Sr. Information Security Analyst

Staar Surgical

$125K — $160K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Undergraduate degree with 2-6 years or graduate degree with 0-4 years of relevant experience.
  • 6-8 years of relevant experience preferred or equivalent combination of education and experience.
  • Security certifications like CISSP, CySA+, GCIH, GSEC, or Security+ are highly desirable.
  • Strong analytical and problem-solving skills across diverse situations.
  • In-depth knowledge of cybersecurity threats, defenses, and relevant technologies.

Responsibilities

  • Define and implement information security strategies and procedures.
  • Collaborate with engineering teams to refine security policies.
  • Monitor vendor and third-party security assessments.
  • Evaluate emerging technologies for potential implementation.
  • Manage access controls and intrusion detection systems to detect anomalies.
  • Integrate security controls to minimize risks effectively.
  • Provide risk analysis and recommend mitigative actions.

Benefits

  • Opportunities for continuous learning and exposure to new assignments.
  • Collaborative work environment within a technology-focused team.
  • Potential for career advancement through mentorship roles.
Full Job Description
MAIN JOB RESPONSIBILITIES / COMPETENCIES
As a Sr. Information Security Analyst within STAAR Surgical's Information Technology team, this individual plays a critical role working closely with the business and across the Information Technology organization defining, delivering and supporting information security solutions and supporting roadmaps. In summary this position: works on information security problems that are diverse and highly complex; selects methods and techniques for identifying and advocating effective security solutions; develops approaches to address critical information security issues; and develops and administers schedules and performance requirements.
• Defines and implements information security strategies and procedures.
• Works with engineering teams to define and refine information security and systems management policies and settings.
• Monitors and assesses vendor and 3rd party information security reports/lists.
• Evaluates new and emerging products, technologies and makes recommendations to leadership concerning introduction of new technologies.
• Coordinates, administers, manages and monitors the use of access control systems security tools and intrusion detection systems to identify anomalous events and security infractions that exploit system vulnerabilities.
• Integrates information security controls into an environment to identify risks and reduce their impact.
• Provides analysis of potential risk to information security and recommends solutions.
• Creates and maintains information security documentation.
• Communicates information security procedures to users.
• Reviews and recommends changes to information security policies, including STAAR Surgical IT use policies, Data Sensitivity and Personally Identifiable Information Security Policies and procedures.
• Understands and applies principles, concepts, theories, technologies and standards of professional field.
• Develops and applies specialized knowledge within own discipline.
• Deepens knowledge through exposure to new assignments and continuous learning.
• Knowledge of related industry considerations.
• Good working knowledge and demonstrated ability utilizing systems, tools and procedures to accomplish a job.
• Builds a deeper understanding of processes, procedures, customers and organization.
• Assists program or process development and implementation.
• Coordinates activities and processes.
• Leads or provides direction for information security projects.
• Provides complex analysis of potential risk to information security and recommends innovative solutions.
• Recommends and implements changes to procedures and systems to enhance information systems security.
• Mentor junior information security personnel.
• Works on assignments where considerable judgment and initiative are required in resolving problems and making choices, recommendations, or decisions.
• Regularly exercises discretion and independent judgment on business matters.
• Performs other duties as assigned.

REQUIREMENTS

EDUCATION & TRAINING
• Preferred: Undergraduate degree and 2-6 years relevant experience or Graduate degree and 0-4 years relevant experience.
• Highly desirable: Security certifications such as CISSP, CySA+, GCIH, GSEC, Security+

EXPERIENCE
Preferred: 6-8 years of relevant experience or equivalent combination of education and work experience.

SKILLS
• Applies research, information gathering and analytical and interpretation skills to problems of diverse scope.
• Develops solutions to a variety of problems of moderate complexity.
• Screens, categorizes, evaluates, reconciles, reports and resolves data integrity issues.
• Interprets generally defined practices and methods.
• Recognizes and acts on inconsistencies in data or results and escalates unusual problems.
• Identifies issues beyond the stated situation.
• Works on assignments where considerable judgment and initiative are required in resolving problems and making choices, recommendations, or decisions.
• Regularly exercises discretion and independent judgment on business matters.
• Involved with local or business specific engagement initiatives in support of broader programs.
• Competent in security best practices and defense in depth strategies for multiple platforms (i.e., Linux/Unix, Windows, Mac).
• Competent in staying up to date on common cybersecurity threats, attacks, and TTPs.
• Competent in intrusion detection and investigations.
• Competent in incident handling and reporting.
• Competent in analyzing host-based and network logs.
• Competent in analyzing firewalls rules and configuration.
• Competent in public cloud computing platforms.
• Competent in standard cybersecurity frameworks and implementing security controls.
• Competent in managing privileged account management (PAM) solutions.
• Competent in managing vulnerability scanning solutions.
• Competent in methods of data protection, encryption, and data loss prevention (DLP) solutions.
• Competent in identity and access management methodology.
• Competent in automation scripting languages (i.e., PowerShell, Python, Bash).
• Proficient in developing and managing a security awareness training program.
• Proficient in managing endpoint protection solutions (EDR/XDR).
• Proficient in multifactor authentication (MFA) technologies.
• Proficient in managing email security gateway solutions.
• Ability to analyze more complex security issues, determine its cause and impact to the business and identify the corrective action needed to eliminate and prevent the event for the future.
• Familiar with database technology and query analysis.
• Ability to recommend security standards and procedures.
• Must possess strong verbal and written communication skills and be able to adapt to the level and nature of their audience.

Pay range is $125k - $160k - Final compensation/salary will depend on experience.

Similar Jobs

More Jobs at Staar Surgical

More Information Technology Jobs

Find similar Sr. Information Security Analyst jobs: