- Company Name
- Global Technical Talent, an Inc. 5000 Company
- Job Title
- Information Security Analyst
- Job Description
-
**Job Title**
Information Security Analyst – Senior Security Metrics & KRI Design Analyst
**Role Summary**
Lead the design, governance, and implementation of enterprise security metrics, Key Risk Indicators (KRIs), and Key Performance Indicators (KPIs) across a global security program. Drive the full metric lifecycle—from strategy and design to automation and executive reporting—while partnering with IAM, SOC, Vulnerability Management, Cloud Security, AppSec, GRC, and Third‑Party Risk teams.
**Expectations**
* Deliver defined metric frameworks and dashboards within agreed timelines.
* Achieve high stakeholder adoption and usage of the metrics program.
* Continuously improve data quality, reporting accuracy, and automation levels.
**Key Responsibilities**
1. **Metrics Strategy & Design** – Develop and evolve an enterprise security metric taxonomy, define formulas, thresholds, tiering, and escalation logic aligned with risk appetite and regulatory expectations.
2. **Metrics Library Management** – Build and maintain a centralized Security Metrics Library, ensuring consistent definitions and ownership.
3. **Stakeholder Engagement** – Facilitate workshops with security, technology, ERM, audit, compliance, and executive teams to socialize metrics, secure ownership, and translate technical outcomes into executive insights.
4. **Implementation & Automation** – Work with data engineering to source-to-metric mapping, automate reporting feeds, and embed metrics into BI platforms (Power BI, Tableau, Qlik).
5. **Executive Reporting** – Design executive dashboards and reporting packages; provide trend analyses, root‑cause insights, and actionable recommendations.
6. **Data Quality & Governance** – Enforce controls for accuracy, completeness, and traceability; conduct quarterly review cycles; reduce manual reporting and ensure governance compliance.
**Required Skills**
* 8+ years in cybersecurity metrics, GRC, or InfoSec BI.
* Deep understanding of SOC/Incident Response, Vulnerability Management, IAM/PAM, Cloud Security, AppSec/SDLC, and Third‑Party Risk.
* Advanced Excel, PowerPoint, and executive storytelling capabilities.
* Proficiency with at least one BI tool (Power BI, Tableau, or Qlik).
* Strong written and verbal communication; facilitation and workshop leadership.
* Proactive, ownership‑driven mindset.
**Required Education & Certifications**
* Post‑secondary education preferred but professional experience is prioritized.
* Certifications highly valued: CISSP, CISM, CRISC, Security+, ITIL Foundation.
* Experience with NIST CSF, NIST 800‑53, ISO 27001, or CIS Controls is preferred.
* Knowledge of tools such as Splunk, Sentinel, CrowdStrike, Qualys/Tenable, ServiceNow IRM/GRC, or Archer is a plus.
Mount laurel, United states
Hybrid
12-03-2026