1

Senior Information Security Risk Analyst Jobs in Tennessee

This person will work closely with Information Risk on the execution and enforcement of our information security programs. Additionally, this person will be the primary contact for our due diligence ...

This person will work closely with Information Risk on the execution and enforcement of our information security programs. Additionally, this person will be the primary contact for our due diligence ...

You will Work closely with IT staff to ensure all identified risk and vulnerabilities are mitigated ... Collect, monitor, and analyze activity of logs, intrusion detection system alerts, firewall logs ...

$112K - $228K/yr

... that information in creating customized customer solutions. * Managing Risk - Assessing and ... Analytical Thinking, Effective Communications, Information Security Management, Information ...

Showing results 41-60

Senior Information Security Risk Analyst information

What is the difference between Senior Information Security Risk Analyst vs Information Security Analyst?

AspectSenior Information Security Risk AnalystInformation Security Analyst
CertificationsCISSP, CISA, CRISCCISSP, Security+, CEH
Work EnvironmentFocus on risk assessment, policy development, and strategic planningImplementing security measures, monitoring, and incident response
Employer & Industry UsageFinancial, healthcare, and large enterprises with complex security needsVariety of industries, including tech, retail, and government

Senior Information Security Risk Analysts typically handle advanced risk assessments and strategic security planning, often requiring certifications like CISSP or CISA. Information Security Analysts focus on implementing security controls and monitoring systems. Both roles are vital in maintaining organizational security but differ in scope and seniority.

How does a senior information security risk analyst typically collaborate with other departments to manage organizational risk?

A Senior Information Security Risk Analyst regularly works with various departments such as IT, legal, compliance, and business units to identify and address security risks. This collaboration often includes conducting risk assessments, reviewing new projects for potential vulnerabilities, and providing guidance on security best practices. Effective communication skills are essential, as the analyst must translate technical risks into business impacts and help teams implement appropriate controls. Close teamwork ensures that security is integrated into all business processes and that the organization remains compliant with relevant regulations.

What are the key skills and qualifications needed to thrive as a senior information security risk analyst?

A Senior Information Security Risk Analyst requires a deep understanding of cybersecurity frameworks, risk assessment methodologies, and regulatory compliance, usually backed by a degree in information security or a related field. Familiarity with tools like risk management software (e.g., Archer, RSA), SIEM systems, and certifications such as CISSP, CISM, or CRISC are typically expected. Exceptional analytical thinking, attention to detail, and strong communication skills set top performers apart in this role. These competencies are crucial to effectively identify, evaluate, and mitigate security risks, ensuring the organization's information assets remain protected against evolving threats.

What does a senior information security risk analyst do?

A Senior Information Security Risk Analyst is responsible for identifying, evaluating, and mitigating risks to an organization's information systems and data. They conduct risk assessments, develop security policies, and recommend measures to protect against cyber threats and vulnerabilities. Additionally, they work closely with IT and business teams to ensure compliance with regulations and industry standards, and they often play a key role in incident response and security awareness training.

What are popular job titles related to Senior Information Security Risk Analyst jobs in Tennessee?

For Senior Information Security Risk Analyst jobs in Tennessee, the most frequently searched job titles are:

What job categories do people searching Senior Information Security Risk Analyst jobs in Tennessee look for?

The top searched job categories for Senior Information Security Risk Analyst jobs in Tennessee are:

What cities in Tennessee are hiring for Senior Information Security Risk Analyst jobs?

Cities in Tennessee with the most Senior Information Security Risk Analyst job openings:

Infographic showing various Senior Information Security Risk Analyst job openings in Tennessee as of August 2026, with employment types broken down into 1% As Needed, 74% Full Time, 21% Part Time, and 4% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution.

Full-time

Re-posted 19 days ago


Job description

POSITION SUMMARY

The Sr. Analyst - IT Security designs, implements, and supports enterprise security technologies and processes that protect information assets in hybrid (cloud + on-premises) environments. Primary duties include engineering and hardening security platforms, integrating security controls into CI/CD pipelines, automating detection and response workflows, conducting risk and vulnerability assessments, and serving as a technical lead during cybersecurity incidents. The role collaborates with infrastructure, DevOps, application, and operations teams to ensure systems are securely configured, monitored, and compliant with applicable frameworks and business requirements.

ESSENTIAL FUNCTIONS

May perform any or all of the following duties:

  • Design, deploy, and manage security solutions (firewalls, Cloudflare WAF/bot mitigation, SIEM, EDR/AV, IDS/IPS, DLP, vulnerability-management platforms).
  • Harden Linux (Ubuntu), Windows, network, and cloud services in alignment with CIS, NIST, and vendor best practices.
  • Integrate security tooling into cloud (AWS/Azure/GCP) and on-prem environments, ensuring continuous logging and monitoring.
  • Develop scripts to automate security tasks, orchestration workflows, and reporting.
  • Build automated detection and response playbooks within SOAR/SIEM or equivalent platforms.
  • Maintain high-fidelity alerts, dashboards, and security metrics in SIEM and related logging platforms.
  • Monitor Cloudflare traffic for DDoS, bot, and application-layer attacks, tuning rules and rate-limiting policies as needed.
  • Gather and disseminate threat-intelligence indicators to stakeholders.
  • Serve as a key member of the Cybersecurity Incident Response Team (CIRT/IRT), leading forensic investigations, root-cause analysis, containment, and recovery.
  • Optimize SIEM use-cases and maintain runbooks for both automated and manual response procedures.
  • Participate in a rotating on-call schedule for after-hours security events.
  • Conduct secure source-code reviews and perform SAST, DAST, and software-composition analysis for new and existing applications.
  • Integrate security checks into CI/CD pipelines; enforce secure configuration in infrastructure-as-code and deployment workflows.
  • Provide secure-coding guidance to development and digital-integration teams.
  • Perform risk assessments on business applications, cloud resources, and data-center systems, document findings and track remediation.
  • Engineer and document controls that satisfy PCI-DSS, SOX, NIST, GDPR, and related requirements.
  • Create and maintain key cybersecurity metrics and compliance dashboards.
  • Contribute to security-architecture decisions for network, endpoint, and cloud solutions.
  • Evaluate emerging security technologies and recommend adoption or configuration changes based on threat landscape and business needs.
  • Act as a subject-matter expert (SME) for security best practices across infrastructure, DevOps, and application teams.
  • Partner with stakeholders to design secure solutions and support vulnerability remediation initiatives.
  • Maintain current knowledge of evolving threats, tools, and mitigation strategies.
  • Produce executive-level security reports and assist with other cybersecurity tasks as assigned.

POSITION QUALIFICATIONS/CORE COMPETENCIES

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or related field (or equivalent experience).
  • 5+ years of hands-on experience in cybersecurity engineering or infrastructure security roles.
  • Preferred certifications: CISSP, OSCP, GIAC (GSEC, GCIA, GCIH), or equivalent.
  • Deep technical knowledge of:
  • Network protocols, firewalls, proxies, IDS/IPS
  • Cloud platforms (e.g., AWS, Azure, GCP) and securing cloud-native services
  • Cloudflare Enterprise traffic monitoring & threat hunting
  • Endpoint protection and EDR tools
  • Security monitoring and SIEM solutions (e.g., Elastic, Lima Charlie)
  • Vulnerability scanning tools (e.g., Tenable, Burp Suite)
  • Identity and access management (IAM), MFA, and SSO
  • Strong scripting or automation skills (e.g., Python, PowerShell, Bash)
  • Knowledge of secure software development and DevSecOps practices is a plus
  • Experience engineering controls for compliance with security standards and frameworks (PCI, NIST, CCPA)
  • Excellent communication skills and ability to translate technical risk into business impact

WORK ENVIRONMENT

  • The Restaurant Support Center is a fast-paced, high-volume, deadline-driven environment.

PHYSICAL DEMANDS

  • Sitting for extended periods, using the telephone, typing, and/or operating a computer and/or mouse.
  • Travel as needed: approximately five (5)%.