Akraya
Akraya

61 Akraya Information Security Analyst Jobs Hiring Near You

Information Security Analyst: Role Every Regulated Industry Is Competing to Fill Last updated: May 27, 2026 There is a specific type of security professional that a hospital's CISO calls when the ...

Information Security Analyst

Hawthorne, CA · On-site +1

$110K - $130K/yr

INFORMATION SECURITY ANALYST We are looking for an Information Security Analyst to join our Information Security team. This role is the operational backbone of our security services, focused on ...

Information Security Analyst

Charlotte, NC · On-site

$43.59 - $51.59/hr

Genesis10 is currently seeking an Information Security Analyst for a contract position with a Global Financial Institution located in Charlotte, NC, Las Colinas, TX, or Chandler, AZ. This is a 12 ...

Information Security Analyst

Hawthorne, CA · On-site +1

$110K - $130K/yr

INFORMATION SECURITY ANALYST We are looking for an Information Security Analyst to join our Information Security team. This role is the operational backbone of our security services, focused on ...

next page

Showing results 1-20

Akraya Jobs Information

What is it like to work at Akraya?

Akraya is a professional staffing firm that values collaboration and innovation, fostering a dynamic work environment where employees can grow and contribute to the company's mission.

Akraya's team structure is designed to support a consultative approach, with a focus on building strong relationships with clients and candidates. The company's headquarters is located in the heart of Silicon Valley, providing access to a diverse range of industries and technologies.

Working at Akraya may appeal to individuals who are passionate about the staffing industry and enjoy a fast-paced, entrepreneurial environment, with opportunities to develop their skills and advance their careers in a rapidly growing company.

What makes Akraya an attractive place to work?

Akraya is a staffing and recruitment agency that specializes in providing IT and professional staffing solutions to clients across various industries. The company offers a dynamic and collaborative work environment that values innovation, teamwork, and employee growth, with a focus on delivering exceptional service to clients and candidates alike. By joining Akraya, professionals can gain valuable experience, develop their skills, and contribute to the company's mission of connecting talented individuals with exciting career opportunities.
Infographic showing various Information Security Analyst job openings at Akraya in the United States as of August 2026, with employment types broken down into 55% Full Time, 43% Temporary, and 2% Contract. Highlights an 67% Physical, 12% Hybrid, and 21% Remote job distribution.

Information Security Analyst

TomorrowDesk

Arlington, WA • On-site

$85 - $132/hr

Other

Medical, Retirement

Posted 4 days ago


Job description

Information Security Analyst: Role Every Regulated Industry Is Competing to Fill

Last updated: May 27, 2026

There is a specific type of security professional that a hospital's CISO calls when the Office for Civil Rights opens a HIPAA audit. It is not the SOC analyst triaging firewall alerts. It is not the penetration tester who ran last quarter's red team exercise. It is the information security analyst: the professional who understands where sensitive data lives, how it flows, what legal framework governs it, and whether the organization can prove it is protected.

That distinction matters more in 2026 than it ever has. GDPR enforcement has reached over €7.1 billion in cumulative fines, with €1.2 billion levied in 2025 alone. Eight new U.S. state privacy laws came into effect last year. The EU AI Act reaches full enforcement for high-risk systems in August 2026. The SEC's cybersecurity disclosure rules are forcing public companies to formalize incident reporting. Every one of these regulatory developments creates demand for a specific kind of analyst: one who can translate legal obligations into security controls, document the evidence, and communicate the risk to people who make financial decisions.

If you are building a career, we are discussing what information security analysts actually do, how the role differs from adjacent titles, which sectors hire the most and pay the most, how to enter the field from where you stand today, and what the next decade looks like for professionals who build expertise at the intersection of security, regulation, and enterprise risk.

What an Information Security Analyst Actually Does

The BLS official occupational description for information security analysts (SOC code 15-1212) is intentionally broad. It covers everyone from a Tier 1 SOC analyst at a tech startup to a senior risk officer at a federal defense agency. That breadth creates genuine confusion for people researching the career.

Here is the practical distinction that experienced practitioners and hiring managers actually apply.

"Cybersecurity analyst " typically describes someone whose primary operating environment is threat detection and response: monitoring SIEM dashboards, investigating alerts, containing incidents, hunting for adversarial activity inside live networks. Their output is operational. Their day is event-driven. Something happens, they respond.

"Information security analyst" describes someone whose primary operating environment is the organization's information itself: what data exists, who has access to it, what controls govern it, whether those controls satisfy applicable legal and regulatory requirements, and what happens when they fail. Their output is a combination of documented policy, risk assessments, control evidence, and strategic recommendations to leadership. Their day is more structured, more stakeholder-facing, and more deeply embedded in the governance layer of the organization.

Neither definition is perfectly clean. Many professionals do both. But the distinction maps to real hiring patterns. Healthcare systems post "information security analyst" roles requiring HIPAA expertise and risk assessment experience. Defense contractors post "information security analyst" roles requiring FISMA knowledge and security clearances. Banks post "information security analyst" roles requiring familiarity with SOX, PCI DSS, and the NIST Cybersecurity Framework. These employers are not looking for SOC operators. They are looking for people who can run the governance program.

The WiCyS research publication captures this well: where the two titles diverge in practice, "information security analyst" more often deals with internal concerns, policy, and regulatory adherence, while "cybersecurity analyst" more often refers to external threats and online attack surfaces.

The Regulatory Engine Behind the Demand

An information security analyst is one of the few technology roles where regulatory change is a direct driver of job creation. Understanding this engine helps you position yourself in sectors where demand is structurally strongest.

The federal compliance ecosystem is the largest single employer of information security analysts in the United States. Every federal agency must comply with FISMA (the Federal Information Security Modernization Act), which requires implementing a documented information security program, conducting annual assessments, and reporting to Congress. Agencies do this through the NIST Risk Management Framework: a seven-step process that categorizes systems by risk, selects and implements security controls from NIST SP 800-53, assesses control effectiveness, authorizes systems to operate, and monitors continuously.

Information security analysts who understand the RMF process are essential to this machinery. They do not just implement the controls. They write the System Security Plans (SSPs), conduct Security Control Assessments (SCAs), manage Plan of Action and Milestones (POA&Ms), and shepherd systems through the Authorization to Operate (ATO) process. This work requires a specific combination of technical knowledge, documentation discipline, and regulatory fluency. It is not glamorous. It is in extremely high demand.

Healthcare operates under HIPAA's Security Rule, which requires covered entities and business associates to implement administrative, physical, and technical safeguards for protected health information. Healthcare is also the sector that has experienced the costliest data breaches in the U.S. for 14 consecutive years, according to IBM's Cost of a Data Breach data. The average breach in healthcare now exceeds $9.7 million. That creates sustained institutional pressure to hire and retain qualified information security analysts regardless of broader economic conditions.

Financial services faces layered compliance requirements, including SOX for public companies, PCI DSS for card data environments, GLBA for consumer financial data, and New York's NYDFS Cybersecurity Regulation (23 NYCRR 500), which has become a model for state-level financial cybersecurity requirements across the country. The SEC's final cybersecurity disclosure rules, which took effect in 2023 and are now fully embedded in public company operations, require material incident reporting within four business days and annual disclosure of cybersecurity risk management programs. Every one of these obligations generates demand for information security analysts who can build, document, and audit the underlying programs.

The practical implication: information security analyst roles are growing fastest not in pure technology companies, where "cybersecurity analyst" remains the dominant title, but in regulated industries where legal obligations create mandatory, budget-protected demand.

Information Security Analyst Salary: Sector Premium Breakdown

The BLS median salary for information security analysts stands at $124,910 as of May 2024, the most recent federal data available. That number is accurate for the broad occupational category. It obscures the variation that matters most for career decisions.

The federal government and defense present a more complex compensation picture than the headline number suggests. Direct federal employment uses the General Schedule pay system. In the Washington-Baltimore-Arlington locality table for 2026, a GS-11 information security analyst earns roughly $85,000 to $111,000 with locality pay included. A GS-12 earns approximately $102,000 to $132,000. A GS-13 runs $122,000 to $158,000. Base pay appears modest compared to the private sector. But total compensation is stronger than it looks: Federal Employee Health Benefits (FEHB), the FERS pension system, Thrift Savings Plan with employer matching, and generous leave accrual often add 25 to 35 percent to the effective value of the compensation package.

Defense contractors offer a different proposition. Firms like Booz Allen Hamilton, Leidos, CACI, and SAIC pay significantly more than federal direct employment, particularly for roles requiring security clearances. A Secret clearance adds $5,000 to $10,000 over an uncleared baseline. A Top Secret clearance adds $15,000 to $25,000. TS/SCI access in the NSA and CIA contractor ecosystems, particularly for analysts with full-scope polygraph clearances, commands premiums of $20,000 to $40,000 above standard information security roles. Information security analysts with active TS/SCI clearance in the DC metro area average $140,000 to $170,000 according to ClearanceJobs compensation data. The pool of qualified candidates for these roles is tightly constrained because the clearance process itself takes 6 to 18 months, which means cleared analysts command structural premiums regardless of experience level.

Financial services pays the highest industry median for information security analysts, with finance and banking roles averaging $135,000 at the median according to SANS Security Salary Survey data. Investment banks, trading firms, and payment processors sit at the upper end. A mid-level information security analyst with CISA or CISM certification at a major bank in New York can realistically earn $130,000 to $165,000 in base salary, with bonuses that range from 10 to 30 percent on top.

Healthcare pays near the national median at approximately $102,000 for information security analysts, reflecting tighter institutional budgets than financial services or defense. However, compensation is growing. ZipRecruiter data from April 2026 puts the average healthcare cybersecurity salary at $132,962 annually. Senior information security analysts overseeing HIPAA compliance programs at large health systems earn $135,000 to $180,000. Medical device security is an emerging specialty within healthcare that commands additional premiums.

Technology companies tend to use "cybersecurity analyst" rather than "information security analyst" as a title, but for roles that do carry the information security title, particularly those focused on product security compliance, privacy engineering, and GRC programs, compensation runs $115,000 to $155,000 for mid-level professionals, with significant equity upside at growth-stage companies.

The state-level salary variation mirrors what the BLS data shows for the broader category. California tops the list at $162,486 median for information security analysts, followed by New York at $138,414, Massachusetts at $134,803, and Washington at $132,396.

How Information Security Analyst Differs From Three Titles People Confuse It With Information Security Analyst versus Cybersecurity Analyst

As covered above, the practical distinction is governance depth versus operational depth. Both titles sit under the same BLS occupational code. The information security analyst role typically involves more policy documentation, regulatory compliance work, risk assessment, and executive communication. The cybersecurity analyst role typically involves more hands‑on detection, response, and threat hunting. In many organizations, particularly mid‑sized enterprises, one person does both. In large, regulated organizations, the functions are separated.

Information Security Analyst versus Security Engineer

This is the most financially significant distinction. Security engineers design, build, and maintain the technical infrastructure that protects information: firewalls, SIEM configurations, identity and access management systems, encryption implementations, and cloud security architecture. Analysts assess, document, and communicate risk across that infrastructure. Engineers earn a persistent $25,000 premium over analysts at comparable experience levels, which makes the analyst‑to‑engineer transition one of the most financially rewarding pivots available. The prerequisite is deeper hands‑on technical capability, typically developed by specializing in cloud security, application security, or security architecture.

Information Security Analyst versus GRC Analyst

A GRC (Governance, Risk, and Compliance) analyst is a specialized subset of information security analysis focused almost entirely on the compliance and audit dimension. GRC analysts build and maintain compliance programs, conduct control assessments, manage third‑party risk, and interface with auditors and regulators. Information security analysts in enterprise settings typically do some GRC work but also retain broader security program responsibilities. In consulting firms and large regulated institutions, GRC is a distinct career track with its own certification pathway through ISACA.

Entry Level Careers: What Actually Works in 2026

The information security analyst role is accessible from multiple starting points. The path that works depends on where you are currently.

From IT or technology backgrounds

IT support, network administration, systems administration, and help desk roles are the most common entry points. Two to three years in an IT role builds the foundational understanding of enterprise systems, access management, and network architecture that information security analysis requires. Add Security+ certification, study for CISA or CySA+, and apply for junior information security analyst or security compliance analyst roles. This path is reliable and well‑worn.

From non‑technical backgrounds

The information security analyst role, more than almost any security title, has genuine career paths from non‑technical starting points. Auditors, paralegals, compliance officers, and risk analysts who develop working knowledge of security frameworks (NIST CSF, ISO 27001, HIPAA Security Rule) are competitive candidates for GRC‑focused information security analyst roles. The reason is that a large portion of the work is risk assessment, documentation, policy writing, and regulatory interpretation. These are skills that transfer from legal, audit, and business backgrounds. CompTIA Security+ provides the minimum technical credibility. CISA from ISACA is the professional credential most valued in this track.

From military and government service

Veterans with Information Assurance (IA) experience, particularly those who worked in classified environments with FISMA‑governed systems, are exceptionally well‑positioned for federal contractor information security analyst roles. Translating military IA experience into civilian credentials typically means pursuing Security+ (if not already held), adding CISA or CISSP depending on experience level, and targeting the DoD contractor ecosystem in Virginia, Maryland, Colorado Springs, San Antonio, or San Diego. Military experience with security clearances is a structural advantage. The Trusted Workforce 2.0 initiative formalizes clear