Our 2026 Hiring Report is out — see what 146,050 job postings say about getting hired.

Read the report →
JOB DETAILS

Information Security Analyst

CompanyCobalt Benefits Group LLC
LocationManchester
Work ModeOn Site
PostedSeptember 23, 2026
About The Company
Four brands: Blue Benefit Administrators of Massachusetts, CBA Blue, Great Bay Administrators, and EPBA. One mission: Optimize member health and experience by delivering cost-effective, tailor-made benefit programs through a data-driven and service-oriented approach. One vision: To be the foremost advocate for clients, brokers, and employees – setting the standard for value within the third-party administrator market. For more than 60 years, the Cobalt Benefits Group family of Third-Party Administrator (TPA) brands has been helping employers get more value out of every dollar spent on employee benefits through self-funding. We combine data-driven insights, flexible benefit designs, and one of the nation’s largest insurance networks to deliver affordable coverage without compromise. The result: An insurance partner that helps you reduce costs, improve outcomes, and deliver a better member experience.
About the Role

Description

  

Cobalt Benefits Group is seeking an Information Security Analyst to help safeguard information assets and technology services across cloud and on-premises environments. The analyst will monitor security controls, investigate alerts, coordinate remediation, and improve the organization’s ability to prevent, detect, and respond to cybersecurity risk.

The successful candidate will bring practical experience across multiple security domains rather than expertise in a single vendor platform. The role works closely with IT Operations, infrastructure, and application teams in a regulated environment.

  


Security Operations & Incident Response

  • Monitor managed detection and response, endpoint, identity, email, network, cloud, and security analytics platforms for suspicious activity.
  • Triage and investigate alerts; document findings; coordinate containment, remediation, recovery, and post-incident follow-up.
  • Analyze event, identity, endpoint, cloud, application, and network logs to distinguish security incidents from expected activity and false positives.
  • Maintain incident response plans, investigation procedures, escalation paths and case documentation.

Cloud, Identity & Secure Access

  • Assess and improve security across public cloud subscriptions, storage, workloads, applications, and hybrid connectivity.
  • Administer identity and access controls including multifactor authentication, conditional access, role-based access, privileged access, service identities, access reviews, and joiner-mover-leaver processes.
  • Support Zero Trust and secure access services for private applications.
  • Partner with administrators and engineers to design secure access for cloud data platforms, application hosting, and future AI-enabled services.

Data Protection, Human Risk & Insider Risk

  • Operate data security posture management capabilities to discover sensitive data, excessive access, shadow data, orphaned files, and insecure sharing.
  • Administer data loss prevention controls across email, endpoints, collaboration platforms, cloud services, applications, and file repositories.
  • Support data discovery, classification, information protection, retention, encryption, and remediation workflows for regulated and confidential information.
  • Administer security awareness training, phishing simulations, targeted education, completion tracking, and human-risk reporting.

Endpoint, Network & Application Security

  • Support endpoint detection and response, device security, mobile device management, application control, browser protection, and workstation security baselines.
  • Coordinate vulnerability and exposure management across endpoints, servers, network devices, databases, applications, and cloud workloads and prioritize remediation through patching.
  • Assess application and infrastructure changes for secure configuration, logging, access, data protection, and resilience requirements.
  • Monitor security systems, including firewalls, intrusion detection systems, to detect and respond to security incidents in a timely manner.
  • Collaborate on operating system, application, firmware, and security patching; validate remediation and document accepted exceptions.

Resilience, Governance & Continuous Improvement

  • Support backup, recovery, immutable storage, business continuity, and disaster recovery security requirements.
  • Maintain policies, standards, procedures, diagrams, and inventories.
  • Contribute to automation and repeatable analysis using scripting, query languages, and workflow integrations.
  • Evaluate emerging security requirements for cloud, software-as-a-service, and AI Agents.
  • Partner with business and technology stakeholders to establish AI governance, security controls, and risk management practices that enable the responsible use of generative AI, AI agents, automation, and machine-to-machine services.
  • Contribute to the organization's AI Risk Management Framework (AI RMF) program by supporting AI inventory management, risk assessments, control validations, policy development, monitoring activities, and ongoing governance reviews.


Requirements

Job Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent relevant experience.
  • Three to five years of experience in security operations, cloud security, infrastructure security, or a comparable role.
  • Hands-on experience investigating alerts and working across endpoint, identity, email, network, cloud, and data security controls.
  • Experience with vulnerability assessment, remediation tracking, patch management, incident response, and security control validation.
  • Understanding of data discovery, classification, data loss prevention, sensitive-information handling, and insider-risk concepts.
  • Ability to explain technical findings, business impact, and recommended actions to both technical and non-technical audiences.
  • Strong judgment, discretion, documentation, analytical thinking, and the ability to manage multiple priorities.

  Preferred Qualifications

  •   Experience in a regulated environment and familiarity with security or compliance frameworks such as NIST, MITRE ATT&CK, SOC 2, or HITRUST.
  • Experience securing hybrid environments with cloud infrastructure, productivity platforms, on-premises systems, virtualized infrastructure, and software-as-a-service applications. Working knowledge of cloud security, identity governance, and hybrid infrastructure.
  • Familiarity with security information and event management, extended detection and response, cloud security posture management, web application protection, and security orchestration.
  • Experience with scripting or security analytics using PowerShell, query languages, or comparable automation methods.
  • Relevant industry or cloud security certifications 


Key Skills
Security OperationsIncident ResponseCloud SecurityIdentity And Access ManagementVulnerability ManagementData Loss PreventionEndpoint SecurityNetwork SecurityThreat DetectionRisk ManagementComplianceScriptingSecurity AnalyticsZero TrustAI GovernancePatch Management
Categories
Security & SafetyTechnologySoftwareData & Analytics
Job Information
📋Core Responsibilities
The Information Security Analyst will monitor security controls, investigate alerts, and coordinate remediation across cloud and on-premises environments. They will also partner with IT teams to improve security posture, manage identity access, and contribute to AI governance and risk management frameworks.
📋Job Type
full time
💰Salary Range
$90,000 - $115,000
📊Experience Level
2-5
💼Company Size
155
📊Visa Sponsorship
No
💼Language
English
🏢Working Hours
40 hours
Apply Now →

You'll be redirected to
the company's application page