The Role \n\nLeafLink takes security exceptionally seriously. In the role of Information Security Analyst, youโll help play a key role in protecting our systems, employees, and most importantly our customers and their data. Partnering closely with key stakeholders across the organization youโll help maintain and improve our security posture, procedures, and policies while evaluating current and new technologies against emerging threats. \nWhat Youโll Be Doing \n\n\n* Evaluate, devise, and enhance our security systems against emerging standards and regulatory requirements while monitoring adversarial threats and techniques\n\n* Conduct regular security awareness training for employees & provide recommendations for improving the security posture for LeafLink\n\n* Play a key role in contributing to efforts to achieve, maintain, and enforce our SOC 2 compliance across the organization\n\n* Keep abreast of new developments within SOC 2 and security industries and ensure LeafLinkโs security policies, procedures, and postures are up-to-date, robust, and industry-leading\n\n* Participate in frequent disaster recovery and business continuity (DRBC) exercises and scenarios\n\n* Monitor security alerts and incidents, investigate and coordinate with the IT and Platform teams the appropriate, timely responses\n\n* Conduct in-depth analysis of security incidents, determine root causes, and implement corrective actions\n\n* Work with the Platform team to drive proper KPIs and reporting around threat detection and vulnerabilities\n\n* Participate in regular vulnerability assessments and penetration testing with the Platform team\n\n* Partner with the procurement team to ensure vendors meet internal security requirements \n\n* In conjunction with Platform and IT teams; manage and optimize security tools, including but not limited to firewalls, IDS/IPS, antivirus, and SIEM solutions\n\n* Stay up-to-date with the latest security technologies and trends\n\n* Conduct risk assessments to identify and mitigate potential security risks\n\n* Work closely with cross-functional teams to integrate security best practices into business processes\n\n* Communicate security risks and issues to both technical and non-technical stakeholders\n\n* Partner alongside our Security Engineer with a variety of teams including Engineering, Legal, Compliance, IT, and senior leadership to ensure security remains top of mind for all employees\n\n\n\nWhat Youโll Bring to the Team\n\n\n* Bachelor's degree in Information Security, Cyber Security, Computer Science, or a related field\n\n* Experience working in financial services\n\n* Proven experience as an Information Security Analyst, with a focus on SOC 2 compliance\n\n* Strong knowledge of SOC 2 controls and requirements\n\n* Experience with security tools such as firewalls, IDS/IPS, antivirus, SIEM, etc.\n\n* Hands-on experience with OKTA, Crowdstrike, and security hardening within Google Workplace and AWS environments is a plus\n\n* Basic knowledge of maintenance windows and patch cadence for mission-critical systems is a plus\n\n* Knowledge of industry standards and frameworks (ISO 27001, NIST, etc.)\n\n* Certifications such as CISSP, CISM, or CompTIA Security+ are a plus\n\n* Experience with Data Loss Prevention (DLP) systems is a plus\n\n* Excellent communication and interpersonal skills\n\n\n\nLeafLink Perks & Benefits\n\n\n* Flexible PTO - youโre going to be working hard so enjoy time off with no cap!\n\n* A robust stock option plan to give our employees a direct stake in LeafLinkโs success\n\n* 5 Days of Volunteer Time Off (VTO) - giving back is important to us and we want our employees to prioritize cultivating a better community\n\n* Competitive compensation and 401k match\n\n* Comprehensive health coverage (medical, dental, vision)\n\n* Commuter Benefits through our Flexible Spending Account\n\n\n\n\nLeafLinkโs employee-centric culture has earned us a coveted spot on BuiltInNYCโs Best Places to Work for in 2021 list. Learn more about LeafLinkโs history and the path to our First Billion in Wholesale Cannabis Orders here. \n\n#Salary and compensation\n
No salary data published by company so we estimated salary based on similar jobs related to Senior and Engineer jobs that are similar:\n\n
$67,500 — $115,000/year\n
\n\n#Benefits\n
๐ฐ 401(k)\n\n๐ Distributed team\n\nโฐ Async\n\n๐ค Vision insurance\n\n๐ฆท Dental insurance\n\n๐ Medical insurance\n\n๐ Unlimited vacation\n\n๐ Paid time off\n\n๐ 4 day workweek\n\n๐ฐ 401k matching\n\n๐ Company retreats\n\n๐ฌ Coworking budget\n\n๐ Learning budget\n\n๐ช Free gym membership\n\n๐ง Mental wellness budget\n\n๐ฅ Home office budget\n\n๐ฅง Pay in crypto\n\n๐ฅธ Pseudonymous\n\n๐ฐ Profit sharing\n\n๐ฐ Equity compensation\n\nโฌ๏ธ No whiteboard interview\n\n๐ No monitoring system\n\n๐ซ No politics at work\n\n๐ We hire old (and young)\n\n
\n\n#Location\nNew York City, New York, United States
๐ Please reference you found the job on Remote OK, this helps us get more companies to post here, thanks!
When applying for jobs, you should NEVER have to pay to apply. You should also NEVER have to pay to buy equipment which they then pay you back for later. Also never pay for trainings you have to do. Those are scams! NEVER PAY FOR ANYTHING! Posts that link to pages with "how to work online" are also scams. Don't use them or pay for them. Also always verify you're actually talking to the company in the job post and not an imposter. A good idea is to check the domain name for the site/email and see if it's the actual company's main domain name. Scams in remote work are rampant, be careful! Read more to avoid scams. When clicking on the button to apply above, you will leave Remote OK and go to the job application page for that company outside this site. Remote OK accepts no liability or responsibility as a consequence of any reliance upon information on there (external sites) or here.