×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Cybersecurity Analyst I, II, or III

Job in Santa Ana, Orange County, California, 92725, USA
Listing for: Socket.dev
Full Time position
Listed on 2026-08-17
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 90000 - 120000 USD Yearly USD 90000.00 120000.00 YEAR
Job Description & How to Apply Below

Overview

Position: Cybersecurity Analyst I, II or III (Depending on experience)

Salary: Starting at $90,000/year+ D.O.E

* Actual compensation may vary from posting based on geographic location, work experience, education, and/or skill level.

Location: On-Site Role - Santa Ana, California

Position Summary:

The Cybersecurity Analyst I/II/III supports the Third-Party Cyber Risk Management (TPCRM) program by identifying, assessing, monitoring, and helping reduce cybersecurity risk across NAF's third-party ecosystem.

The role includes vendor cybersecurity assessments, continuous cyber monitoring, Security Architecture Reviews (SARs), AI risk assessments, emerging third-party threat analysis, remediation support, and development of meaningful risk reporting and metrics.

This role partners with Third-Party Management (TPM), Legal, Privacy, Enterprise Technology, Procurement, and Business Unit stakeholders to provide practical, risk-based cybersecurity guidance and strengthen third-party cyber resilience.

The position may be filled at the I, II, or III level based on the selected candidate's relevant experience, hands‑on technical depth, demonstrated judgment, level of accountability, complexity and scale of prior vendor ecosystems, and experience operating in regulated environments. Candidates with more advanced experience are encouraged to apply; title, level, responsibilities, and compensation may be adjusted accordingly.


* Disclaimer

:

Identity Verification checks are in place throughout the Candidate journey to prevent candidate fraud

Responsibilities
  • Level of responsibility will scale with demonstrated capability, hands‑on experience, independence, and complexity of prior responsibilities. General differentiation by level includes:
  • Analyst I
    - Executes defined vendor cyber risk assessments and monitoring activities with guidance; independently handles lower-to-moderate complexity vendors and escalates significant findings. Demonstrates foundational hands‑on TPRM/security assessment experience and accountability for an assigned portfolio or assessment queue.
  • Analyst II
    - Independently owns end‑to‑end assessments for moderate‑to‑high risk and critical vendors, leads vendor discussions and remediation, performs SAR and AI risk reviews, and makes risk‑based recommendations with limited oversight. Demonstrates experience managing larger or more complex vendor populations and working across multiple business and technology stakeholders.
  • Analyst III
    - Leads the most complex, critical, or strategically significant third‑party assessments and incidents; provides independent challenge, mentors less‑experienced analysts, influences risk decisions, and drives program/process improvements. Demonstrates substantial hands‑on experience in large vendor ecosystems and/or highly regulated industries where regulatory, audit, data protection, resiliency, and due‑diligence expectations materially increase assessment depth.
  • Perform cybersecurity risk assessments for new and existing third‑party vendors, review security questionnaires, SOC reports, penetration tests, certifications, policies, and other supporting evidence.
  • Assessing vendor security controls across cloud security, identity and access management, AI, encryption, API security, vulnerability management, logging, incident response, and secure software development practices.
  • Support or independently lead Security Architecture Reviews (SARs) based on role level and vendor risk. Analyst I supports defined reviews;
    Analyst II independently leads higher‑risk reviews;
    Analyst III leads complex/critical reviews, challenges control design, and provides senior‑level risk recommendations.
  • Monitor and investigate emerging third‑party cyber threats, including critical vulnerabilities, ransomware, software supply chain attacks, and vendor breaches. Increasing seniority requires greater independence in correlating events to NAF's vendor ecosystem, determining business impact, directing mitigation, and briefing senior stakeholders.
  • Assess cybersecurity risks associated with vendor use of Artificial Intelligence (AI), including AI governance, model usage, data handling, AI‑enabled services,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary