Information Security Analyst (Remote)

2 hours, 35 minutes ago
Full-time
Mid Level
Cybersecurity
Evio Beauty

Evio Beauty

Evio Beauty is an impact-led, clean beauty brand that creates inclusive, good-for-you beauty products. Founded by a survivor of domestic violence, Evio breaks stigmas and supports social causes through its high-performing skincare and makeup collection...

Consumer Goods
11-50
Founded 2014

Description

  • Own and execute user access management, including provisioning and deprovisioning across AWS, O365, HRIS, SaaS platforms, and databases.
  • Implement and maintain least-privilege RBAC, access control matrices, and entitlement catalogs.
  • Administer identity and access systems, including IdP/SSO integrations and SCIM provisioning.
  • Enforce privileged access management, multi-factor authentication, separation of duties, and key/secret rotation.
  • Conduct recurring quarterly and annual access reviews across systems and maintain onboarding/offboarding provisioning workflows.
  • Monitor, triage, and investigate security alerts and support incident response activities.
  • Perform audit trail and log reviews across SIEM, CloudTrail, and O365 logs, and track remediation.
  • Support SOC 2, HIPAA, and HITRUST audits by collecting evidence and tracking remediation.
  • Maintain and update security policies, standards, and procedures, and partner with Legal, Compliance, IT, and business teams to resolve findings.
  • Lead third-party risk assessments, vendor security reviews, phishing simulations, and other recurring cybersecurity calendar activities while identifying automation opportunities and reporting security metrics.

Requirements

  • 3+ years of experience in information security, risk, or compliance.
  • Experience in regulated environments, with healthcare preferred.
  • Familiarity with HIPAA, SOC 2, HITRUST, or NIST frameworks.
  • Experience with cloud and SaaS security environments, including AWS and O365.
  • Strong analytical skills and the ability to clearly communicate risk.
  • Relevant certifications such as Security+, CISSP, CISM, or CISA are a plus.
  • Hands-on experience with IAM, IdP, SSO, SCIM, and privileged access management tools is preferred.
  • Experience with SIEM platforms, log analysis, and vulnerability management tools is preferred.
  • Scripting or automation experience with Python, PowerShell, or similar tools is preferred.
  • Experience supporting audits and preparing evidence, especially for SOC 2, HIPAA, and HITRUST, is preferred.
  • Experience working with healthcare data and protecting PHI is strongly preferred.

Benefits

  • Compensation of $100,000 to $115,000 plus additional variable compensation based on performance.
  • Great health insurance with 100% of medical, dental, and vision premiums covered for teammates and 50% for dependents.
  • 401(k) match of 100% of teammate contributions up to 5% of salary, subject to IRS limits.
  • Flexible vacation policy to unplug and recharge when needed.
  • Generous paid parental leave for birth and non-birth parents.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Analytics Manager, Full Stack (Fraud Analytics)

Affirm 1K-5K Diversified Financial Services

Affirm is hiring a Fraud Strategy & Analytics team member to lead fraud monitoring and escalations while partnering across teams to improve detection and decisioning as the company scales internationally.

Machine Learning Python SQL
20 minutes ago

Senior Cybersecurity Risk Analyst

American Institutes for Research 1K-5K Professional Services

AIR is hiring a Senior Cybersecurity Risk Analyst to support institution-wide security, risk, and compliance efforts across advanced testing, monitoring, assessments, and client-facing security activities.

AWS Azure Cybersecurity GCP Penetration Testing
1 hour, 20 minutes ago

Manager, Security Operations

Marqeta 251-1K Diversified Financial Services

Marqeta is hiring a Manager of Security Operations to lead its security operations program, overseeing incident monitoring, detection, response, and continuous improvement in a flexible remote-first environment.

AWS CrowdStrike Cybersecurity DDoS SIEM SOC
1 hour, 20 minutes ago

Intern - Security Operations

Marqeta 251-1K Diversified Financial Services

Marqeta is hiring a Security Operations Intern for a 12-week remote program in Canada to support incident response, SOAR automation, and tabletop exercises for its Product and Infrastructure Security team.

AWS Bash Cybersecurity Linux Python SIEM
2 hours, 20 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers