Senior Information Security Specialist
Quick Summary
Perform and maintain third-party risk assessments and track vendor remediation activities. Support coordination and analysis of internal and external security testing,
Halcyon is seeking a seasoned and collaborative Senior Information Security Specialist to support the advancement of our cybersecurity and GRC (Governance, Risk, and Compliance) programs. In this role, you will play a critical part in strengthening our enterprise-wide security posture by coordinating across teams, managing third-party risk, supporting compliance initiatives, and maturing internal security processes and documentation. Your responsibilities will span operational security, risk assessment, policy development, and incident response preparedness.
Responsibilities
~1 min read- →Perform and maintain third-party risk assessments and track vendor remediation activities.
- →Support coordination and analysis of internal and external security testing, including vulnerability scans and penetration tests.
- →Develop, track, and follow up on corrective action plans for identified security gaps or audit findings.
- →Collaborate with managed security service providers and internal stakeholders to monitor and manage security events and escalations.
- →Partner with engineering and operations teams to ensure implementation of security and compliance requirements across the organization.
- →Assist in developing, maintaining, and communicating information security policies, standards, and procedures.
- →Coordinate security incident response planning, disaster recovery testing, and business continuity exercises.
- →Monitor and support enforcement of technical and administrative security controls across the enterprise.
- →Stay current with evolving security and privacy regulations and frameworks (e.g., SOC 2, ISO 27001, TX-RAMP, FedRAMP).
Requirements
~1 min read- 5+ years of experience in information security, GRC, or IT risk management.
- Strong understanding of cybersecurity concepts, controls, and risk frameworks.
- Demonstrated experience with third-party risk management processes and tooling.
- Proven ability to coordinate security testing and vulnerability management efforts.
- Excellent communication, documentation, and cross-functional collaboration skills.
- Ability to assess and implement technical and administrative controls across cloud and hybrid environments.
- Experience with regulatory compliance and audit support in fast-paced environments.
- Hands-on participation in incident response or disaster recovery exercises is a plus.
- Experience with compliance platforms (e.g., Drata, Vanta).
- Knowledge of security frameworks beyond SOC 2 and ISO 27001, such as NIST 800-53 or CIS Controls.
- Familiarity with secure software development practices or DevSecOps principles.
- Background in auditing or supporting third-party security assessments.
- Experience with Microsoft 365 and/or Google Workspace security configuration.
- Exposure to regulatory environments such as HIPAA, GDPR, or CCPA.
- Certifications such as CISSP, CISA, CISM, Security+, or similar are a plus.
Location & Eligibility
Listing Details
- Posted
- September 11, 2026
- First seen
- September 11, 2026
- Last seen
- September 12, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 76%
- Scored at
- September 11, 2026
Signal breakdown

Threats like ransomware are designed to evade modern security tools, and just one miss can have a catastrophic impact on your organization.
View company profilePlease let Halcyon know you found this job on Jobera.
3 other jobs at Halcyon
View all →Explore open roles at Halcyon.
Similar Information Security Specialist jobs
View all →Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.