1

Infosec Jobs in Arizona (NOW HIRING)

RemOps - InfoSec Location : Phoenix AZ (onsite 3 days in office) Overview: The Information Security Analyst for the Remediation Operations team is responsible for evaluating security exceptions ...

Apply InfoSec principles to assess risks and recommend mitigations. Required Skills & Qualifications * Strong experience in SaaS assessments, vendor risk management, or cloud security. * Good ...

$52K/yr

Click on "Learn more about this agency" button below for IMPORTANT additional information. Positions may be filled as permanent, temporary or term with a full-time work schedule. This is a Direct ...

$52K/yr

Click on "Learn more about this agency" button below for IMPORTANT additional information. Positions may be filled as permanent, temporary or term with a full-time work schedule. This is a Direct ...

Manager, Cybersecurity Operations

Tempe, AZ · Hybrid

$108K - $145K/yr

A minimum of 6 years of experience in infosec roles that provide a background in IT areas such as software development, infrastructure, operations, and incident response, is required * Understanding ...

Manager, Cybersecurity Operations

Tempe, AZ · On-site

$108K - $145K/yr

A minimum of 6 years of experience in infosec roles that provide a background in IT areas such as software development, infrastructure, operations, and incident response, is required * Understanding ...

next page

Showing results 1-20

Infosec information

See Arizona salary details

$40

$69

$102

How much do infosec jobs pay per hour?

As of Aug 5, 2026, the average hourly pay for infosec in Arizona is $69.24, according to ZipRecruiter salary data. Most workers in this role earn between $46.83 and $86.92 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as an information security (infosec) professional, and why are they important?

Infosec, short for information security, refers to the practices, policies, and technologies used to protect digital and physical information from unauthorized access, disclosure, alteration, and destruction. Professionals in infosec work to secure computer systems, networks, and data from threats such as hackers, malware, and data breaches. Their responsibilities include risk assessment, implementing security measures, monitoring for suspicious activity, and ensuring compliance with relevant laws and regulations. Infosec is a critical field in today's digital world, as organizations increasingly rely on secure information to operate effectively.

What are some common challenges faced by infosec professionals when working with cross-functional teams?

Infosec professionals often collaborate with various departments, such as IT, legal, and business units, to ensure the organization’s security policies are followed. One common challenge is communicating technical risks in a way that non-technical colleagues can understand and act upon. Additionally, balancing security requirements with operational needs can lead to difficult compromises, as different teams may have conflicting priorities. Building strong relationships and fostering a culture of security awareness are key strategies for overcoming these challenges.

What are the key skills and qualifications needed to thrive as an information security (infosec) professional, and why are they important?

InfoSec, a shortening of information security, is a set of practices carried out by information and cybersecurity specialists designed to prevent hacking or unauthorized access to private information and data, databases, or services. Your responsibilities are to design or improve systems built to protect sensitive information, such as electronic health records, industry or trade secrets like proprietary code or industrial designs, or national security information. Although much contemporary InfoSec revolves around protecting digital information, there are still large amounts of physical information that must be protected from unauthorized access.

What is the difference between Infosec vs Cybersecurity Analyst?

AspectInfosecCybersecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentOrganizations' security teams, IT departmentsSecurity operations centers, IT security teams
Industry UsageBroad, including government, finance, healthcarePrimarily tech, finance, and government sectors
Job FocusOverall security policies, risk managementMonitoring, incident response, vulnerability assessment

Infosec (Information Security) is a broad field encompassing policies, risk management, and overall security strategy. A Cybersecurity Analyst typically focuses on monitoring systems, responding to threats, and vulnerability management within the broader Infosec framework. While both roles require similar certifications and work in security teams, Infosec professionals often handle strategic planning, whereas Cybersecurity Analysts are more operational.

What are popular job titles related to Infosec jobs in Arizona? For Infosec jobs in Arizona, the most frequently searched job titles are:
What cities in Arizona are hiring for Infosec jobs? Cities in Arizona with the most Infosec job openings:
Infographic showing various Infosec job openings in Arizona as of July 2026, with employment types broken down into 88% Full Time, 10% Part Time, and 2% Contract. Highlights an 67% Physical, 27% Hybrid, and 6% Remote job distribution, with an average salary of $144,027 per year, or $69.2 per hour.

RemOps - InfoSec

Inficare Technologies

Phoenix, AZ • On-site

Full-time

This job post has expired today. Applications are no longer accepted.


Job description

Role : RemOps - InfoSec
Location : Phoenix AZ (onsite 3 days in office)
Overview:
The Information Security Analyst for the Remediation Operations team is responsible for evaluating security exceptions, assessing associated risk, and driving remediation of critical and high-risk vulnerabilities across applications and platforms. This role operates within the Application Security and Infrastructure Security ecosystem, ensuring adherence to Enterprise Vulnerability standards and reducing enterprise risk exposure.
Key Responsibilities:
Exception Review & Risk Assessment
• Review and assess security exception requests for compliance with Enterprise Vulnerability standards and supporting policies.
• Validate business justifications, compensating controls, and risk responses (Mitigate, Accept, Transfer, Avoid).
• Ensure exceptions align with the Exceptions Management Program and include required documentation and leadership approvals.
• Challenge insufficient or unjustified exceptions, prioritizing remediation over risk acceptance.
Vulnerability Governance & Remediation Oversight
• Monitor and track critical and high vulnerabilities across application and infrastructure portfolios.
• Enforce remediation timelines in accordance with defined Service Level Objectives (SLOs).
• Ensure vulnerabilities exceeding SLOs are either remediated or formally documented via approved exceptions.
• Validate remediation through coordination with security tooling, rescans, or evidence-based confirmation.
Stakeholder Engagement & Reach-Out
• Proactively engage application and platform owners with critical risk exposure or past-due vulnerabilities.
• Communicate risk clearly, including exploitability, business impact, and compliance implications.
• Drive accountability through follow-ups, escalation paths, and alignment with leadership where required.
• Support application teams in understanding remediation options and security requirements.
Security Tooling & Data Analysis
• Leverage results from enterprise security tools (e.g., SAST, DAST, SCA, IRIS, Tenable, API security tools) to identify and track vulnerabilities.
• Analyze risk metrics, dashboards, and reports (e.g., Application Health, vulnerability reports) to prioritize actions.
• Correlate findings across tools to identify systemic risk patterns and recurring issues.
Policy & Standards Alignment
• Ensure adherence to:
• Application Security Policy
• Enterprise Vulnerability Standard
• Application Vulnerability Management Procedure
• Interpret and translate policy requirements into actionable guidance for engineering teams.
• Identify gaps or non-compliance and recommend corrective actions.
Continuous Threat Exposure Management (CTEM) Support
• Contribute to continuous risk identification, prioritization, and validation efforts.
• Support risk-based prioritization using exploitability, asset criticality, and exposure context.
• Assist in reducing attack surface and improving overall security posture.
Required Qualifications
Technical & Security Expertise
• Strong understanding of:
• Application Security (OWASP Top 10, secure coding practices)
• Vulnerability management lifecycle and risk-based prioritization
• Security testing methodologies (SAST, DAST, SCA, API security)
• Familiarity with enterprise security tools and platforms
• Ability to interpret vulnerability data, CVSS scoring, and exploitability context.
Risk & Governance Knowledge
• Experience with security exceptions management and risk acceptance processes.
• Understanding of SLO-driven remediation and escalation models.
• Ability to assess compensating controls and residual risk.
Communication & Stakeholder Management
• Ability to engage technical and non-technical stakeholders effectively.
• Strong written and verbal communication skills for risk articulation and escalation.
• Experience driving remediation through influence rather than authority.
Preferred Qualifications
• Experience within financial services or highly regulated environments.
• Familiarity with Enterprise Vulnerability Management or similar enterprise security frameworks.
• Exposure to CTEM practices and risk-based security operations.
• Experience working with cloud, APIs, or distributed systems.
Key Success Metrics
• Reduction in critical/high vulnerabilities past SLO
• Decrease in exception volume and aging exceptions
• Improved application security posture
• Timely engagement and remediation outcomes with application teams
• Quality and completeness of exception reviews and risk assessments
Role Positioning
This role is not a passive reviewer. It is an active risk driver responsible for:
• Enforcing security standards
• Driving remediation outcomes
• Preventing misuse of exceptions as a substitute for fixing risk