Haystack
← Back to Jobs
Administrative

Sr. Security Analyst

Javen Technologies, IncChicago, IL🇺🇸United StatesPosted 22 Jul 2026

Why This Role Stands Out

This hybrid role at Javen Technologies, Inc. offers significant growth potential by allowing you to deepen your expertise in cyber risk management and vulnerability remediation across various areas. You will thrive here if you are a skilled security professional eager to contribute to a resilient security environment and collaborate with a supportive team. Apply today to leverage your risk assessment and advisory skills in a dynamic setting.

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

ROLE OBJECTIVE (Manager Perspective):

  1. Add capacity to existing security analysts and assist with operational tasks
  2. Perform security risk assessments, quantify risk, facilitate risk decisions, and provide advisory services to business and technology stakeholders.
  3. Support existing team of security analysts with different types of vulnerability remediation and vulnerability functional process improvements: (Infrastructure, Container, SAST, DAST)
  4. Support miscellaneous project work supporting Cyber Risk Management, Security Awareness, and Vulnerability Management Programs

Job Description Summary - We are seeking a skilled and motivated Sr. Security Analyst to join our team! The ideal candidate will be responsible for adding depth to the Cyber Risk Management Program, supporting the Bank's Vulnerability Management Program, Security Awareness Program, and provide hands-on support for day-to-day security operations to ensure a resilient and secure environment. The addition of this role will help establish a more mature cybersecurity risk management capability by enabling proactive security risk assessments, risk quantification, and consultation activities that complement our existing vulnerability management and operational security functions.

Requirements:

  • 4 year college degree in information technology, cyber security or equivalent experience OR Security and technology certifications are preferred (Security+, Microsoft Azure, AWS, etc).
  • Security risk assessment experience.
    • Understanding of NIST CSF, NIST 800-53, ISO 27001, CIS Controls, or similar frameworks.
    • Experience evaluating technical and administrative controls.
    • Risk scoring and risk quantification experience.
    • Strong documentation and report-writing skills.
    • Ability to communicate risk to non-technical audiences.
  • 5 years of vulnerability management experience.
  • Experience with vulnerability scanning tools such as Nexpose, Qualys or Nessus is a plus
  • Experience with Servicenow Vulnerability Response Module is a plus
  • Experience with Infrastructure, Container, SAST, DAST vulnerability remediation is a plus
  • Excellent analytical and problem solving skills.
  • Demonstrated experience evaluating security statistics to identify patterns and produce metrics that can be used for strategic decision making.
  • Be a clear and confident public speaker, able to tailor messaging around technical concepts to diverse audiences.
  • Ability to quickly learn new processes and tools
  • Naturally curious and driven to understand how technologies, applications, and business processes operate.

Key Responsibilities:

  • Add depth to the Cyber Risk Management Function of the Team.
  • Assist with efforts to quantify and analyze areas of risk in the environment.
  • Design and operationalize a robust, actively maintained Security Risk Register that informs security priorities, drives riskbased decisionmaking, and directly supports the Bank s overall security strategy through improved process, governance, and reporting.
  • Demonstrates intellectual curiosity and a desire to continuously learn, investigate security concerns, challenge assumptions, and identify emerging risks, threats, and opportunities for security improvement.
  • Work with existing staff to identify and create process improvements to the existing vulnerability management and security awareness programs
  • Work with remediation teams to create and track plans to address discovered vulnerabilities.
  • Identify and evaluate vulnerability metrics to determine areas of concern and improvement.
  • Creating and adhering to procedure documents.
  • Perform Vendor Security and Software Risk Assessments.
  • Contribute to Security Awareness efforts on an as needed basis.
  • Support Misc. operational tasks

We are looking for additional support in the below operational support areas:

  • Manage and resolve incoming service requests and incidents through a ticketing system.
  • Evaluate new technologies and solutions to ensure alignment with organizational security policies, standards, and risk tolerance before adoption.
  • Review and assess SOC2 reports as part of vendor security evaluations.
  • Review and respond to phishing emails reported by users, and escalate if necessary.

Enhancing Qualifications:

  • Familiarity of Infrastructure, Container, SAST, DAST vulnerability remediation concepts from a vulnerability management remediation perspective is a plus. This role will work with existing application security resources to enhance the existing vulnerability management program.
  • Experience conducting risk assessments is a plus
  • Self-starter who can work independently as well as in a team setting
  • Experience with Data Visualization Tools
  • Ability to think critically, ask thoughtful questions, and challenge assumptions in a constructive manner.

Similar jobs