Information Security Analyst jobs in United States
cer-icon
Apply on Employer Site
company-logo

TENEX.AI · 1 day ago

Information Security Analyst

TENEX is an AI-native, automation-first Managed Detection and Response provider, seeking a detail-oriented Information Security Analyst to lead internal compliance and manage the Third-Party Risk Management program. This role involves preparing for audits, performing control monitoring, and ensuring adherence to security policies and governance standards.

Artificial Intelligence (AI)Cyber SecurityNetwork SecuritySaaS

Responsibilities

Internal SOC 1 & SOC 2 Compliance
Audit Readiness: Lead the preparation for annual SOC 1 Type II and SOC 2 Type II audits
Control Monitoring: Perform continuous testing of technical and administrative controls (e.g., access reviews, change management, encryption standards)
Evidence Collection: Coordinate with Engineering, HR, and DevOps teams to gather and organize audit evidence throughout the year
Remediation: Identify gaps in current processes and work with department heads to implement corrective actions
Third-Party Risk Management (TPRM)
Vendor Assessments: Conduct security assessments of new and existing vendors, reviewing their SOC reports, ISO certifications, and SIG questionnaires
Risk Scoring: Evaluate the risk profile of third-party tools and services, providing recommendations to leadership on whether to approve or mitigate risks
Contract Review: Partner with Legal to ensure security addendums (DSAs/BAsAs) meet our internal compliance requirements
Policy & Governance
Maintain and update the Information Security Management System (ISMS) documentation
Develop and deliver security awareness training tailored to compliance requirements
Act as the primary point of contact for client inquiries regarding our security posture

Qualification

Information SecurityCompliance (GRC)AICPA Trust Services CriteriaCloud EnvironmentsTPRM ToolsCertifications CISACertifications CRISCSoft Skills

Required

At least 2 years in Information Security, IT Audit, or Compliance (GRC)
Deep understanding of AICPA Trust Services Criteria (SOC 2) and SSAE 18 (SOC 1) along with ISO 27001, NIST-800
Familiarity with cloud environments (GCP/AWS/Azure), IAM, and vulnerability management
Experience with risk assessment platforms (e.g., OneTrust, Vanta, or Drata)
Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related field (or equivalent experience)

Preferred

CISA, CRISC, or Security+ preferred (CPA-tracked experience is a plus)

Benefits

Competitive salary and benefits package.

Company

TENEX.AI

twittertwittertwitter
company-logo
TENEX.AI is a cybersecurity company that utilizes AI and human expertise to help enterprises protect their digital assets.

Funding

Current Stage
Early Stage
Total Funding
$27M
Key Investors
Crosspoint Capital PartnersAndreessen Horowitz
2025-09-11Series A· $27M
2025-01-20Seed

Leadership Team

leader-logo
Eric Foster
Chief Executive Officer
linkedin
leader-logo
Edwin Solis
Co-Founder & Chief Revenue Officer (CRO)
linkedin
Company data provided by crunchbase