SENIOR SECURITY ANALYST
Make your next big career move by applying as KMC Solutions’ next SENIOR SECURITY ANALYST
The Senior Security Analyst will play a critical role in strengthening and advancing GCI's cybersecurity capabilities as part of the organization's security maturity journey.
This position is responsible for independently assessing security risks, identifying control gaps and vulnerabilities, recommending remediation strategies, and driving practical security improvements across the organization. The successful candidate will lead the design, implementation, and operation of IT security controls aligned with organizational policies, Information Security Management System (ISMS) requirements, and ISO 27001 frameworks.
We are seeking a hands-on cybersecurity professional who thrives in evolving environments, possesses strong problem-solving capabilities, takes initiative, and can effectively balance security requirements with business objectives.
On top of your salary, here are the exciting benefits you can look forward to:
- Health Insurance/HMO
- Enjoy unlimited MadMax Coffee
- Diverse learning & growth opportunities
- Accessible Cloud HR platform (Sprout)
- Above standard leaves
The main responsibilities of a SENIOR SECURITY ANALYST include:
Security Risk & Vulnerability Management
- Conduct independent security assessments, investigations, and reviews of infrastructure, systems, applications, and business processes.
- Identify security risks, control deficiencies, and vulnerabilities across the organization's technology landscape.
- Perform risk and vulnerability assessments and recommend practical remediation strategies to address root causes.
- Drive remediation initiatives and ensure mitigation measures are effectively implemented and monitored.
- Evaluate emerging threats and assess their impact on the organization's security posture.
Security Controls Design & Implementation
- Design, implement, operate, and continuously improve IT security controls aligned with ISMS and ISO 27001 requirements.
- Assess the effectiveness of existing security controls and recommend enhancements to strengthen organizational security.
- Develop preventive, detective, and corrective security measures to reduce cyber risks.
- Lead security improvement initiatives that support GCI's security maturity roadmap.
Security Operations & Incident Management
- Monitor security events, alerts, and incidents across systems, networks, cloud platforms, and endpoints.
- Investigate security incidents, determine root causes, and implement corrective actions.
- Support incident response, containment, recovery, and post-incident reviews.
- Document security findings, risks, incidents, and remediation activities.
Infrastructure & Cloud Security
- Support the security of Microsoft 365, Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Firewalls, SD-WAN, Network Security Infrastructure, and Proxy Solutions.
- Identify and remediate infrastructure, endpoint, and network vulnerabilities.
Governance, Compliance & Continuous Improvement
- Support the implementation, maintenance, and continuous improvement of the Information Security Management System (ISMS).
- Ensure security practices are aligned with ISO 27001 controls and organizational security policies.
- Develop and recommend security standards, procedures, and best practices.
- Partner with stakeholders across the business to drive security awareness and continuous improvement initiatives.
- Contribute to the organization's next phase of security maturity and capability development.
To apply, you must be an expert on the following requirements:
Required Experience
- Minimum of 5 years of experience in Information Security, Cybersecurity, or related field.
- Proven experience conducting independent security assessments, investigations, and risk evaluations.
- Strong hands-on experience designing, implementing, and operating IT security controls.
- Demonstrated expertise in risk management, vulnerability management, and remediation planning.
- Experience supporting or implementing ISMS and ISO 27001 frameworks.
- Strong track record of identifying security gaps and driving practical security improvements.
- Experience working in organizations undergoing security transformation or improving security maturity is highly preferred.
Technical Skills
- Hands-on experience with Microsoft Defender, Microsoft Sentinel, Microsoft 365 Security, Microsoft Azure Security, Firewalls, SD-WAN, Network and Infrastructure Security, and Proxy Technologies.
- Experience performing vulnerability assessments, security reviews, and penetration testing activities.
- Strong understanding of cybersecurity controls, threat management, and risk mitigation practices.
It will also be favorable if you are knowledgeable in:
- Proactive and solutions-oriented mindset.
- Strong analytical, investigative, and problem-solving abilities.
- Ability to work independently and take ownership of security initiatives.
- Strong stakeholder management and communication skills.
- Ability to influence change and drive security improvements across the organization.
- Continuous improvement mindset with a focus on strengthening security maturity.
IT - Security
Applying takes about a minute
Know someone for this?
Refer them in a few clicks and track their progress from your referrals dashboard.