Security Analyst

SMX Services and Consulting, Inc.

$80K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-6 years of experience in information security, IT risk, or GRC with hands-on implementation or audit involvement.
  • Proficient knowledge of NIST CSF 2.0 and its functions, categories, and tiers or the ability to learn quickly.
  • Experience securing cloud and SaaS environments (AWS, Azure, GCP) and understanding configurations.
  • Strong project management skills with experience coordinating multi-workstream projects.
  • Excellent technical writing skills for clear and concise documentation of policies and procedures.
  • Ability to collaborate with non-security stakeholders and communicate security requirements effectively.
  • Self-motivated with the ability to show progress independently, especially in the initial weeks.
  • Bilingual in English and Spanish.

Responsibilities

  • Implement and audit information security frameworks to ensure compliance.
  • Develop and maintain security policies and procedures aligned with industry standards.
  • Manage security assessments and coordinate with various stakeholders for completion.
  • Oversee security controls in cloud and SaaS environments to ensure effectiveness.
  • Prepare clear status reports and documentation for both technical and non-technical audiences.
  • Translate security controls into actionable tasks for engineering and administrative teams.

Benefits

  • Flexible working hours with remote work options.
  • Opportunities for professional development and training.
  • Access to cutting-edge security tools and technologies.
  • Supportive work culture promoting diversity and inclusion.
  • Health and wellness programs, including mental health resources.
Full Job Description
Qualifications:
  • 3-6 years in information security, IT risk, or GRC, including at least one framework implementation or audit program you personally worked on (NIST CSF, NIST 800-53, ISO 27001, SOC 2, CIS Controls, or similar).
  • Working knowledge of NIST CSF 2.0 - the six Functions (Govern, Identify, Protect, Detect, Respond, Recover), Categories and Subcategories, Implementation Tiers, and Organizational Profiles - or demonstrated ability to get fluent in a comparable framework quickly.
  • Hands-on experience securing cloud and SaaS environments (AWS, Azure, or GCP, plus core SaaS platforms such as identity providers, productivity suites, and endpoint tooling). You should be able to read a configuration, not just ask someone about it.
  • Demonstrated project management capability: you have kept a multi-workstream effort with distributed owners on schedule, using whatever tooling was at hand.
  • Strong technical writing. Policies, procedures, and status reports that are clear, concise, and hold up to outside scrutiny.
  • Comfort working with non-security stakeholders - engineers, IT admins, executives - and translating control requirements into work they can actually schedule.
  • Able to work independently with limited supervision and produce visible progress in the first two weeks.
  • Bilingual English and Spanish communication capabilities
Preferred Qualifications
  • Security certification such as CISSP, CISA, CRISC, CISM, Security+, or a cloud security credential (AWS Security Specialty, Azure SC-100, CCSK, CCSP).
  • PMP, CAPM, or equivalent formal project management training.
  • Experience responding to enterprise customer security reviews and vendor due-diligence questionnaires.
  • Familiarity with GRC or compliance-tracking tooling, and with scripting or automation for evidence collection.
  • Background in media, content identification, or another data-intensive technology sector.

Similar Jobs

More Jobs at SMX Services and Consulting, Inc.

More Information Technology Jobs

Find similar Security Analyst jobs: