The insurance industry runs on Vertafore. We equip agencies, MGAs, and carriers with the core digital systems, specialized AI, and data-driven foundation to eliminate distribution drag across the insurance lifecycle, spanning sales, servicing, and back-office operations.
Underpinned by unmatched speed and performance power, we are the trusted backbone that’s taking the insurance industry from friction to flow with Distribution Velocity – speed, performance, and trust - to drive growth at scale.
With over 95% of the top agencies and insurers and 50% of industry compliance transactions running through Vertafore, we lead at the intersection of innovation and trust, giving insurance professionals the confidence to transform and win in the AI era.
Our reach is global, with headquarters in Denver, Colorado, and offices across the U.S., Canada, and India.
Description:
As a Senior Information Security Analyst, you will serve as a key contributor in security operations, combining core analyst responsibilities with light engineering tasks. You will Lead, monitor and respond to security events, support vulnerability and application security efforts, and contribute to automation and tool optimization initiatives. This role is ideal for professionals with strong analytical skills and a detailed understanding of scripting and security tooling.
Key Responsibilities:
Essential job functions include but are not limited to the following:
Security Operations & Incident Response
· Monitor and analyze security alerts from SIEM, EDR, and vulnerability scanners.
· Assist in investigating medium to high-severity incidents with guidance.
· Contribute to incident response playbook updates and automation improvements.
· Correlate threat intelligence with internal events to assess impact.
· Support forensic analysis and evidence collection with MDR/MSSP partners.
· Support Security Engineers on any technical requirements.
Security Engineering & Automation:
· Develop basic scripts (e.g., Python, PowerShell) to automate repetitive security tasks.
· Support integration and tuning of security tools (SIEM, SOAR, EDR).
· Assist in building dashboards and reports for security metrics.
Application Security Support
· Review and validate automated scan results (e.g., Veracode).
· Identify false positives and provide remediation guidance.
· Support CI/CD pipeline security integration and issue resolution.
Vulnerability Management
· Conduct CVE research and impact analysis using CVSS scoring.
· Assist in prioritizing and tracking remediation efforts.
· Support development of vulnerability dashboards and reports.
Compliance & Documentation
· Support audit and compliance activities by maintaining documentation.
· Contribute to security procedures, knowledge base articles, and metrics reporting.
Team Collaboration & Mentorship
· Mentor junior team members on investigation and documentation practices.
· Participate in onboarding and knowledge sharing activities.
· Contribute to team process improvements and tool evaluations.
Knowledge, Skills and Abilities:
- Solid understanding of network security fundamentals (TCP/IP, SSL, PKI, RADIUS, DNS, routing/switching)
- Proficiency with multiple security tools such as Splunk, Check Point, Cisco ASA, Imperva WAF, Carbon Black, Forcepoint, Qualys
- Intermediate scripting capabilities in PowerShell, Python, or shell scripting with ability to develop basic automation
- Good knowledge of security vulnerabilities, attack vectors, and the OWASP Top 10
- Solid understanding of operating systems security for both Windows and Linux environments, and, working knowledge of cloud security concepts, preferably AWS
- Proficient in Git, GitLab, and commercial software scanning solutions
- Good knowledge of Agile planning processes and associated tools (Jira, Rally, Confluence)
- Familiarity with ServiceNow for case management and workflow development
- Solid knowledge of threat modeling methodologies
- Good understanding of the NVD, CVEs, and CVSS 3.0 scoring systems
- Knowledge of incident response practices and basic forensic analysis techniques
- Understanding of APIs and common security implementation methods
- Strong communication skills with ability to present security topics to technical and business audiences
- Developing leadership and mentoring capabilities
- Good analytical thinking and problem-solving skills
- Ability to work independently with moderate supervision
- Basic project coordination skills
Why Vertafore is the place for you: *US Only
- The opportunity to work in a space where modern technology meets a stable and vital industry
- We have a Flexible First work environment! Our North America team members use our offices for collaboration, community and team-building, with members asked to sometimes come into an office and/or travel depending on job responsibilities. Other times, our teams work from home or a similar environment.
- Medical, vision & dental plans
- PPO & high-deductible options
- Health Savings Account & Flexible Spending Accounts Options:
- Health Care FSA
- Dental & Vision FSA
- Dependent Care FSA
- Commuter FSA
- Life, AD&D (Basic & Supplemental), and Disability
- 401(k) Retirement Savings Plain & Employer Match
- Supplemental Plans - Pet insurance, Hospital Indemnity, and Accident Insurance
- Parental Leave & Adoption Assistance
- Employee Assistance Program (EAP)
- Education & Legal Assistance
- Additional programs - Tuition Reimbursement, Employee Referral, Internal Recognition, and Wellness
- Commuter Benefits (Denver)
The selected candidate must be legally authorized to work in the United States.
The above statements are intended to describe the general nature and level of work being performed by people assigned to this job. They are not intended to be an exhaustive list of all the job responsibilities, duties, skill, or working conditions. In addition, this document does not create an employment contract, implied or otherwise, other than an "at will" relationship.
Vertafore strongly supports equal employment opportunity for all applicants regardless of race, color, religion, sex, gender identity, pregnancy, national origin, ancestry, citizenship, age, marital status, physical disability, mental disability, medical condition, sexual orientation, genetic information, or any other characteristic protected by state or federal law.