74 Security Analyst jobs in Washington
Security Analyst
Posted 3 days ago
Job Viewed
Job Description
We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
Today's world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team helps protect the EY brand and build client trust.
Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.
**The opportunity**
The Internal Investigations Services (IIS) team is responsible for responding to cyber security incidents and events caused by EY Personnel, Contractors and Associates globally. The scope of IIS also includes performing computer forensic reviews and managing eDiscovery requests supporting General Counsel.
Senior Specialist Internal Investigations Services acts as a lead technical investigator for information gathering, analysis and reporting in support of digital forensic investigations
**Your key responsibilities**
+ Leads security investigations and eDiscovery matters
+ Produces fact-based technical reports detailing events over specified periods of time for the investigation and shares the reports with stakeholders to act upon
+ Advise and assist stakeholders on the relevance of information derived from internal and external sources associated with information security matters, digital forensic inquiries, and investigative work
+ Identify and propose areas for improvement in IIS processes and procedures
**Skills and attributes for success**
In depth technical knowledge (IT infrastructure, forensic tools, forensic methodologies)
+ Strong investigative and analytical mentality, and problem-solving skills
+ Able to see the comprehensive picture based on the correlation of the data captured from the various data sources
+ Ability to multitask in a time sensitive environment with awareness of confidentiality and local privacy laws
+ Flexibility to adjust to multiple demands, ambiguity and rapid change environment
+ Global approach for working with different cultures and backgrounds
+ Excellent teaming skills
+ Ability to team well with others to facilitate and enhance the understanding & compliance to security policies
+ Knowledge of existing and emerging legal issues within information security environments (i.e., data privacy)
+ Possess an efficient and versatile communication style
+ Proven integrity and judgment within a professional environment
+ Ability to work in a global environment (Virtual teaming, multiple jurisdictions)
+ Experiences in investigation case management
+ A strong information security background and knowledge to speak thoughtfully to both technical and non-technical teams
+ Ability to appropriate balance work/personal priorities
+ Understanding of the Big 4 workplace culture and business structure
+ Conduct interview skills with investigative mind-set, supporting GCO from a technical perspective
**Other Requirements:**
Some weekend work should be expected
**To qualify for the role you must have**
**Education:**
Bachelor or Master Degree in Computer Science or a related field
**Experience** :
+ 5-10 years of experience in one or more of the following:
+ Information Security, demonstrating experience in investigative unit and incident response.
+ Information Security, in depth understanding of cyber investigation, forensic tools, and methodologies, including: log correlation and analysis, forensically handling electronic data, knowledge of the computer security investigative processes
+ Be familiar with a basic understanding of legalities surrounding discovery and analysis of electronically stored information
+ Experience with Forensic tools such as Encase, F-Response, FTK, Nuix, Axiom,.
+ Experience with Microsoft Purview, Defender and other monitoring tools
+ Familiar with Microsoft environment (Exchange, SharePoint, Purview , Sentinel, Azure.)
+ Knowledge of scripting languages such as Python to automate collection
+ Experience with PowerShell
**Experience in reporting to Senior Leadership Certification Requirements:**
Candidates must hold or be actively pursuing related professional certifications such as CISSP, Security+, EnCE, ACE, GCFE, GCIA
Ability to obtain and maintain Security Clearance if assigned in US
**Ideally, you'll also have**
+ Certifications demonstrating interest and development of Soft Skills
**What we look for**
Understanding the impact and associated risks data security incidents cause for the Business and EY as a Company, you will handle incoming requests in a timely and appropriate manner.
**What we offer you**
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
+ We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $91,100 to $70,400. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is 109,300 to 193,600. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
+ Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
+ Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
**Are you ready to shape your future with confidence? Apply today.**
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
**EY | Building a better working world**
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at .
Sr. Information Security Analyst
Posted 3 days ago
Job Viewed
Job Description
This role is responsible for assessing, auditing, and enhancing the security posture of enterprise systems in alignment with industry standards and regulatory requirements. The ideal candidate will have a strong background in information security, risk management, and compliance frameworks, including ISO 27001, NIST, and CIS Controls, among others.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: and Requirements
- Bachelor's degree in information security, Computer Science, or a related field (or equivalent experience).
- 5+ years of experience in information security, with at least 2 years in an enterprise environment.
- Proven experience conducting audits and assessments against standards such as ISO 27001, NIST 800-53, CIS, or SOC 2.
- Strong understanding of enterprise IT systems, multi-cloud platforms (Azure, etc.), and network security.
- Experience working with any county/state/federal government engagements
- Excellent analytical, communication, and documentation skills. - Professional certifications such as CISSP, CISA, CISM, or ISO 27001 Lead Auditor.
- Experience with regulatory compliance (e.g., GDPR, HIPAA, PCI-DSS).
- Knowledge of secure software development lifecycle (SDLC) and DevSecOps practices.
Senior Information Security Analyst
Posted today
Job Viewed
Job Description
Key Responsibilities:
- Monitor security alerts and logs for potential threats and anomalies.
- Conduct vulnerability assessments and penetration testing to identify and mitigate security risks.
- Develop, implement, and maintain security policies, procedures, and standards.
- Respond to security incidents, including investigation, containment, eradication, and recovery.
- Manage and configure security tools such as firewalls, intrusion detection/prevention systems (IDS/IPS), and SIEM platforms.
- Stay up-to-date on the latest cybersecurity threats, trends, and technologies.
- Develop and deliver security awareness training to employees.
- Ensure compliance with relevant data protection regulations (e.g., GDPR, CCPA).
- Collaborate with IT and development teams to integrate security into the software development lifecycle (SDLC).
- Assist in security audits and assessments.
Qualifications:
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field. Advanced certifications such as CISSP, CISM, or CEH are highly valued.
- Minimum of 5-7 years of experience in information security, with a strong focus on security operations, incident response, and vulnerability management.
- In-depth knowledge of network security, system security, cryptography, and security frameworks (e.g., NIST, ISO 27001).
- Proficiency with security tools and technologies (SIEM, IDS/IPS, firewalls, endpoint protection).
- Experience with scripting languages (e.g., Python, PowerShell) for automation is a plus.
- Strong analytical and problem-solving skills, with the ability to make sound decisions under pressure.
- Excellent communication and interpersonal skills, with the ability to explain technical concepts to both technical and non-technical audiences.
- Ability to work independently and as part of a team in a fast-paced environment.
- Understanding of cloud security principles (AWS, Azure, GCP) is desirable.
Senior Information Security Analyst
Posted 1 day ago
Job Viewed
Job Description
Responsibilities:
- Conduct comprehensive risk assessments and vulnerability analyses to identify potential security threats.
- Develop, implement, and maintain security policies, procedures, and controls.
- Monitor security systems and networks for suspicious activities and potential breaches.
- Lead incident response efforts, including investigation, containment, eradication, and recovery.
- Perform regular security audits and penetration testing to ensure compliance and identify weaknesses.
- Provide technical guidance and support to IT staff on security best practices.
- Stay current with emerging security threats, vulnerabilities, and technologies.
- Develop and deliver security awareness training to employees.
- Collaborate with cross-functional teams to integrate security into all aspects of the business.
- Contribute to the development and improvement of the overall security architecture.
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Minimum of 7 years of experience in information security or cybersecurity roles.
- In-depth knowledge of security frameworks (e.g., NIST, ISO 27001), protocols, and technologies (e.g., firewalls, IDS/IPS, SIEM).
- Proven experience with incident response and forensic analysis.
- Strong understanding of network security, cloud security, and application security.
- Excellent analytical and problem-solving skills.
- Relevant certifications such as CISSP, CISM, or CEH are highly desirable.
- Effective communication and reporting skills, capable of explaining complex security concepts to technical and non-technical audiences.
- Experience with scripting languages (e.g., Python, PowerShell) for automation is a plus.
- Ability to work independently and collaboratively in a hybrid team environment.
Senior Information Security Analyst
Posted 3 days ago
Job Viewed
Job Description
Principal Information Security Analyst
Posted 4 days ago
Job Viewed
Job Description
Key Responsibilities:
- Develop and implement comprehensive information security strategies and roadmaps aligned with business objectives.
- Lead proactive threat hunting initiatives, identify emerging threats, and develop countermeasures.
- Oversee and manage incident response activities, including investigation, containment, eradication, and recovery.
- Conduct in-depth vulnerability assessments and penetration tests, and guide remediation efforts.
- Design, deploy, and manage security technologies such as firewalls, IDS/IPS, SIEM, EDR, DLP, and encryption solutions.
- Develop, update, and enforce security policies, standards, and procedures.
- Provide expert guidance on security best practices to internal teams and stakeholders.
- Conduct security awareness training for employees.
- Evaluate and recommend new security technologies and solutions.
- Manage security compliance with relevant regulations (e.g., GDPR, HIPAA, PCI DSS).
- Act as a subject matter expert in various security domains, including cloud security, network security, and application security.
- Mentor and guide junior security analysts.
- Maintain documentation related to security infrastructure, policies, and procedures.
Qualifications:
- Master's degree in Computer Science, Cybersecurity, or a related field, or equivalent practical experience.
- 10+ years of progressive experience in information security.
- Proven track record in developing and executing security strategies.
- Extensive experience with incident response and forensics.
- Deep understanding of security frameworks (NIST, ISO 27001) and compliance requirements.
- Expertise in network security, endpoint security, cloud security (AWS, Azure, GCP), and application security.
- Proficiency with SIEM tools (e.g., Splunk, QRadar), IDS/IPS, firewalls, and vulnerability scanning tools.
- Strong understanding of threat intelligence platforms and methodologies.
- Relevant security certifications such as CISSP, CISM, SANS GIAC certifications.
- Excellent analytical, problem-solving, and communication skills.
- Ability to work independently and lead initiatives in a remote setting.
Senior Information Security Analyst
Posted 5 days ago
Job Viewed
Job Description
Be The First To Know
About the latest Security analyst Jobs in Washington !
Senior Information Security Analyst
Posted 7 days ago
Job Viewed
Job Description
Senior Information Security Analyst
Posted 8 days ago
Job Viewed
Job Description
Senior Information Security Analyst
Posted 8 days ago
Job Viewed
Job Description
Responsibilities will include developing and implementing comprehensive security strategies, conducting risk assessments and vulnerability analyses, managing security incident response procedures, and overseeing the deployment and maintenance of security tools and technologies. You will also be responsible for creating and delivering security awareness training programs for employees, ensuring compliance with relevant regulations, and collaborating with IT and engineering teams to integrate security best practices into all aspects of the development lifecycle. The role requires a proactive approach to identifying potential threats, a meticulous attention to detail in threat analysis, and the ability to communicate complex security concepts clearly and effectively to both technical and non-technical stakeholders.
Qualifications include a Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent practical experience. A minimum of 5 years of experience in information security is required, with a focus on areas such as network security, endpoint security, cloud security, and cryptography. Relevant certifications such as CISSP, CISM, or CEH are highly desirable. Strong analytical and problem-solving skills, excellent communication and interpersonal abilities, and the capacity to work both independently and as part of a collaborative team are essential. Experience with SIEM tools, intrusion detection/prevention systems, firewalls, and data loss prevention technologies is a must. Familiarity with scripting languages (e.g., Python, Bash) for automation and analysis is a plus.
This is an exceptional opportunity to contribute to a robust security program and grow your career in a collaborative and innovative environment. If you are a security-minded professional looking to make a significant impact, we encourage you to apply.