- Salary
- $72k – $119k
- Location
- Horsham, PA (Walnut Grove), United States of America · Philadelphia · New Jersey
- Type
- Full-time
- Department
- IT
- Experience
- 7+ years
- Source
- Workday
Description
About our Team
LexisNexis Reed Tech brings clarity to innovation for businesses worldwide. We enable innovators to accomplish more by helping them make informed decisions, be more productive, comply with regulations, and ultimately achieve a competitive advantage for their business. Our Reed Tech suite of SingleSource™ for Medical Devices, SingleSource™ for Drug Products, and Navigator™ for Drug Labels enables life sciences companies to create product data management strategies and meet compliance deadlines on time. We are proud to directly support and serve these innovators in their endeavors to better humankind. For more information, please visit https://www.reedtech.com/.
About the Role
The Infrastructure Compliance Analyst III – Infrastructure Security serves as a senior security advisor to Infrastructure Engineering, partnering with Cloud Engineering, Platform Engineering, Site Reliability Engineering (SRE), and Systems Engineering teams to design, implement, and continuously improve secure infrastructure services. This role bridges the gap between Security, Governance Risk & Compliance (GRC), and Infrastructure by translating security requirements into practical engineering solutions that enable the business while reducing organizational risk
Accountabilities
- Partner with engineering teams throughout the design, implementation, and operational lifecycle to ensure infrastructure solutions are secure, scalable, resilient, and compliant.
- Interpret and translate security frameworks, regulatory requirements, and organizational security policies into actionable technical guidance for infrastructure engineers.
- Provide subject matter expertise on secure architecture, operating system hardening, identity management, cloud security, network security, encryption, certificate management, and infrastructure best practices.
- Work closely with Governance, Risk & Compliance (GRC) and Information Security teams to understand compliance objectives, security findings, audit requirements, and risk management priorities while communicating those requirements effectively to infrastructure teams.
- Guide infrastructure teams through vulnerability remediation efforts by helping prioritize findings, identifying practical remediation strategies, evaluating operational impacts, and validating successful remediation.
- Develop secure configuration standards using industry best practices including DISA STIGs, vendor hardening guidance, and organizational security baselines.
- Assist engineering teams in implementing and maintaining compliant configurations across Windows, Linux, virtualization platforms, cloud services, identity platforms, storage systems, and enterprise infrastructure.
- Aggregate, analyze, and interpret vulnerability, compliance, operational, and infrastructure data to identify trends, measure organizational risk, and recommend strategic improvements to the company’s security posture.
- Develop executive dashboards, metrics, and reporting that communicate infrastructure security health, remediation progress, compliance status, risk trends, and operational maturity.
- Collaborate with engineering leadership to prioritize security initiatives based on business risk, operational impact, and strategic objectives.
- Identify opportunities to automate security validation, compliance reporting, configuration management, vulnerability remediation, and infrastructure governance using modern engineering practices.
- Evaluate emerging technologies, security controls, and infrastructure practices to continuously modernize the organization’s security capabilities.
- Promote a “Security by Design” culture by embedding security considerations into infrastructure planning, engineering standards, operational processes, and technology roadmaps.
- Provide technical leadership during infrastructure modernization initiatives including cloud migrations, platform upgrades, operating system lifecycle management, and enterprise technology transformations.
- Participate in security architecture reviews, infrastructure design discussions, change management activities, and technical governance boards.
- Develop technical documentation, security standards, implementation guides, engineering playbooks, and operational procedures that improve consistency across infrastructure teams.
- Advise engineers on security best practices, secure engineering principles, and modern infrastructure security techniques.
- Continuously evaluate Reed Tech's infrastructure security posture and recommend long-term improvements.
- Advocate for modern security practices including Zero Trust, Infrastructure as Code, Policy as Code, Continuous Compliance, and Secure Configuration Management.
- Champion automation-first security practices that reduce manual effort while improving consistency and compliance.
Requirements
Comfortable using AI tools (e.g., Copilot, Claude) to accelerate compliance documentation and evidence review, with sound judgment on appropriate use given data sensitivity and regulatory requirements
- Bachelor’s degree in Information Security, Computer Science, Information Technology, Engineering, or equivalent professional experience.
- 7+ years of experience in infrastructure engineering, cybersecurity, cloud engineering, or enterprise systems administration.
- Strong knowledge of Windows Server, Linux, Active Directory, Microsoft Entra ID, networking, virtualization, cloud infrastructure, and enterprise platforms.
- Experience interpreting and implementing security frameworks such as NIST SP 800-53, NIST Cybersecurity Framework (CSF), DISA STIGs, ISO/IEC 27001, and FedRAMP.
- Experience with vulnerability management platforms such as Qualys, Tenable, or Rapid7 and enterprise endpoint management platforms such as Tanium or Microsoft Intune.
- Experience supporting cloud environments including Microsoft Azure and AWS.
- Strong analytical skills with the ability to interpret large datasets and transform technical information into meaningful recommendations.
- Excellent communication skills with the ability to explain complex security concepts to technical and non-technical audiences.
Core Competencies
- Infrastructure Security
- Security Architecture
- Secure Engineering
- Strategic Thinking
- Data Analytics
- Risk Analysis
- Security Modernization
- Cloud Security
- Influencing Without Authority
- Collaboration
- Problem Solving
- Communication
Work in a Way That Works for You
We promote a healthy work/life balance across the organisation. We offer an appealing working prospect for our people. With numerous wellbeing initiatives, shared parental leave, study assistance and sabbaticals, we will help you meet your immediate responsibilities and your long-term goals.
Working Pattern
Working flexible hours - flexing the times when you work in the day to help you fit everything in and work when you are the most productive.
About the Business
LexisNexis Legal & Professional® provides legal, regulatory, and business information and analytics that help customers increase their productivity, improve decision-making, achieve better outcomes, and advance the rule of law around the world. As a digital pioneer, the company was the first to bring legal and business information online with its Lexis® and Nexis® services.
U.S. National Base Pay Range: $71,600 - $119,400. Geographic differentials may apply in some locations to better reflect local market rates. If performed in New Jersey, the base pay range is $84,546 - $135,054.We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click here to access benefits specific to your location.
We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact 1-855-833-5120.
Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams here.
Please read our Candidate Privacy Policy.
We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.
USA Job Seekers: