benefits: Career development
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.