Senior Associate, Information Security Analyst
About the role
What You'll Do
- Monitor, investigate, and analyze security alerts, events, and indicators of compromise.
- Support incident response activities, including evidence collection, documentation, and root cause analysis.
- Conduct vulnerability assessments and partner with stakeholders to validate remediation efforts.
- Research emerging cybersecurity threats, vulnerabilities, and attack techniques.
- Develop and maintain security automation scripts using Python, Bash, or JavaScript.
- Perform security audits, control testing, and risk assessments aligned with regulatory requirements.
- Collaborate with engineering, infrastructure, and business teams to strengthen security controls.
- Create reports and deliver findings to technical and non-technical stakeholders.
Basic Requirements
- 2+ years of cybersecurity, information security, security operations, or related IT experience.
- Bachelor's degree or equivalent combination of education and experience.
- Basic understanding of cybersecurity threats, vulnerabilities, attack techniques, and risk management principles.
- Experience monitoring security events, investigating alerts, or supporting incident response activities.
- Proficiency in scripting using Python, Bash, JavaScript, or similar languages for automation and analysis.
- Foundational knowledge of networking concepts, including TCP/IP, DNS, routing, firewalls, and network protocols.
- Experience using security tools such as SIEM, endpoint security, vulnerability management, or log analysis platforms.
- Strong written and verbal communication skills with the ability to document findings and recommendations.
Preferred Skills/Experience
- Experience supporting a Security Operations Center (SOC) environment.
- Familiarity with compliance frameworks, security audits, and regulated industries.
- Exposure to cloud security technologies and concepts.
- Knowledge of threat intelligence and threat hunting methodologies.
- Understanding of identity and access management (IAM) principles.
- Experience with security automation, orchestration, or workflow optimization.
- Professional certifications such as Security+, CySA+, GSEC, or equivalent.
- Experience collaborating across multiple technical teams and driving remediation efforts.
We are proud to offer a competitive compensation package at McKesson as part of our Total Rewards. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered. For more information regarding benefits at McKesson, please click here.
Our Base Pay Range for this position
McKesson is an Equal Opportunity Employer
Not included in the source posting: about the role, benefits.
Skills
Who can apply
The employer didn't state any visa, work authorization, citizenship or clearance requirements in this posting. Confirm with the employer before applying.
Read automatically from the employer's posting text. Always confirm with the employer — requirements can change after a job is published.