The Senior Analyst, Cybersecurity supports Nightingale Collegeโs security operations, vulnerability management, vendor risk management, and access governance activities. This roleย monitorsย security events, coordinates investigations and remediation, performs vendor security assessments, and helps mature information security processes, reporting, policies, and controls.ย
Monitor, triage, document, and escalate security alerts, phishing reports, suspected account compromise, malicious email, suspicious forwarding rules, and endpoint security events.ย
Coordinate with managed detection and response, secure access, identity and collaboration, and IT teams to investigate alerts and complete containment or remediation actions such as password resets, session revocation, ticket follow-up, and evidence collection.ย
Operate vulnerability management workflows using a vulnerability management tool and related endpoint data, including recurring reporting, prioritization, remediation coordination, and security stack coverage review.ย
Perform third-party risk assessments for new and existing vendors, including review of SOC 2 reports, HECVAT responses, ISO certifications, bridge letters, security questionnaires, access controls, SSO/MFA, encryption, and data protection practices.ย
Prepare vendor assessment summaries,ย identifyย risks and follow-up items,ย maintainย assessment documentation, and support vendor inventory, reassessment, and reporting processes.ย
Support access governance, privileged access reviews, local administrator reviews, policy/procedure updates, SLA/KPI development, and security process improvement.ย
Leverage approved AI-enabled tools and automation technologies to accelerate analysis, summarize security documentation, improve assessment workflows, generate reports, and support operational decision-making whileย maintainingย appropriate securityย and privacy controls.ย
Create dashboards, reports, and data analysis workflows that provide actionable security metrics, trends, and performance insights.ย
Bachelorโs degree in Computer Science, Information Security, Information Technology, Cybersecurity, Engineering, or related field preferred; equivalent experience may be considered.ย
5+ years of experience in cybersecurity, information technology, security operations, vulnerability management, vendor risk, access governance, or related technical risk functions preferred.ย
Experience with identity and collaboration platforms, endpoint/security tools, vulnerability management tools, ticketing systems, and vendor security documentation preferred.ย
Working knowledge of incident response, vulnerability remediation, third-party risk management, MFA/SSO, access controls, encryption, NIST CSF, SOC 2 reports, ISO 27001 certifications, FERPA, and GLBA concepts.ย
Strong documentation, communication, analytical, stakeholder coordination, and follow-through skills.ย