Information Security Analyst
Job description
About the role
Cognism is a B2B data intelligence platform that is hiring an Information Security Analyst to join its team in Croatia. This role is central to safeguarding the company's data assets, infrastructure, and customer information from evolving cyber threats on a daily basis. The analyst will work closely with engineering, operations, and product teams to identify and address security risks across the entire platform and its supporting systems. Candidates should have a strong foundation in information security principles, a methodical approach to risk assessment, and a genuine interest in contributing to a fast-growing technology company that serves businesses worldwide. The ideal candidate thrives in a collaborative environment and takes ownership of security initiatives from planning through execution.
Key facts
What you'll do
Monitor security systems and alert logs continuously for potential threats or anomalous activity across the network.
Conduct vulnerability assessments and penetration tests to identify weaknesses and recommend remediation steps to engineering teams.
Review access controls and user permissions across internal applications, cloud environments, and third-party integrations regularly.
Support the incident response process by documenting, triaging, and analyzing security events to determine root causes.
Collaborate with software developers to integrate security checks and code review practices into the development lifecycle.
Maintain and update security policies, standard operating procedures, and technical documentation for the entire organization.
Perform regular audits of third-party vendors and assess their overall security posture and compliance status.
Assist with compliance efforts related to data protection regulations, industry standards, and internal governance frameworks.
Lead security awareness training sessions for employees across the company to promote a strong security culture.
Analyze network traffic patterns and endpoint telemetry to detect unusual or unauthorized activity in real time.
Requirements
Bachelor's degree in computer science, information security, or a closely related technical field is required.
At least 2 years of hands-on experience in an information security, IT risk, or similar role.
Solid understanding of common attack vectors including phishing campaigns, malware, and injection-based security flaws.
Familiarity with established security frameworks such as ISO 27001 or the NIST Cybersecurity Framework is essential.
Practical experience working with SIEM tools or security monitoring and alerting platforms on a daily basis.
Strong written and verbal communication skills for reporting findings clearly to both technical and business stakeholders.
Ability to work independently and manage multiple concurrent security tasks, projects, and competing priorities effectively.
Knowledge of cloud security concepts including AWS or Azure security controls, configurations, and best practices.
Nice to have
Professional certification such as CISSP, CompTIA Security+, or CEH is considered a strong plus for this role.
Hands-on experience with DevSecOps practices and automated security testing tools integrated into CI/CD pipelines.
Background in B2B SaaS or data platform environments is highly valued and considered a significant advantage.
Familiarity with GDPR and European data protection regulations along with organizational compliance requirements is helpful.
Experience with security orchestration, automation, and response platforms to streamline incident handling and threat intelligence workflows.
Skills & tools
Proficiency with security information and event management platforms for real-time monitoring, correlation, alerting, and forensic analysis.
Experience using vulnerability scanning and penetration testing tools to systematically identify, classify, and prioritize security weaknesses.
Working knowledge of firewalls, intrusion detection systems, intrusion prevention systems, and endpoint protection solutions and their configurations.
Comfort with scripting languages such as Python or PowerShell for automating repetitive security tasks, workflows, and reporting.
Understanding of identity and access management protocols, directory services, single sign-on, and multi-factor authentication mechanisms.
Familiarity with cloud providers and their native security features, controls, compliance certifications, and shared responsibility models.
Practical notes
This is a full-time position based in Croatia with a hybrid work arrangement combining on-site collaboration and remote working days each week.
The hiring process includes an initial technical screening, a written security assessment, and final interviews with the security leadership team and senior engineers.
Cognism offers a competitive benefits package, professional development budgets, conference attendance opportunities, and ongoing learning resources in the cybersecurity domain.
Applications should be submitted through the Cognism careers page with an up-to-date resume and a cover letter detailing relevant experience and motivation for joining.