Senior Security Analyst

Energage•Exton, PA
•$77,000 - $82,000•Remote

About The Position

The Senior Security Analyst is responsible for advancing Energage's information security, privacy, and compliance programs by implementing and continuously improving technical controls, governance processes, and risk management practices. This role serves as a senior technical and operational resource responsible for protecting company systems, customer data, and business operations while enabling the organization's continued growth. The position partners closely with Engineering, Product, IT, Legal, HR, and business leaders to embed security and privacy into company operations, ensuring compliance with regulatory requirements and industry best practices while maintaining a practical, business-focused approach to risk management. The position reports to the Director of Information Security & Data Privacy.

Requirements

  • Bachelor's degree in Information Security, Computer Science, Information Technology, or equivalent professional experience.
  • 3+ years of progressive experience in Information Security, Cybersecurity, Security Engineering, or related discipline.
  • Experience supporting security and compliance programs involving ISO 27001, SOC 2, NIST CSF, or similar standards and frameworks.
  • Experience performing security risk assessments and vulnerability management.
  • Working knowledge of cloud security principles and technologies in environments such as AWS, Azure, or Google Cloud.
  • Strong understanding of networking, authentication, encryption, access control, and security architecture principles.
  • Strong written and verbal communication skills, including the ability to communicate security risks and recommendations to technical and non-technical stakeholders.
  • Intellectual Curiosity, someone who asks the questions to understand the” what and why”.

Nice To Haves

  • Experience supporting privacy compliance initiatives involving regulations such as GDPR and CCPA/CPRA.
  • Experience with SIEM, endpoint security, vulnerability management, identity management, and security monitoring tools.
  • One or more relevant information security, privacy, audit, or cloud certifications are preferred, such as: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Cloud Security Professional (CCSP), CompTIA Security+.
  • Equivalent or comparable industry-recognized certifications will also be considered.

Responsibilities

  • Maintain and improve network, endpoint, and related security controls.
  • Monitor security tools and investigate alerts or suspicious activity; coordinate escalation and response as appropriate.
  • Help assess and prioritize weaknesses in network and endpoint configurations.
  • Partner with IT and other technical teams to implement and maintain effective protections.
  • Participate in security reviews of systems, integrations, cloud services, and significant technology changes.
  • Identify security risks and recommend practical mitigations that account for business needs.
  • Review designs involving authentication, authorization, access control, encryption, and secure data handling.
  • Help incorporate security requirements early in projects and technology decisions.
  • Support audit and assurance activities, including ISO 27001, SOC 2, customer security assessments, and related reviews.
  • Help prepare evidence, maintain security documentation, and track findings and remediation actions.
  • Contribute to risk assessments, policies, procedures, and ongoing improvements to the security program.
  • Escalate significant risks, overdue actions, and decisions requiring leadership or business-owner input.
  • Assist with incident response, including investigation, coordination, documentation, and follow-up.
  • Support general security awareness and help employees understand and follow security practices.
  • Contribute to the Privacy Program in partnership with Legal, Product, Engineering, and other stakeholders.
  • Maintain working familiarity with CSPM, IAM, threat and vulnerability management, and other security and privacy functions so they can provide peer coverage when needed.
  • Share knowledge, maintain useful documentation, and contribute to a team that can respond flexibly as priorities change.

Benefits

  • PTO policy includes company holidays, sick time, vacation time, and floating holidays
  • Remote
  • Company pays a portion of individual health care premium
  • Option to participate in a company-sponsored 401(k)
  • Training and education
  • Professional development; all employees have access to a third party professional coach
  • Tuition reimbursement program
  • Opportunity to work for a purpose-driven organization using business as a force for good
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service