Analyst - Information Security Job at Luxottica, Mason, OH

QW9jNGtPWU1DaUdYN0lyUmZ1NGo1bCt5NGc9PQ==
  • Luxottica
  • Mason, OH

Job Description

Analyst - Information Security

We are a global leader in the design, manufacture, and distribution of ophthalmic lenses, frames, and sunglasses. We offer our industry stakeholders in over 150 countries access to a global platform of high-quality vision care products (such as the Essilor brand, with Varilux, Crizal, Eyezen, Stellest and Transitions), iconic brands that consumers love (such as Ray-Ban, Oakley, Persol, Oliver Peoples, Vogue Eyewear and Costa), as well as a network that offers consumers high-quality vision care and best-in-class shopping experiences (such as Sunglass Hut, LensCrafters, Salmoiraghi & Vigan and the GrandVision network), and leading e-commerce platforms.

Join our global community of over 190,000 dedicated employees around the world in driving the transformation of the eyewear and eyecare industry.

Are you willing to pioneer new frontiers, foster inclusivity and collaboration, embrace agility, ignite passion, and make a positive impact on the world? Join us in redefining the boundaries of what's possible.

General Function

The IS Application Security Analyst supports the execution of the Vulnerability Management program by coordinating vulnerability assessments, penetration testing, and social engineering efforts. This role facilitates remediation across systems to reduce the organization's attack surface, analyzes application security scan results, and ensures vulnerabilities are properly addressed through post-development testing. While not responsible for direct remediation, the Analyst collaborates with technical teams and leverages automated tools to validate fixes and maintain enterprise-wide security oversight.

Major Duties and Responsibilities
  1. Monitor and analyze vulnerability data to identify and communicate technical risks across the organization.
  2. Support classification and impact assessment of newly discovered vulnerabilities.
  3. Conduct and assist with vulnerability assessments, penetration testing, and social engineering exercises.
  4. Provide threat intelligence updates, including attacker tactics, techniques, and procedures, to security teams.
  5. Review application security scan results with an understanding of code structures to offer actionable feedback.
  6. Assist in post-development testing to validate remediation of identified vulnerabilities.
  7. Coordinate and track remediation efforts across application, infrastructure, and operations teams to ensure timely resolution.
  8. Contribute to the strategic goals of the vulnerability management program.
  9. Aggregate and report findings from various scanning tools and platforms.
  10. Use IS tools (e.g., DLP, code scanners, external security profiles) to identify and analyze gaps in security controls.
  11. Participate in IT projects to ensure security is embedded by default and by design through the SDLC process.
  12. Build collaborative relationships across departments and with clients to support compliance and enhance satisfaction.
  13. Assist with regulatory and compliance activities, including audits, assessments, certifications, and client inquiries.
  14. Present vulnerability findings and risk assessments to IS leadership.
  15. Help identify and address capability gaps in vulnerability management services.
  16. Work with cross-functional teams to strengthen the organization's security posture and integrate security into workflows.
  17. Pursue continuous learning to enhance effectiveness in supporting Information Security functions.
Basic Qualifications
  • Bachelor's degree in computer science, IT or equivalent
  • 3+ years of experience in IT, Information Security, or Compliance
  • Familiarity with major standards: SOC 1-2, ISO 27001/2, PCI DSS, HITRUST, SANS, and NIST
  • Experience implementing compliance frameworks in financial services environments
  • Broad understanding of IT hardware and software products
  • Strong project management, presentation, communication, and writing skills
  • Excellent analytical and problem-solving abilities
  • Experience managing enterprise security and intrusion detection systems
  • Ability to collaborate effectively across business and technology teams
  • High-level understanding of application structures and code to assess and respond to scan results
Preferred Qualifications
  • Certified Information Systems Security Profession, PCI DSS, Certified HIPAA Privacy Security Expert, Certified Information Security manager, Global Information Assurance Certification, or related.
  • Experience or knowledge with healthcare or health insurance
  • Knowledge of CMS and HIPAA related vendor requirements
  • Knowledge of Security SDLC tools

Our Diversity, Equity and Inclusion commitment

We are committed to creating an inclusive environment for all employees. We celebrate diversity and provide equal opportunities to all, regardless of race, gender, ethnicity, religion, disability, sexual orientation, or any other characteristic that makes us unique.

Job Tags

Similar Jobs

Adecco

UX Researcher - 777825 Job at Adecco

 ...Job Description Job Description UX Researcher (777825) Location: Morrisville, NC Schedule: Full-Time, Hybrid (3 days onsite) Pay Range: $45.00$62.50/hour Type: Open-ended contract with potential for direct hire A global leader in innovation is seeking... 

Hollywood Presbyterian

Operating Room Assistant Days Job at Hollywood Presbyterian

 ...supervision of a registered professional nurse, the OR Assistant provides support services that include but limited to general...  ...nursing care and other tasks that support clinical operations of the operating rooms Post Anesthesia Recovery Room. I.e. running errands,... 

Crowne Health Care

PRN Licensed Practical Nurse (LPN) - Med Nurse Job at Crowne Health Care

 ...PRN Licensed Practical Nurse (LPN) - Med Nurse7P-7A Opening IF INTERESTED IN FULL TIME, WE HAVE A DAY SHIFT OPENING We are currently...  ...on Experience # PRN Qualifications # LPN License or Temporary PN License # Must pass background and drug screen... 

Cardiovascular Institute of San Diego

Interventional Cardiologist Job at Cardiovascular Institute of San Diego

 ...part of a successful established team including 15 energetic cardiologists in beautiful coastal Southern California. Expect to be busy...  ...practice represent all fields of cardiology, including General, Interventional, Structural, Peripheral, Electrophysiology, Imaging,... 

M3USA

Physician Recruiter, Academics Division (Remote) Job at M3USA

 ...Medicus Firm (TMF) , a part of M3USA, is a national healthcare recruitment firm with a mission to be the market leader which is most...  ...its Performance, People, and Partnerships. One of the largest physician recruitment companies in the US, TMF focuses on providing the...