Hiring.Camp

Information Security Operations Analyst II

Jmfamily

·

May 21, 2026

Location
FL - Deerfield Bch HDQ, United States of America
Type
Full-time
Department
Operations
Source
Workday

Description

Information Security Operations Analyst II at JM Family Enterprises is responsible for designing, building, and scaling offensive security capabilities through adversary‑focused testing, attack simulation, and the development of custom tooling and automation.

They will support transformation of offensive security program from a predominantly tool‑ and vendor‑driven model to a build‑first approach, leveraging software engineering, automation, and AI‑assisted techniques to improve the coverage, depth, and repeatability of offensive security activities.

Responsibilities include but are not limited to:

  • Conduct offensive security activities including penetration testing, attack simulations, threat‑based assessments, and control validation across on‑prem, cloud, identity, and SaaS environments.

  • Execute and assist in the development of red team and purple team exercises, collaborating with detection and response teams to validate defensive coverage.

  • Perform vulnerability and exploitation analysis, including chaining weaknesses to demonstrate real‑world attack paths and business risk.

  • Identify, validate, and responsibly disclose security weaknesses to stakeholders, providing clear remediation guidance and risk context.

  • Design, develop, and maintain custom offensive security tooling (Python, PowerShell, Bash, or similar), including frameworks, reusable modules, and automation that scale testing beyond point‑in‑time assessments.

  • Evaluate when to build versus buy offensive security capabilities, with a bias toward internal tooling where it improves flexibility, visibility, or speed of iteration.

  • Incorporate AI‑assisted techniques (e.g., automation, chaining analysis, signal prioritization) to increase testing efficiency and analyst leverage.

  • Contribute documentation such as test reports, playbooks, findings templates, and executive‑level summaries.

  • Contribute to the long‑term architecture of the offensive security program, including shared libraries, testing pipelines, data models, and reporting outputs optimized for reuse and scale.

  • Mentor junior analysts and contribute to team knowledge sharing.

  • Partner with application and platform engineering teams not only to test systems, but to co‑design secure patterns, reference implementations, and reusable testing components.

  • Build developer‑consumable assets (templates, scripts, sample exploits, safe test harnesses) that enable teams to self‑validate security assumptions earlier in the SDLC.

  • Provide developer‑friendly remediation guidance, proof‑of‑concepts, and secure coding recommendations that are actionable and aligned to real‑world development workflows.

  • Support the integration and tuning of security testing tools within CI/CD pipelines, balancing detection depth with developer experience and signal quality.

  • Collaborate with Security Engineering and Application teams to improve self‑service security capabilities, documentation, and testing patterns that developers can reuse.

  • Participate in post‑testing debriefs with developers to educate, coach, and improve security outcomes—not just report findings.

Qualifications:

  • Hands‑on experience with penetration testing, red team, purple team, or adversary emulation activities.

  • Strong understanding of Windows, Active Directory, Azure/Entra ID, networking, cloud platforms, and SaaS architectures.

  • Experience with common offensive security tools and frameworks (e.g., C2 frameworks, vulnerability scanners, exploit frameworks).

  • Knowledge of MITRE ATT&CK, kill chains, and attacker tradecraft.

  • Experience validating security controls such as EDR, SIEM, identity protections, email security, and cloud security controls.

  • Strong scripting and automation skills; ability to customize or build tools to support testing objectives.

  • Ability to translate technical findings into clear risk‑based narratives for technical and non‑technical audiences.

  • Strong analytical, problem‑solving, and critical‑thinking skills.

  • Ability to work independently while collaborating effectively in cross‑functional teams.

  • High attention to detail with a strong sense of ethics and responsible disclosure.

  • Experience working directly with software engineers to remediate vulnerabilities and improve secure development practices.

  • Understanding of modern SDLC and CI/CD pipelines, including how security testing fits into developer workflows.

  • Familiarity with secure coding practices and common vulnerability classes in modern applications (web, APIs, cloud‑native services).

  • Ability to communicate security findings in a way that developers can quickly understand, prioritize, and fix.

  • Mindset oriented toward enablement over enforcement, with a focus on reducing friction while improving security outcomes.

  • Background in software engineering, platform engineering, or SRE, with a desire to specialize in security.

  • Experience designing or maintaining production‑quality code, not just scripts.

  • Comfort working with APIs, data pipelines, CI/CD systems, and cloud‑native services as part of security capability development.

  • Curiosity and practical interest in applying AI/ML‑assisted techniques to security testing, automation, and analysis.

#LI-AM1

#LI-HYBRID

This job description may not be inclusive of all assigned duties, responsibilities, or aspects of the job described, and may be amended at any time at the sole discretion of JM Family. All work arrangements are subject to associate performance, business need and manager discretion, and may be revised as necessary.

JM FAMILY IS PROUD TO BE AN EQUAL OPPORTUNITY EMPLOYER 

JM Family Enterprises, Inc. is an Equal Employment Opportunity employer. We are committed to recruiting, hiring, retaining, and promoting qualified associates without regard to age, race, religion, color, gender, sex (including pregnancy, childbirth and related medical conditions), sexual orientation, gender identity, gender expression, mental or physical disability, national origin, marital status, citizenship, military status, genetic information, veteran status, or any other characteristic protected by federal, state, provincial, or local law.

 

DISABILITY ACCOMMODATIONS 

If you have a disability and require a reasonable accommodation to complete the job application process, please contact JM Family’s Talent Acquisition department at [email protected] for assistance. If you have an accommodation request for one of our recruiting events, please notify us at least 72 hours prior so that we may provide assistance. 

Skills

PythonAzureCI/CDPenetration TestingSIEMSRE

Similar Jobs

27

Information Security Operations Engineer - Endpoint Protection

Essity · Lisbon, Portugal +2 · Onsite

4 days ago

Information Security Operations Analyst (IAM)

Mastercard · Bogota, Colombia

1 week ago

Information Security Operations Specialist

Digitain · Yerevan, Yerevan, Armenia

1 week ago

Manager, Information Security Operations

Scoutmotors · Charlotte, North Carolina, United States

2 weeks ago

Information Security Operations Specialist

Altaml · Edmonton +1 · Onsite

3 weeks ago

Senior Information Security Operations Analyst

Mastercard · Bogota, Colombia

1 month ago

Information Security Operations Analyst

Insights. Connections. Experiences. · Atlanta HQ North Tower Office, United States of America

1 month ago

Information Security Operations Analyst

Peckham · Lansing, MI, United States of America · Hybrid

1 month ago

Director, Information Security Operations

Onity · Pune, India · Hybrid

2 months ago

Associate Director, Information Security Operations

AIA Careers · SG-Tampines Agency Building, Singapore

2 months ago

Information Security Operations Lead

Brooksauto · Malaysia - Johor +1 · Onsite

3 months ago

Information Security Operations Lead/Manager

Default · Carmel

3 months ago

Assistant Director, Information Security Operations

New York University · New York, NY, US

3 months ago

Assistant Director, Information Security Operations

Us Nyu · New York, NY, US

3 months ago

Information Security Operations Analyst

Mastercard · Bogota, Colombia · Remote

9 months ago

Information Security Operations Senior Associate

Morae · Bangalore, India

1+ year ago

Information Security Operations Manager

Minor International · Bangkok, Bangkok, Thailand

1+ year ago

Sr. Director, Information Security & Cloud Operations

Prolaio · Chicago, IL +1

1 month ago

Director of Information Security & Sovereign Operations (f/m/x)

LiveEO GmbH

8 months ago

Manager Information Technology and Security Operations

"Olivine, Inc." · Chicago, IL

3 days ago

Director, Information Security (Security Engineering & Operations)

Achieve · Tempe, AZ, United States · Hybrid

2 weeks ago

Information Security Analyst, Scholars Operations Center

Florida Virtual School and FlexPoint Careers · FL - Home Office, United States of America

1 month ago

Lead Information Security Analyst -Security Operations/Incident Management

Inmobi · Lucknow, Uttar Pradesh

5 months ago

Information Security Manager for IAM Operations

Rb · New York, NY, United States of America · Onsite

1 week ago

Lead Full Stack Information Security Engineer - Counter Threat Operations

Wells Fargo · 142019-NC-300 South Brevard, Charlotte, United States of America · Hybrid

3 weeks ago

Director Chief Information Security Officer - IT Infrastructure and Operations

SPH Business Unit · Helena, MT, United States, US · Hybrid

1 month ago

Sr. Manager, Information Security Identity and Access Management Operations

Bcbsma · Hingham, United States of America

6 months ago