Information Security Analyst

3 weeks ago


Jersey City, United States Saxon Global Full time

Need 10+ years of experience

Job Description:

What will I be doing?

We seek a candidate who has the technical expertise and communication skills to work closely with other teams at Hilton, such as infrastructure, cloud, external contractors, field-level IT resources, and risk management teams, as well as unaffiliated security researchers who participate in the Hilton Bug Bounty Program (BBP).

As a Senior Cyber Security Analyst on the SecPEN team, your primary responsibilities will include assisting developers with remediating vulnerabilities discovered from security testing, triaging findings that are submitted to the Hilton BBP, as well as developing Hilton BBP KPI reports for senior management.

What are we looking for?

Responsibilities:

•Track the lifecycle of bug bounty reports submitted through the Hilton Bug Bounty Program (BBP) assuring that program SLAs are met.

•Triage security vulnerabilities that are disclosed through the Hilton BBP.

•Facilitate communications as needed between the BBP and Hilton's various engineering teams, development teams, and finders.

•Collaborate with Hilton's Risk and Incident Response teams as needed to facilitate the management of reported security vulnerabilities.

•Schedule and assist with penetration and remediation testing for a wide variety of Hilton assets.

•Process and track all bug bounty payments to researchers and provide monthly expenditures.

•Analyze the data produced by Hilton's Bug Bounty Program using to surface trends and other insights which can be utilized to positively affect Hilton's security.

•Assist with the development of internal tooling to benefit the penetration testing and BBP programs.

We believe that success in this role will demonstrate itself through the following attributes and skills:

•Experience in Bug Bounty Management and experience working with shifting timelines and priorities is preferred.

•Strong oral and written communication skills with demonstrated experience presenting to various internal and external groups.

•Work effectively in situations involving uncertainty or lack of information, respond favorably to change, and react decisively in an unstructured environment.

•Demonstrated hands-on experience with penetration testing tools, such as Burp Suite or Metasploit •Deep understanding of common application security issues, such as Cross-Site Scripting (XSS) and Server-Side Request Forgery (SSRF)

To fulfill this role successfully, you should demonstrate the following minimum qualifications:

•At least three (3) years of experience in Technology or a related field •At least one (1) year of experience in a Cybersecurity-related role

It would be helpful in this position for you to demonstrate the following capabilities and distinctions:

•Bachelor's Degree, or Associate's Degree plus five (5+) years of Technology related experience, or High School Degree/GED plus ten (10+) years of Technology related experience •Experience programming in one or more of the following languages: Python, C#, JavaScript, TypeScript •Familiarity with one or more of the following technologies: Node.js, React, Express, GraphQL, IIS, Flask, ASP.NET, Active Directory (AD) •Understanding of fundamental networking related concepts, such as the OSI model, subnetting, etc.

•Relevant cybersecurity certifications (e.g., OSCP, CEH) •Prior security experience in a Fortune 500 or Hospitality environment



  • Arizona City, United States Verra Mobility Full time

    Who we are Verra Mobility is a global leader in smart mobility. We develop technology-enabled solutions that help the world move safely and easily. We are fostering the development of safe cities, working with police departments and municipalities to install over 4,000 red-light, speed, and school bus stop arm safety cameras across North America. We are also...


  • California City, United States absolute Full time

    Responsibilities of Information Security Analyst Responsible for managing/advising protection on Local Area Networks (LAN) the Wide Area Networks (WAN) firewalls routers Internet gain access to wireless methods Directory Services Network Intrusion Detection Systems (NIDS) Intrusion Protection Systems (IPS) outside communication products as well as...


  • Arizona City, United States Saxon Global Full time

    PUBLIC FACING JOB DESCRIPTION: Job Description: Information Security Analyst - Kubernetes Security American Express is on an exciting Cloud transformation journey led by a high-energy, delivery-focused team delivering security as code and integration to enable on-premise equivalent security models for cloud workloads. The Cloud Security Engineering group...


  • Arizona City, United States Saxon Global Full time

    PUBLIC FACING JOB DESCRIPTION: Job Description: Information Security Analyst - Kubernetes Security American Express is on an exciting Cloud transformation journey led by a high-energy, delivery-focused team delivering security as code and integration to enable on-premise equivalent security models for cloud workloads. The Cloud Security Engineering group...


  • Newark, New Jersey, United States Fawkes IDM Full time

    Responsibilities: Maintain and update security policies, controls, and procedures to reflect the firm’s security environment and technological changes. Respond to client security assessments, complete questionnaires, and support adjustments based on assessment outcomes. Track remediation actions, controls, and configuration changes to comply with...


  • Atlantic City, United States Semcon Group LLC Full time

    Job Type Full-time Description SEMCON supports the Federal Aviation Administration (FAA)'s mission, vision, and goals; and provides highly qualified, professional, technical, and managerial resources to satisfy our customer requirements. SEMCON is proud to offer a company culture that aligns enriching career experiences, growth opportunities, and...


  • Atlantic City, United States Semcon Group LLC Full time

    Description: SEMCON supports the Federal Aviation Administration (FAA)'s mission, vision, and goals; and provides highly qualified, professional, technical, and managerial resources to satisfy our customer requirements. SEMCON is proud to offer a company culture that aligns enriching career experiences, growth opportunities, and collaborative engagement for...


  • Atlantic City, United States Semcon Group LLC Full time

    Job DescriptionJob DescriptionDescription:SEMCON supports the Federal Aviation Administration (FAA)’s mission, vision, and goals; and provides highly qualified, professional, technical, and managerial resources to satisfy our customer requirements.SEMCON is proud to offer a company culture that aligns enriching career experiences, growth opportunities, and...


  • Jersey City, New Jersey, United States Verisk Full time

    Job Description Working as part of a team, the analyst will leverage various sources of data to classify and assess the security program and associated practices of Verisk Analytics suppliers, highlight risks and control gaps associated with the supplier's security program, categorize the potential risks based on severity, and identify potential mitigation...


  • Jersey City, United States Phaxis Full time

    The rate is $70 to $80 per hourHybrid position: 1 to 2 days onsite in NYC or Jersey City, NJResponsibilities:Oversee and maintain various security systemsStrengthen network infrastructure securityDrive security projects from conception to implementationEstablish and uphold data security standards for AWS and cloud resourcesRequired Skills:Proficiency in...


  • Jersey City, United States Phaxis Full time

    The rate is $70 to $80 per hourHybrid position: 1 to 2 days onsite in NYC or Jersey City, NJResponsibilities:Oversee and maintain various security systemsStrengthen network infrastructure securityDrive security projects from conception to implementationEstablish and uphold data security standards for AWS and cloud resourcesRequired Skills:Proficiency in...


  • Jersey City, New Jersey, United States Verisk Full time

    Job Description Verisk is seeking an Incident Response Analyst to join the Enterprise Incident Response team. The successful candidate will identify and respond to information security incidents and proactively hunt for potential threats and intrusions to Verisk systems. Main Responsibilities Respond to security incidents while following the incident...


  • Del City, United States Insight Global Full time

    Title: SOC Analyst Location: Onsite in Oklahoma City, OK Shift: Rotating shift work (6a-2p CST, 2-10p CST, and 10p-6a CST), including Saturdays and Sundays, and rotating every 3 months Required Skills and Experience - Associates or Bachelors Degree in Security or cybersecurity - 1 year of experience within SOC or Cybersecurity - Security+ Certification -...


  • Oklahoma City, United States Insight Global Full time

    Title: SOC AnalystLocation: Onsite in Oklahoma City, OKShift: Rotating shift work (6a-2p CST, 2-10p CST, and 10p-6a CST), including Saturdays and Sundays, and rotating every 3 monthsRequired Skills and Experience - Associates or Bachelors Degree in Security or cybersecurity- 1 year of experience within SOC or Cybersecurity- Security+ Certification-...


  • Oklahoma City, United States Insight Global Full time

    Title: SOC AnalystLocation: Onsite in Oklahoma City, OKShift: Rotating shift work (6a-2p CST, 2-10p CST, and 10p-6a CST), including Saturdays and Sundays, and rotating every 3 monthsRequired Skills and Experience - Associates or Bachelors Degree in Security or cybersecurity- 1 year of experience within SOC or Cybersecurity- Security+ Certification-...


  • Jersey City, United States Phaxis Full time

    The rate is $70 to $80 per hour Hybrid position: 1 to 2 days onsite in NYC or Jersey City, NJ Responsibilities: Oversee and maintain various security systems Strengthen network infrastructure security Drive security projects from conception to implementation Establish and uphold data security standards for AWS and cloud resources Required Skills: ...


  • Oklahoma City, Oklahoma, United States Marriott Full time

    Job Number Job Category Information TechnologyLocation Marriott International HQ, 7750 Wisconsin Avenue, Bethesda, Maryland, United StatesSchedule Full-TimeLocated Remotely? YRelocation? NPosition Type ManagementJOB SUMMARY:We are seeking an experienced Cybersecurity Director to lead our organization's efforts in developing and maintaining robust analytical...


  • Jersey City, United States Data Cloud Merge Full time

    Responsibilites-As a Business Analyst you are to understand and assess business requirement using best practices and modelling techniques -Your role is to be a functional expert in business processes such as Audit Tax Finance Customer Supply Chain. -You will explore gather and analyze business variables to understand challenges and develop user...


  • Jersey City, New Jersey, United States BAE Systems Full time

    Job Description We are seeking an experienced Mechanical Analyst to support our EO/IR/RF, precision pointing, and countermeasures-based products and related technologies. If selected you will be part of the Mechanical Analysis Capability Group, a cross-sector team of full-time analysts who apply their extensive knowledge and expertise to understand and...

  • Technical Analyst

    4 weeks ago


    Jersey City, New Jersey, United States Mitchell Martin Inc Full time

    Our client, the leading international insurance organization, is seeking a Technical AnalystLocation: Jersey City, NJPosition Type: ContractJob Summary:We are seeking a professional to provide support on the Application Engineering team to support General Insurance Permit to Build (PTB) governance processes. As a Technical Analyst, you will maintain, and...