Job Overview
This Principal Information Security Analyst role is a key contributor to strengthening an organization’s cybersecurity posture and ensuring compliance with evolving security standards. The position requires a seasoned professional capable of managing complex security challenges, leading initiatives, and mentoring team members. Ideal candidates will bring strong technical expertise, clear communication skills, and the ability to partner effectively across departments and external organizations.
Must Haves
- Bachelor’s degree or equivalent professional experience
- 8–10 years of progressive experience in information security or cybersecurity
- Strong understanding of governance, risk, and compliance (GRC) frameworks
- Proficiency in security technologies and tools such as SIEM, endpoint protection, and identity management
- Demonstrated experience leading incident response and risk mitigation efforts
- Knowledge of relevant security regulations and standards (e.g., NIST, ISO 27001, HIPAA, PCI-DSS)
- Proven ability to communicate technical information to non-technical stakeholders
- Industry-recognized security certifications (e.g., CISSP, CISM, or equivalent)
What the Client Needs You to Do
This position calls for a trusted expert who can elevate the organization’s information security maturity by leading initiatives, improving processes, and ensuring alignment with compliance requirements. You will be expected to act as a key advisor to leadership, collaborate across business and technical units, and support the development of a culture focused on data protection and privacy. Your contributions will directly reduce security risk and strengthen enterprise resilience.
Key Responsibilities
- Investigate and resolve information security incidents, determine root causes, and implement corrective measures
- Conduct comprehensive third-party risk assessments to evaluate and mitigate vendor security exposures
- Develop, review, and update information security policies and procedures in line with best practices
- Perform internal security audits to ensure compliance with organizational standards and identify areas for improvement
- Lead or participate in cross-functional security projects to enhance overall cybersecurity posture
- Partner with IT and business units to implement technical controls and improve awareness of security protocols
- Deliver training and presentations to promote understanding of security principles among non-technical teams
- Stay current with industry trends, threat intelligence, and regulatory changes to recommend appropriate program updates
- Serve as backup to the CISO, including occasional on-call responsibilities
- Provide guidance and mentorship to junior analysts or new team members
Additional Information
This is a senior-level, full-time position within an established cybersecurity program. The role is hybrid, requiring one day/week onsite in Boston, depending on organizational needs. The ideal candidate will demonstrate integrity, accountability, and a collaborative mindset, contributing to an inclusive and innovative workplace culture. Reporting directly to the Chief Information Security Officer, this position offers opportunities for strategic input and professional growth in a mission-driven environment.
W2 employees of Overture Partners who work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), 401(k) starting on day one, a variety of voluntary benefits including life and disability insurance, and sick time if required by law in the worked-in state/locality.
#25199
