Share this Job
Apply now »

Senior Information Security Analyst

Req ID:  38366
Remote Position:  Yes
Country:  US
Line of Business:  VSP Vision Care
Division:  Information Technology

VSP Global is comprised of five complementary businesses that combine high-quality eye care insurance, high-fashion eyewear, customized lenses, ophthalmic technology and retail solutions, with employees in over 23 countries. No matter the role, we’re all focused on a singular mission: to help people see. Learn more by visiting

General Summary

Under the direction of the Information Security Manager, act as a subject matter expert and technical leader concerning complex information security technology, topics and issues. Responsible for technical and specialized duties in the areas of security framework, architecture design, risk management, incident management, vulnerability management, information security program and technology implementations, with the goal of improving the overall security posture of the organization.

Essential Functions

Provide subject matter expertise in defining, evaluating and recommending/implementing information security controls and technology to ensure the protection of the organization’s assets


Lead the security architecture and technology design, identify gaps, recommend security enhancements and lead efforts to ensure security requirements are integrated and implemented


Partner with the Architecture, Infrastructure and Technology teams to review existing architecture, identify gaps, and recommend security enhancements


Assist in defining architectural and technology standards that impacts the security of systems and data


Develops, validates, maintains and implements information security policies, standards, guidelines and procedures to ensure compliance with the Information Security Program


Lead detailed risk analysis and risk assessment to identify, mitigate and control risks to infrastructure, information systems and data; advocate security and risk management to key stakeholders in order to balance security and business needs


Lead third party evaluation to ensure that their technology environment appropriately protects shared data, that contracts have the appropriate security requirements, and that those requirements are met through regular audits and assessments


Monitors changes in current threats and looks at trends for future threat analysis in order to proactively plan and design the environment to protect against current and future threats



Job Specifications

Typically has the following skills or abilities:


Bachelor’s Degree in Computer Science or related field or equivalent experience


Minimum 8 years of hands-on technical information security experience


Expert level knowledge of security principles and technologies


5+ years hands-on experience designing and implementing a variety of security solutions and technologies across multiple disciplines


Broad experience with risk and threat assessment methodologies


Proven ability to weigh business needs against risk concerns and articulate issues to business leaders


Extensive experience implementing security controls to comply with various IT regulatory compliance requirements such as HIPAA and PCI as well as various standards including ISO 27001


Strong, proven skills and ability to identify and analyze security vulnerabilities


Experience performing network and application security penetration testing and/or vulnerability management, interpreting results and remediating findings


Ability to interact with personnel at all levels of the organization and interpret complex business initiatives


Excellent written and verbal communication skills


Ability to analyze various complex issues, projects, technologies and solutions


Ability to regularly exercise discretion and independent judgment in the performance of his/her job duties


Working Conditions / Physical Demands

The working environment is generally favorable.  Lighting and temperature are adequate, and there are no hazardous or unpleasant conditions caused by noise, dust etc.


The above information in this description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.

VSP Global is an equal opportunity employer and gives consideration for employment to qualified applicants without regard to age, gender, race, color, religion, sex, national origin, gender identity, sexual orientation, disability or protected veteran status.  We maintain a drug-free workplace and perform pre-employment substance abuse testing.

Nearest Major Market: Sacramento

Job Segment: Information Security, Ophthalmic, Risk Management, Information Systems, Computer Science, Technology, Healthcare, Finance

Apply now »