Security Analyst II
Trean Insurance GroupAbout the role
Description
**Please note: Trean will not sponsor applicants for work visas.**
POSITION SUMMARY:
The Security Analyst will administer IT security systems to protect the organization's digital assets from unauthorized access. Partner with IT leadership to develop and execute organization-wide best practices for IT security, support cyber security awareness campaigns, and proactively keep the company's security systems up to date. Work independently to monitor computer networks for security-related issues, document and escalate critical issues and incidents, and work with external & internal partners frequently to address security-related issues.
KEY RESPONSIBILITIES:
- Enforce information security policies as part of the overall IT security program.
- Manage and maintain security measures and controls to protect computer systems, networks, and data.
- Comprehend and enforce standards and procedures for compliance with the statutory and regulatory requirements covering internal and external parties, physical security systems, internet, and computer systems.
- Manage and maintain vendor risk management procedures: vendor classification, vendor assessments, and vendor performance reviews.
- Protect digital files and information systems against unauthorized access, modification, or destruction.
- Remediate vulnerabilities discovered on internal and external security audits.
- Manage network intrusion detection, and prevention systems.
- Detect, analyze, respond, and report information security incidents based on companies Incident Response Policy.
- Improve information security awareness and compliance across the company.
- Assist with and lead a “security culture” within the organization.
- Maintain consistent identity and access management.
- Stay current on the latest intelligence, including hackers’ methodologies, to anticipate security breaches.
- Maintain or obtain professional and technical knowledge and industry certifications.
- Make recommendations to managers about security advancements to best protect the company's systems
- Perform other activities, duties, and assignments as needed or requested.
Requirements
MINIMUM QUALIFICATIONS:
- 3-8 years or more of work experience as a network/system engineer, security analyst, penetration tester, forensics specialist, or equivalent combination of education and experience. Insurance industry knowledge preferred.
- Any of the following cyber security certifications are preferred: Certification(s) with an emphasis on security preferred. CompTIA Security+, Microsoft Certified: Security, Compliance, and Identity Fundamentals, any ISACA certifications, or any ISC2 certifications.
- Knowledge of the following topics preferred:
- Auditing, monitoring, and risk assessments
- Security Incident and Event Management (SIEM), log management
- HIPAA, HITRUST, ISO 27001, NIST, PCI-DSS, ITIL, COSO, COBIT, NAIC Data Security Model Law, CCPA, NYDFS, CIS or similar regulations/frameworks
- Physical and logical access control
- TCP/IP, switching, routing, VPNs, Firewalls, and Unified Threat Management (UTM) technologies
- Intrusion Detection/Prevention Systems (IDS/IPS) technologies
- Authentication systems, including MFA
- Vulnerability assessments, penetration testing,
- Social engineering
- Data encryption protocols and algorithms
- Data classification and data loss prevention (DLP)
- Microsoft online services: Intune Mobile Device Management (MDM), Microsoft Azure AD, and security center, Microsoft 365 Defender.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s