Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Job Senior Security Analyst

PowerPlan

Senior Security Analyst / AppSec Specialist

PowerPlan is looking for every opportunity to help our customers and prospects gain more value from our suite of software solutions. We are seeking a Senior Security Analyst / AppSec Specialist to join our Information Security & Compliance team. This is a hands-on, high-impact role responsible for strengthening our application security posture, driving vulnerability management maturity, and supporting security operations across our cloud-hosted SaaS environment. The successful candidate will serve as a technical security practitioner embedded within our engineering and operations ecosystem, partnering closely with DevOps, product, and compliance teams.

To be successful in this role, you should have extensive experience with CrowdStrike Falcon, including its Next-Gen SIEM, Data Protection, CSPM, and Threat Intelligence capabilities, as well as experience coordinating penetration tests and running vulnerability assessments with Qualys. You should have hands-on experience with Rapid7, CI/CD pipeline hardening, cloud security in AWS and/or Azure, and security architecture. Experience implementing process improvements and driving program maturity aligned with NIST CSF 2.0 is essential. You should also have excellent communication, problem-solving, and analytical skills, as well as the ability to work independently and as part of a team.

PowerPlan specializes in enterprise software solutions used by organizations with complex financial, regulatory, and operational needs. We deliver secure, cloud-hosted SaaS products that help customers manage critical workflows with accuracy, transparency, and compliance.

The security team plays a central role in protecting customer trust, enabling rapid product innovation, and ensuring alignment with frameworks such as SOC 2, ISO 27001, and NIST CSF 2.0. We operate in a collaborative environment that values technical depth, continuous improvement, and responsible innovation.

Responsibilities

Key Performance Objectives (First 12 Months)

Objective 1: Implement a Centralized Application Vulnerability Management Platform (First 120 Days)

Outcome: Deploy a consolidated platform (e.g., DefectDojo) that aggregates SAST, DAST, SCA, penetration-testing, and manual-review findings within 120 days. Ensure all engineering teams have visibility into normalized, prioritized findings, with assignment and SLA workflows in place. Produce monthly reports showing coverage, SLA adherence, and remediation progress.

Impact: Provides a "single pane of glass" that enables consistent prioritization, eliminates fragmented tooling silos, and measurably reduces MTTR for application vulnerabilities. Improves audit readiness and strengthens engineering alignment by creating a unified source of truth for risk decisions.

How: Evaluate and implement the platform, integrate scanning tools and pen-test reports, configure cross-team workflows, onboard engineering groups, define remediation SLAs, and publish monthly dashboards to engineering and security leadership.

Objective 2: Lead the Annual Application + Cloud Penetration Testing Program (Annual Cycle)

Outcome: Coordinate annual penetration testing for web applications, APIs, and cloud environments; ensure final reports are processed within 30 days. Track remediation and retesting and ensure all critical/high-risk findings are addressed within SLA. Maintain audit-ready documentation for compliance teams.

Impact: Ensures independent validation of application and cloud security posture, reduces exploitable weaknesses, and directly supports SOC 2 and ISO 27001 evidence requirements. Builds leadership confidence through measurable remediation accountability.

How: Manage vendor selection and scoping, coordinate technical access and test data, review findings, facilitate engineering remediation, validate fixes, capture evidence, and update Confluence with all required artifacts and timelines.

Objective 3: Implement a Standardized Security Architecture Review Process (First 120 Days)

Outcome: Establish and operationalize a design-review process for all major new product features and third-party integrations within 120 days. Produce documented review artifacts, identified risks, and required remediation actions for development teams. Ensure findings are incorporated before release.

Impact: Reduces late-cycle rework, prevents design-level security gaps, and embeds security as a natural part of the product development lifecycle. Improves release confidence and accelerates secure deployment across the SaaS platform.

How: Create templates, facilitate threat-model discussions (e.g., STRIDE), review integration risks, track remediation items, collaborate with engineering leads, and maintain documented review outcomes in shared repositories.

Objective 4: Drive Measurable Maturity Improvements Aligned to NIST CSF 2.0 (First 12 Months)

Outcome: Deliver measurable improvements across NIST CSF functions through documented workflows, baseline control assessments, performance metrics, and quarterly KPI reporting. Create repeatable processes and audit-ready artifacts across Identify, Protect, Detect, Respond, and Recover.

Impact: Strengthens the formal structure and reliability of the security program, reduces operational and compliance risk, and enhances readiness for SOC 2 and ISO 27001 by demonstrating consistent, evidence-based maturity growth.

How: Assess current control gaps, standardize repeatable workflows, document runbooks and procedures, collaborate with engineering and compliance, automate where practical, and present quarterly maturity dashboards.

Objective 5: Strengthen Cross-Functional Collaboration Across Dev, CloudOps, IT & Compliance (First 6–9 Months)

Outcome: Implement recurring cross-team security syncs, remediation checkpoints, and shared KPI dashboards. Drive measurable improvements in SLA adherence, cloud misconfiguration reduction, recurring-vulnerability prevention, and overall operational alignment.

Impact: Builds unified, organization-wide ownership of security responsibilities, accelerates remediation cycles, and reduces risk introduced by siloed decisions or inconsistent practices.

How: Establish communication cadences, run joint review sessions, align remediation expectations, publish shared dashboards, and deliver clear visibility to leadership on cross-team security performance.

Qualifications

What You Bring

  • Hands on experience with application security scanning (SAST/DAST/SCA), pen-testing coordination, and vulnerability management platforms.
  • Strong working knowledge of CrowdStrike, Qualys, and/or Rapid7.
  • Cloud security experience in AWS and/or Azure, including IAM, logging, and posture management.
  • Experience performing or facilitating threat modeling and architecture reviews.
  • Familiarity with SOC 2, ISO 27001, and NIST CSF 2.0.
  • Strong analytical, communication, and documentation skills.
  • Ability to partner effectively across engineering, DevOps, CloudOps, IT, and compliance teams.
  • Demonstrated ability to drive process maturity and measurable improvements.

PowerPlan is an EOE

Applicant and Candidate Privacy Notice

Please note that this is a hybrid role that involves a combination of onsite work from our corporate office as well as work from home. While we strive to accommodate flexible working arrangements when sensible, there will be times when onsite work is required. This could include scheduled office days, team meetings, client meetings, or special events.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Job Senior Security Analyst in Atlanta, GA vacancy
  •  ...divh2Senior Physical Security And Safety Analyst/h2pWe are seeking a highly experienced and knowledgeable Senior Physical Security and Safety Analyst to join our Corporate Physical Security Team. As a Senior Analyst, you will play a key role in assessing and enhancing... 
    Senior
    Work at office

    Zenefits

    Atlanta, GA
    4 days ago
  •  ...every opportunity to help our customers and prospects gain more value from our suite of software solutions. We are seeking a Senior Security Analyst / AppSec Specialist to join our Information Security & Compliance team. This is a hands-on, high-impact role responsible... 
    Senior
    Work at office
    Work from home
    Flexible hours

    PowerPlan

    Atlanta, GA
    4 days ago
  •  ...Senior IT Security Analyst The Senior IT Security Analyst serves as INPO's primary cybersecurity risk authority, providing oversight and guidance to protect the organization's mission-critical operations in the nuclear power industry. The position, a combination of... 
    Senior
    Work experience placement

    INPO

    Atlanta, GA
    4 days ago
  •  ...Business consulting services. We are in search of a highly motivated candidate to join our talented Team. Job Title : IT Security Analyst Senior. Location : Atlanta, GA. About the Role: We are seeking a Security Engineer (WAF SME) to join a dynamic... 
    Senior
    For contractors
    Work experience placement
    Remote work

    Ampcus

    Atlanta, GA
    8 days ago
  •  ...Senior IT Security Analyst Asbury Automotive Group (NYSE: ABG) is a Fortune 500 company and one of the largest franchised automotive retailers in the United States. We are redefining the traditional dealership model through innovative technologies such as Clicklane... 
    Senior
    Weekly pay
    Temporary work

    Asbury Automotive

    Atlanta, GA
    6 hours ago
  •  ...seeking a team member for their People & Places Analytics, Research, and Technology (PART) team, focusing on core HCM and Workday security solutions. The role involves designing innovative technology solutions, collaborating with stakeholders for feedback, and executing... 
    Senior

    Intuit Inc.

    Atlanta, GA
    2 days ago
  • $115k

     ...Fully remote IT Infrastructure & Network Engineering & Operations Overview GovCIO is currently hiring for Senior Information Security Analyst with an active Secret clearance to plan and coordinate IT security programs and policies. This position will be located... 
    Senior
    Full time
    Currently hiring
    Remote work
    Flexible hours

    GovCIO

    Atlanta, GA
    2 days ago
  • $115k

     ...Secret Fully remote IT Infrastructure & Network Engineering & Operations Overview GovCIO is currently hiring for Senior Information Security Analyst with an active Secret clearance to plan and coordinate IT security programs and policies. This position will be located... 
    Senior
    Full time
    Currently hiring
    Remote work
    Flexible hours

    GovCIO

    Atlanta, GA
    5 days ago
  • $118.31k - $177.47k

    Senior Offensive Security & Exposure Management Analyst Location: This role requires associates to be in-office 1 - 2 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines... 
    Senior
    Work experience placement
    Work at office
    Local area
    2 days per week
    1 day per week

    Elevance Health

    Atlanta, GA
    5 days ago
  • $90.78k

     ...We are seeking a seasoned Security Governance/Risk professional to support and strengthen enterprise security governance for Federal and DoD customers. This role is responsible for performing complex risk analyses, establishing and advising on Information Assurance and... 
    Senior
    Work at office

    MAXIMUS

    Atlanta, GA
    2 days ago
  •  ...SCS Cybersecurity Offensive Security Analyst Job Description Location: This job can be located at Georgia Power HQ (Atlanta, GA) or Alabama Power HQ (Birmingham, AL). - This job requires 4 days of onsite work At Southern Company, our core objective is... 
    Full time
    Local area

    Southern Company

    Atlanta, GA
    1 day ago
  •  ...IT Security Analyst Arete Technologies, Inc. offers a set of innovative consulting and outsourcing services, bridging the gap between requirements and outputs of various dexterous and facile companies worldwide. The thrust of providing global deliverables with focus... 
    Local area
    Worldwide

    Arete Technologies Inc

    Atlanta, GA
    4 days ago
  • Security Analyst/Engineer Security Analyst/engineer 2+ years -Splunk and Splunk ES -Creating dashboards -creating queries -using transforming commands searches -Any Cisco Security device experience -Can do through analytical investigations.

    ClifyX

    Atlanta, GA
    4 days ago
  •  ...SOC Analyst Location: New York City, Boston MA, Atlanta GA Shift: 3PM to 12AM EST Mon - Fri & participate in an on-call rotation...  ...SOC Analyst serves as the first line of defense for information security operations monitoring, investigating, and responding to potential... 
    Shift work

    Axelon

    Atlanta, GA
    4 days ago
  •  ...Vulnerability Analyst Our client is a global manufacturing firm that partners with their customers to provide differentiated paper and packaging solutions that help them win in the marketplace. Our client is in Atlanta they are seeking a Vulnerability Analyst is responsible... 
    Work at office
    Remote work
    Relocation

    ERS Search

    Atlanta, GA
    4 days ago
  • Alignerr is seeking an Offensive Security Analyst to leverage real-world cybersecurity knowledge in AI training. The role is fully remote, allowing flexible working hours between 10-40 hours per week. Your responsibilities include analyzing attack paths, identifying weaknesses... 
    Remote job
    10 hours per week
    Flexible hours

    Alignerr

    Atlanta, GA
    3 days ago
  • Southern Company is looking for a Cybersecurity Analyst to oversee the endpoint security stack at their GPC HQ in Atlanta, GA. The role involves maintaining security systems, deploying security technologies, and ensuring the protection of company assets. Ideal candidates... 
    Work at office

    Southern Company

    Atlanta, GA
    4 days ago
  • $76.4k - $138.6k

    A leading global professional services firm is seeking an Offensive Security Analyst to manage and evaluate digital vulnerabilities. The role involves assessing third-party risks and implementing security standards across EY's digital assets. Candidates should have a minimum... 

    EY

    Atlanta, GA
    1 day ago
  • A leading security services company is seeking an Information Security Analyst in Atlanta, Georgia. This role involves supporting the maintenance of the security program, monitoring cyber threats, and managing email security configurations. The ideal candidate will have... 

    EMCOR Group

    Atlanta, GA
    3 days ago
  • $30 per hour

     ...the Oracle Government, Defense & Intelligence team supporting Federal Compliance and Federal Sales Teams. The Information Security Compliance Analyst is expected to work with the GDI Performance Management team to ensure documentation, processes and policies up to date... 
    Hourly pay
    Temporary work
    Internship
    Flexible hours

    Oracle

    Atlanta, GA
    4 days ago
  •  ...Overview: GA DHS - Information Security Analyst (776405) Atlanta GA This role is responsible for monitoring, detecting, analyzing, and responding to security events, managing vulnerabilities, and ensuring compliance with federal, agency, and organizational... 

    r2 Technologies, Inc.

    Atlanta, GA
    4 days ago
  •  ...Opportunity We are looking for a skilled cybersecurity professional with relevant technical experience. As the Information Security Analyst 3, reporting to the CISO, the selected candidate will perform technically and lead the hands-on technical team in administering... 

    BizTek People

    Atlanta, GA
    4 days ago
  •  ...Job Posting Assists in planning, directing, and coordinating agency activities, specifically relative to Information Security Assists in developing and enforcing the organization's security policies, standards, and guidelines, security awareness, security information... 

    BizTek People

    Atlanta, GA
    4 days ago
  •  ...in Threat Assessments and Mitigations. Assist in Information Security Investigations. Assist with Office of Information Security...  ...IRS Office of Safeguards and other third-party assessors. The analyst will need a 4-year degree in an IT or InfoSec related field.... 
    Work at office

    ClifyX

    Atlanta, GA
    2 days ago
  •  ...as electrical, mechanical, lighting, air conditioning, heating, security, fire protection, and power generation systems—in virtually...  ...Job Summary EMCOR Group, Inc. seeks an Information Security Analyst – Intel and Email who would be responsible for supporting the maintenance... 
    Full time
    Work at office
    Remote work

    EMCOR Group

    Atlanta, GA
    5 days ago
  •  ...Information Security Analyst 3 Under broad supervision, plans, directs and coordinates agency activities in the field of Information Security...  ...security programs and projects and communicate reports to senior management and the leadership teams. Develop, deliver, and... 
    Work experience placement
    Work at office
    Local area

    TriOptus LLC

    Atlanta, GA
    4 days ago
  •  ...Information Security Forensic Analyst Seeking a Information Security Forensic Analyst 1. Setup, configure, and maintain our EnCase Enterprise system. 2. Handle our forensic research for our Open Records Requests and Security Investigations. 3. Configure the eDiscovery... 

    BizTek People

    Atlanta, GA
    4 days ago
  • $80k - $100k

    Advisor Security Analyst II Location(s): Atlanta: 2300 Windy Ridge Pkwy SE, Suite750, Atlanta, GA 30339 La Vista:12325 Port Grace Blvd, La...  ...potential business impact. Escalate critical threats to senior analysts or IR teams with complete technical context and clear... 
    Full time
    Work at office

    Osaic

    Atlanta, GA
    1 day ago
  • $120k - $130k

     ...As an Information Security Staff Risk Analyst at Deluxe, you will be instrumental in maintaining our high standards of security and compliance,...  ...communicating complex ideas and updates to peers, supervisors, senior management, and stakeholders, negotiating successfully in... 
    Temporary work

    Deluxe Corporation

    Atlanta, GA
    5 days ago
  •  ...Overview: Job Title: Information Security Analyst 3/System Engineer (712525) Duration: Long-Term Location: Atlanta GA ( Hybrid) Reporting to the IT Infrastructure Manager, IT Systems Engineer (IT SE) is a member of the IT Infrastructure Team that identifies... 
    Full time
    Work at office

    r2 Technologies, Inc.

    Atlanta, GA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Job Senior Security Analyst. Be the first to apply!