Senior Information Security Analyst
CooperCompaniesAbout the role
CooperVision, a division of CooperCompanies (NASDAQ:COO), is one of the world’s leading manufacturers of soft contact lenses. The Company produces a full array of daily disposable, two-week and monthly contact lenses, all featuring advanced materials and optics. CooperVision has a strong heritage of solving the toughest vision challenges such as astigmatism, presbyopia and childhood myopia; and offers the most complete collection of spherical, toric and multifocal products available. Through a combination of innovative products and focused practitioner support, the company brings a refreshing perspective to the marketplace, creating real advantages for customers and wearers. For more information, visit www.coopervision.com.
Job Summary:
The Senior Information Security Analyst provides advanced security expertise across the enterprise to reduce risk. The role partners with engineering, compliance, audit, and business stakeholders to define and maintain security architecture, baselines, and standards; streamline remediation of vulnerabilities; and continuously improve Security Controls effectiveness.
Provide leadership and direction for the integration of security culture and design within business and IT strategy; work with the Engineering teams to ensure that security considerations are included in systems architecture and help to identify, evaluate, and select security solutions to meet information security/compliance needs.
Mentor and coach junior team members to develop well-rounded information security skill sets; promote a strong security culture and awareness across the organization.
Work with compliance teams to ensure solutions meet security policies and procedures.
Support compliance with relevant regulations and frameworks (e.g., SOX, HIPAA, PCI, GDPR, GLBA) and privacy laws; prepare for and participate in audits and examinations.
Administer and tune security tools (e.g., SIEM, NAC, firewalls, IDS/IPS, secure email gateway) to ensure effective monitoring and detection while enabling business operations.
Partner with Security Engineers to ensure security-by-design in systems architecture and delivery of secure solutions; participate in change/project management to validate secure designs and implementations.
Define and maintain enterprise security documents (policies, standards, baselines, guidelines, and procedures) and provide detailed hardening guidance to technical teams.
Prioritize vulnerability assessment output based on exploitability, impact, and likelihood; coordinate remediation across infrastructure, endpoints, applications, and cloud services.
Support compliance with relevant regulations and frameworks (e.g., SOX, HIPAA, PCI, GDPR, GLBA) and privacy laws; prepare for and participate in audits and examinations.
Design, scope, and lead deep technical assessments on internal and external systems.
Define incident response playbooks for IT and Information Security personnel to follow when responding to common issues (e.g., malware infection, phishing, etc.)
Act as a Subject Matter Expert within all Information Security disciplines.
Coordinate and help implement significant security projects
Contribute to Business Continuity and Disaster Recovery planning and exercises in coordination with IT and continuity team
Influence and communicate business risk and recommended mitigations to technical and non-technical audiences; document clearly for management and stakeholders.
Handle sensitive/confidential information, investigations, and incidents in a professional and confidential manner.
Perform other duties as assigned.
Travel Requirements: 5% domestic and/or international travel
Knowledge, Skills and Abilities:
- Expert knowledge of secutiry frameworks and concepts such as NIST 800-53, ISO 27001, CIS Critical Controls, the Cyber Kill Chain, MITRE ATT&CK, and OWASP.
- Have in-depth knowledge and understanding of information risk concepts and principles as a means of relating business needs to security controls.
- Deep understanding of enterprise infrastructure and security technologies including network switches/routers, firewalls/VPN, DLP, anti-malware, IDS/IPS, SIEM, SMTP/email security, Active Directory/Group Policy, DNS, DHCP, VLANs, and content filtering.
- Experience with traditional and modern security controls such as SIEM, IDS/IPS, PKI, IAM, antivirus/firewalls, EDR, threat intelligence, security automation/orchestration, deception, and application controls.
- Ability to conduct vulnerability scanning and penetration testing; incident response and digital forensics.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s