Entry Level Information Security Analyst Jobs
New grad information security analyst jobs welcome recent graduates and entry level candidates with zero to two years of experience, where a strong portfolio or internship work can matter more than a long resume. Most openings are on-site and hybrid roles across Technology & Software, Education, and Electronics & Hardware, with employers like Arrowhead Pharmaceuticals, MedAire, and Walmart hiring at this level now.
Find JobsOverview
Showing 4 of 19+ Entry Level Information Security Analyst jobs









INTRODUCTION
Vestwell is the financial technology company powering the new savings economy. Our platform redefines how people save for the critical aspects of life across retirement, education, and healthcare savings needs. Today, Vestwell enables over 350,000 businesses and over 2M active savers, with over $50B in assets saved across all 50 states. Vestwell's platform serves a diverse clientele, including financial advisers, employers, third-party administrators, financial institutions, payroll providers, government agencies, and individual savers.
ABOUT THE ROLE
The Vestwell Corporate Information Technology team is looking for an experienced, meticulous and detail-oriented Information Security compliance analyst to be responsible for monitoring the compliance systems in our rapidly scaling organization. The compliance analyst's responsibilities include reviewing our SOC controls and comparing them to actions today, coming up with new automations to confirm compliance, responding to RFPs, and building a library of knowledge to speed up the RFP response program. You will work cross-functionally with teams such as Security and Engineering to identify and correct any flaws in our Compliance systems as well as Legal and Compliance to advise on best practices and policies. You should have a sound working knowledge of compliance, including audits and RFPs. You should be detail oriented with strong analytical skills and have good communication, interpersonal, and leadership skills.
YOUR ROLE AND RESPONSIBILITIES
- Manage cybersecurity risk processes, including risk registers, findings, vulnerabilities, remediation plans, ownership, escalation, and business acceptance within the Vestwell Governance, Risk and Compliance (GRC) solution.
- Manage cybersecurity compliance obligations across regulatory, contractual, and customer requirements, including NIST, ISO and SOC 1&2, and other applicable cybersecurity standards and frameworks.
- Coordinate cybersecurity audits, assessments, evidence requests, customer reviews, and remediation tracking in partnership with Legal, Compliance, IT, and business leaders.
- Support customer, vendor, supplier, and subcontractor cybersecurity risk management, including questionnaires, contract reviews, security expectations, and customer-facing services.
BASIC QUALIFICATIONS
The Necessities
- Experience with SOC, ISO, and other audits
- Experience responding to RFPs
- Experience working cross-teams to implement new compliance processes
- Vendor management, review experience
The Extras
- Familiarity with software such as:
+ Crowdstrike
+ Vanta
+ Responsive
- Led an audit response
LOCATION
This role will be based in our New York City or Austin office, and will be part of Vestwell's hybrid in-office operation.
COMPENSATION
- Salary Range: $90K - $105K base
This position is eligible to participate in the Company Bonus Pool and is eligible to receive new hire equity in the Company. Please note that salary bands are based on NY and other similar metro areas and may differ based on where the role is ultimately hired.
EMPLOYEE BENEFITS
We’re an innovative, high-growth company with an exciting future ahead. At Vestwell, we prioritize employee wellbeing through comprehensive health benefits, generous time off, and a dedicated Employee Wellbeing Committee. Our hybrid work model offers flexibility while providing access to our collaborative offices in Midtown Manhattan, Austin, King of Prussia, and Scottsdale. And, of course, as a company focused on helping people save for the future, we offer a competitive 401(k) plan.
INTERVIEW PROCESS
Our interview process starts the same for every candidate with 1-2 introductory conversations to learn more about your background, interests, and what you're looking for, while also giving you the opportunity to learn more about Vestwell and the team. From there, the process varies by role but typically includes a skills or experience-based assessment, such as a coding interview, portfolio review, or deeper discussion of your relevant experience. Successful candidates then move on to a virtual or in-person interview panel. Before extending an offer, we complete a reference check with a current or former manager and a peer. Throughout the process, we prioritize transparency, clear communication, and minimizing surprises. For your awareness you will only receive correspondence from recruiting@vestwell.com; any other domain not ending in vestwell.com is not our Recruitment team.
Vestwell’s Privacy Policy.
Attention California residents: In the course of conducting our business and complying with federal, state, and local government regulations governing such matters as employment, tax, insurance, etc., we must collect Personal Information from you. Should you accept employment with Vestwell you may view our California Privacy Rights Act here: Vestwell’s California Privacy Rights Policy.
See All 19 Entry Level Information Security Analyst Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsEntry Level Information Security Analyst Job Market
Who's Hiring



Top Industries Hiring
- Technology & Software
- Education
- Electronics & Hardware
- Banking & Financial Services
- Healthcare & Medical Services
Entry Level Information Security Analyst Jobs: Frequently Asked Questions
How do I get an entry level information security analyst job?
Start by earning a foundational certification such as CompTIA Security+ or Google's Cybersecurity Certificate, which signals readiness to employers who hire at this level. Build a home lab, document a personal project, or complete a capture-the-flag competition to give interviewers something concrete to discuss. Internships, college coursework in networking or operating systems, and any hands-on security work all strengthen an entry level application meaningfully.
Which companies hire entry level information security analysts?
Companies hiring entry level information security analysts right now include Arrowhead Pharmaceuticals, MedAire, and Walmart, based on current listings on Migrate Mate as of September 2026. At this level, hiring covers large enterprises with structured security operations centers, federal contractors with compliance-driven teams, and mid-size technology firms building out their first dedicated security function.
Are there remote entry level information security analyst jobs?
Yes, though on-site and hybrid roles still make up the majority at this stage. About 29% of entry level information security analyst openings are remote or hybrid as of September 2026, reflecting demand across distributed security teams. Many fully remote postings require candidates to be within a specific region or time zone, so check individual listings carefully before applying.
Are these new grad information security analyst jobs?
Yes, this page includes new grad, recent graduate, and junior information security analyst roles alongside other entry level postings. A new grad-friendly posting typically welcomes zero to two years of experience, accepts internships or academic projects in place of full-time history, and does not require industry certifications as a hard prerequisite. Look for language like "0-2 years," "recent graduates welcome," or "will train" as reliable signals.
Which industries hire the most entry level information security analysts?
Entry Level information security analyst roles concentrate in Technology & Software, Education, and Electronics & Hardware, based on current listings on Migrate Mate as of September 2026. These sectors drive hiring at this level because they face strict data protection requirements, high volumes of sensitive information, or regulatory mandates that require dedicated security staff even in smaller or growing organizations.