Senior Information Security Engineer
Analysis GroupAbout the role
Overview
Analysis Group is one of the largest international economics consulting firms, with more than 1,500 professionals across 15 offices in North America, Europe, and Asia. Since 1981, we have provided expertise in economics, finance, health care analytics, and strategy to top law firms, Fortune Global 500 companies, and government agencies worldwide. Our internal experts, together with our network of affiliated experts from academia, industry, and government, offer our clients exceptional breadth and depth of expertise.
The Senior Information Security Engineer will serve as a trusted security leader and subject matter expert, partnering closely with the Information Security Manager to advance the firm’s cybersecurity strategy, architecture, and operations. This role will take ownership of critical security initiatives, lead the design and enhancement of security programs, and guide cross-functional teams in implementing secure, resilient, and compliant solutions. The Senior Information Security Engineer will be responsible for architecting and managing enterprise security tools, leading incident response efforts, ensuring robust cloud security, and proactively addressing emerging threats. This position requires a deep understanding of both the firm’s business objectives and the evolving cybersecurity landscape, ensuring that security solutions are business-enabling, scalable, and aligned with industry best practices.
Essential Job Functions and Responsibilities:
- Architect and oversee enterprise identity governance initiatives and the Privileged Access Management (PAM) platform, ensuring access control frameworks meet regulatory and business requirements.
- Serve as a principal advisor to IT and business leaders on balancing business needs with security best practices in technology adoption and process design.
- Lead advanced incident response activities, including root cause analysis, threat hunting, containment, and post-incident improvement plans.
- Lead the design, implementation, and optimization of Data Loss Prevention (DLP) solutions and related controls to safeguard sensitive data and prevent breaches.
- Define and enforce robust cloud security strategies, including Netskope and other zero trust/SASE solutions.
- Drive the maturity of the identity and access management program across cloud services, high-performance computing environments, and hybrid infrastructures.
- Provide senior-level oversight of information security tools and operations, including SIEM platforms, EDR solutions, and advanced malware defense.
- Represent Information Security in enterprise architecture and technical project reviews, guiding secure design and implementation decisions.
- Lead investigations into phishing campaigns, targeted threats, and complex security incidents, providing actionable intelligence to stakeholders.
- Conduct continuous threat landscape assessments, recommending both tactical mitigations and strategic security investments.
- Participate in the vulnerability management lifecycle, from pre-deployment risk assessment to remediation validation and compliance reporting.
- Guide the ongoing development of the Information Security Management System (ISMS) and related governance processes.
- Mentor and coach junior security engineers, fostering skill growth and a proactive security culture across the organization.
- Partner with business stakeholders to elevate security training, awareness programs, and process improvements.
- Establish and refine advanced technical security controls to ensure visibility, rapid incident response, and adherence to compliance frameworks.
- Participate in rotational on-call responsibilities to support the firm and respond to critical security events and incidents.
Qualifications:
- Bachelor’s degree preferred; degree in Information Systems Security, Computer Science, or related field preferred.
- Industry-recognized certifications strongly preferred (e.g., CISSP, CISM, GIAC, CCSP).
- Minimum of 5 years of substantive relevant experience required.
- An ideal candidate will have 7-10 years of progressive cybersecurity experience, with at least 3 years in a senior or lead engineering role.
- Proven track record designing, implementing, and managing enterprise security architectures in cloud and hybrid environments (AWS, Azure strongly preferred).
- Advanced expertise in identity governance, privileged access management, cloud security controls, and incident response.
- Experience with data security engineering and data loss prevention solutions.
- Deep understanding of enterprise IT systems, networking, and application architecture.
- Exceptional communication, documentation, and stakeholder eng
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s