Information Security Analyst Jobs
Information Security Analyst jobs are open across finance, healthcare, government, defense, and technology, at every level from entry-level to senior and lead, with specializations in cloud security, threat intelligence, and compliance. Find a role that fits from the openings below and apply directly.
Find JobsLooking for remote work? View remote information security analyst jobs →Student or new grad? View information security analyst internships →Overview
Showing 5 of 1,303+ Information Security Analyst jobs











City: Boston
Country/Region: US
Type of Contract: Full-time Employment / Unlimited
Job Requisition ID: 12448
Assoc Dir, Information Security Governance Risk & Compliance
About Servier
Servier in the U.S. is a Boston-based, commercial-stage biopharmaceutical company launched by Servier Group in 2018. As a privately held organization, Servier is uniquely positioned to advance cutting-edge science, tackle underserved therapeutic areas and make patients the focus of every strategic decision.
Role Summary
The Associate Director, Information Security Governance Risk and Compliance serves as the functional leader for Governance, Risk and Compliance across the US affiliate, reporting to the Associate Director, Cybersecurity. This role establishes and leads the GRC operating model, governance framework, risk methodology, strategic priorities, and maturity roadmap. The role provides oversight of information security risk management, policy governance, compliance, third-party risk management, control assurance, audit readiness, and risk reporting while directing operational execution through subordinate managers, analysts, contractors, and service providers. This position partners closely with Global Information Security, IT, Legal, Privacy, Procurement, Quality, Internal Audit, and business stakeholders to ensure risks are identified, assessed, communicated, and managed in alignment with enterprise requirements. The role serves as the primary GRC advisor and enables risk-informed decision making by translating information security risk into business, operational, regulatory, and financial impact. This is a high visibility leadership role with the opportunity to build and scale a modern GRC capability aligned to Servier’s global cybersecurity strategy, enterprise risk expectations, regulatory obligations, and business growth.
Primary Responsibilities
Cyber Risk Management and Governance
Establish and lead the US information security risk management framework across the affiliate
Define risk assessment methodologies, risk taxonomy, scoring models, reporting standards, and escalation criteria
Provide oversight and challenge of risk assessments performed by the GRC team
Ensure information security risks are clearly defined, consistently assessed, and aligned to Group methodology and enterprise risk expectations
Review material risks, treatment recommendations, mitigation strategies, and risk acceptance proposals before escalation
Drive risk-based prioritization of remediation activities, investment recommendations, and control improvement initiatives
Local Risk Coordinator and GRC Program Leadership
Serve as the senior US GRC leader responsible for coordinating information security risk governance across the affiliate
Act as the primary US liaison to Global Information Security for GRC-related risk, compliance, policy, and assurance activities
Establish governance routines, program cadences, reporting expectations, and execution standards for the US GRC function
Ensure alignment between US affiliate execution and Global risk management methodology, policy baselines, and governance expectations
Escalate material risks, systemic issues, overdue remediation, and governance concerns through US and Global governance channels
Governance, Policy and Control Assurance
Establish governance expectations for information security policies, standards, procedures, control requirements, and exception management
Sponsor the local information security policy lifecycle, ensuring alignment with Global baselines, US business requirements, and regulatory obligations
Define the control assurance approach used to evaluate control design, implementation, effectiveness, and maturity
Oversee control monitoring, compliance validation, gap analysis, and continuous improvement activities
Define and monitor KPIs and KRIs measuring policy adoption, control maturity, security posture, remediation progress, and governance effectiveness
Third-Party Risk and Enterprise Risk Integration
Establish the strategic direction for third-party information security risk management across the US vendor ecosystem
Define governance requirements, risk acceptance criteria, assessment standards, and escalation paths for third-party engagements
Partner with Procurement, Legal, Privacy, IT, and business stakeholders to ensure vendor security risks are appropriately assessed and managed
Oversee integration of third-party security risk into enterprise risk management, procurement processes, contractual reviews, and business decision making
Drive cross-domain alignment across Information Security, IT, Legal, Privacy, Procurement, Quality, and business functions
Audit, Compliance and Assurance Oversight
Oversee information security audit readiness across internal audits, external audits, regulatory engagements, and assurance activities
Establish governance over evidence collection, control validation, audit response, remediation tracking, and management reporting
Ensure audit findings, compliance gaps, and control deficiencies are translated into clear risk treatment plans with defined owners, timelines, and measurable outcomes
Partner with Internal Audit, Quality, Legal, Privacy, and Global Information Security to support assurance activities and regulatory expectations
Executive Engagement and Cross-Functional Influence
Act as a trusted advisor on information security governance, risk, compliance, and assurance matters
Translate complex information security risks into business, operational, regulatory, financial, and reputational impact
Deliver executive-level reporting on information security risk posture, governance maturity, compliance status, control effectiveness, and remediation progress
Support governance committees, leadership forums, business reviews, and strategic planning discussions with clear risk-based recommendations
Represent US GRC priorities in Global information security and enterprise risk forums, influencing alignment where appropriate
Organizational Leadership and Capability Building
Lead and develop the US Information Security Governance Risk and Compliance function
Manage GRC managers, analysts, contractors, consultants, managed service providers, and supporting resources
Define the GRC organizational structure, operating procedures, quality standards, workforce strategy, and capability development roadmap
Build scalable and repeatable GRC processes aligned to information security maturity objectives and organizational growth
Identify opportunities to improve efficiency through automation, process standardization, documentation quality, tooling, and operating model maturity
Education and Required Skills
Minimum of 8+ years of experience in information security GRC, IT risk management, cybersecurity, compliance, audit, security operations, or related disciplines
Minimum of 3+ years in a leadership role with responsibility for program ownership, people leadership, functional leadership, or management of managers
Bachelor’s degree preferred in Cybersecurity, Information Technology, Information Systems, Business, Risk Management, or a related field
Deep expertise in information security risk frameworks and governance models, including NIST CSF 2.0, ISO 27001, PCI, SOX, FAIR, or similar methodologies
Experience leading policy governance, third-party risk management, compliance oversight, audit readiness, control assurance, and remediation governance programs
Strong executive communication skills with the ability to influence senior stakeholders in a global, matrixed organization
Relevant certifications such as CISSP, CISM, CRISC, CISA, CGRC, FAIR, or equivalent preferred
Travel and Location
Onsite in Boston preferred 1-2 days hybrid; Remote considered with occasional travel to Boston
Estimated travel required: 5-10%
Servier’s Commitment
Servier is committed to modeling diversity, equity, and inclusion within the industry. We are dedicated to fostering an environment that maintains equitable treatment for all and we welcome applicants who are passionate, committed, and innovative individuals. We encourage candidates to apply to our open roles as we are always willing to consider experiences and skills beyond what is listed in the job description.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Salary Range
The salary range for this role is $179,000-$212,000. An employee’s pay position within the salary range will be based on several factors including, but not limited to, relevant education, qualifications, certifications, experience, skills, geographic location, performance, and business or organizational needs. We may ultimately pay more or less than the posted range, and the range may be modified in the future. Employees in this position are also eligible for Short-Term and Long-Term incentive programs. Servier also offers a competitive and comprehensive benefits package that includes benefits such as medical, dental, vision, flexible time off (Servier provides unlimited sick time and flex time, and does not accrue time off), 401(k), life and disability insurance, recognition programs among other great benefits (all benefits are subject to eligibility requirements). For more information on our benefits, please visit this link .
Nearest Major Market: Boston
Information Security Analyst Jobs by Experience Level
Top Cities Hiring Information Security Analysts
Explore information security analyst openings in the cities hiring most right now.
See All 1,303+ Information Security Analyst Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsInformation Security Analyst Job Market
Who's Hiring
- Ryder System48

- Booz Allen Hamilton29

- General Dynamics Information Technology27

- Raytheon22

- AMERICAN SYSTEMS21

Top Industries Hiring
- Technology & Software29
- Consulting & Professional Services13
- Education12
- Retail10
- Insurance10
What Employers Look For
The qualifications that appear most often in information security analyst jobs.
- Bachelor's degree in computer science, information security, or a related technical field
- Proficiency with SIEM platforms such as Splunk, Microsoft Sentinel, or IBM QRadar
- Hands-on experience with vulnerability scanning tools like Nessus, Qualys, or Rapid7
- Knowledge of security frameworks including NIST CSF, ISO 27001, and CIS Controls
- One or more certifications such as CompTIA Security+, CISSP, CEH, or CISM
- Experience supporting incident response, threat detection, or security operations center workflows
Tips for Your Information Security Analyst Job Search
Tailor your resume to the threat model
Hiring managers scan for specific attack surfaces you've defended. Call out the environments you've secured, whether cloud-native, on-prem, or hybrid, and name the frameworks you've worked within, like NIST CSF or ISO 27001, rather than listing tools alone.
Certify strategically before you apply
CompTIA Security+, CISSP, and CEH appear in a large share of postings, but the right cert depends on the seniority level. Entry-level roles often list Security+ as a baseline, while senior and cloud-focused roles increasingly ask for CCSP or AWS Security Specialty.
Apply early to roles that fit
Migrate Mate lists information security analyst openings from across the United States in one place, so you can find roles that match and apply directly to each listing.
Filter openings by industry vertical
Security requirements differ sharply by sector. A fintech role will stress PCI DSS and fraud detection, while a healthcare opening will emphasize HIPAA controls and PHI handling. Targeting your search by industry helps you find postings where your specific compliance experience is a direct match.
Prepare for a technical screening round
Most information security analyst interviews include a hands-on component: a SIEM log analysis exercise, a vulnerability triage scenario, or a case study on an incident response workflow. Practice articulating your methodology out loud, not just your conclusions, because interviewers are evaluating how you reason under uncertainty.
Negotiate using total compensation context
When discussing offers, ask explicitly about on-call expectations, certification reimbursement, and budget for security tooling, since these vary widely across organizations and affect your real workload. Security teams with thin tooling often mean longer manual investigation hours, which is worth factoring in before you accept.
Information Security Analyst Jobs: Frequently Asked Questions
Which companies are hiring the most information security analysts?
The companies hiring the most information security analysts right now include Ryder System, Booz Allen Hamilton, and General Dynamics Information Technology, with the largest share of openings in Virginia, Maryland, and California, based on current listings on Migrate Mate as of August 2026. Demand is concentrated in sectors with high compliance obligations, including financial services, healthcare, and federal contracting.
How many information security analyst jobs are remote?
About 51% of information security analyst openings are fully remote or hybrid as of August 2026, though the share varies significantly by sub-role. Governance, risk, and compliance positions and threat intelligence analyst roles tend to be more remote-friendly, while SOC analyst and network security roles more often require on-site access to classified systems or physical infrastructure.
How do you become an information security analyst?
Start with a degree in computer science, information technology, or cybersecurity, or complete a recognized bootcamp with hands-on lab work. Earn a foundational certification like CompTIA Security+ to establish baseline credibility with hiring managers. Build practical experience through a help desk, IT support, or junior sysadmin role, then move into a SOC analyst or security operations position before stepping into a full analyst title.
Can you get hired as an information security analyst with little experience?
Yes, entry-level information security analyst roles exist, especially at managed security service providers and in large enterprise SOC teams that hire analysts to monitor alerts and escalate incidents. Candidates with no professional experience improve their chances by completing home lab projects, earning Security+ or Google Cybersecurity Certificate credentials, and contributing to capture-the-flag competitions, which give hiring managers concrete evidence of hands-on ability.
What does the information security analyst interview process look like?
Most processes start with a recruiter or HR screen focused on your background and role fit, followed by a technical interview where a security engineer or hiring manager tests your knowledge of threat detection, log analysis, and incident response. Many employers add a practical exercise, such as reviewing a SIEM alert or walking through a phishing investigation. Final rounds typically involve a panel with the security team lead and sometimes a cross-functional stakeholder from IT or compliance.
Where can I find and apply to information security analyst jobs?
You can find and apply to information security analyst jobs on Migrate Mate, which lists current openings from employers across the United States. Search the listings to find roles that match your experience level, specialization, and preferred location, then apply directly to each one that fits.
See All 1,303+ Information Security Analyst Jobs
Find roles that match your experience and apply in just a few clicks.
Find Jobs