Information Security (InfoSec) Analyst

Corporate Services Team (CST) – Enterprise Technology Solutions /
Full-time /
BPM Overview:

What does BPM stand for? Innovation, opportunity, community, diversity, inclusivity, flexibility and so much more. B-P-M stands for “Because People Matter,” because at our core, our people drive everything we do and how we do it. We are a forward-thinking, full-service accounting firm providing modern solutions to businesses across the globe. We focus on comprehensive assurance, tax, and consulting services for our clients, and we provide our people and our community with the resources to lead meaningful and purposeful lives.
While we are one of the largest California-based accounting firms, our flexible work locations and schedules mean we have professionals across the continent. Our teams and our clients drive us to provide quality services and ignite unique insights and ideas that contribute to our continued success. Our clients come from different backgrounds and industries, which keep our people intellectually challenged every day.

Burr Pilger Mayer India Pvt. Ltd. (BPM India) is a subsidiary of BPM LLP. Founded in 1986, BPM is one of the largest California-based accounting and consulting firms, ranking in the top 50 in the country. With 17 offices across the world, BPM serves emerging and mid-cap businesses as well as high-net-worth individuals in a broad range of industries, including financial services, technology, life science, manufacturing, food, wine and craft brewing, automotive, nonprofits, real estate and construction. The Firm’s International Tax Practice is one of the largest on the West Coast and its well-recognized SEC practice serves approximately 35 public reporting companies, mostly in the technology industry.

About the role:
The IT Security Analyst performs two core functions for BPM. The first is the day-to-day operations of the in-place security solutions, while the second is identifying, investigating, and resolving security breaches detected by those systems. Secondary tasks may include involvement in implementing new security solutions, participation in creating and maintaining policies, standards, baselines, guidelines, and procedures, assisting with E-Discovery, and conducting vulnerability audits and assessments. The IT Security Analyst is expected to be fully aware of the enterprise’s security goals as established by its stated policies, procedures, and guidelines and to work to uphold those goals.


    • Strategy & Planning
    • Participate in the planning and design of enterprise security architecture under the direction of the IT Security Manager, where appropriate.
    • Participate in creating and maintaining enterprise security documents (policies, standards, baselines, guidelines, and procedures) under the direction of the IT Security Manager, where appropriate.
      Acquisition & Deployment
    • Maintain up-to-date detailed knowledge of the IT security industry, including awareness of new or revised security solutions, improved security processes, and the development of new attacks and threat vectors.
    • Recommend additional security solutions or enhancements to existing security solutions to improve overall enterprise security.
    • Perform the deployment, integration, and initial configuration of all new security solutions and any enhancements to existing security solutions following standard best operating procedures generically and the enterprise’s security documents specifically.

    • Operational Management
    • Maintain up-to-date baselines for the secure configuration and operations of all in-place devices, whether under direct control (i.e., security tools) or not (e.g., workstations, servers, network devices).
    • Maintain operational configurations of all in-place security solutions per the established baselines.
    • Monitor all in-place security solutions for efficient and appropriate operations.
    • Review logs and reports of all in-place devices, whether they are under direct control (i.e., security tools) or not (e.g., workstations, servers, network devices). Interpret the implications of that activity and devise plans for appropriate resolution.
    • Participate in investigations into problematic activity.
    • Participate in E-Discovery projects.
    • Participate in the design and execution of vulnerability assessments, penetration tests, and security audits.
    • Provide on-call support for end users for all in-place security solutions.

Position Requirements:

    • Education & Certification
    • College diploma or university degree in Computer Science and/or two years equivalent work experience.
    • One or more of the following certifications:
    • CompTIA Security+
    • GIAC Information Security Fundamentals
    • Microsoft Certified Systems Administrator: Security
    • Associate of (ISC)2

    • Knowledge & Experience
    • Extensive experience working in a SOC environment responding to incidents and breaches.
    • Experience with firewalls, intrusion detection systems, anti-virus software, data encryption, and other industry-standard techniques and practices.
    • Experience in E-Discovery, including content searches and relevant procedures and practices.
    • Experience with current systems software, protocols, and standards.
    • Working technical knowledge of network, PC, and platform operating systems
    • Strong understanding of IP, TCP/IP, and other network administration protocols.
    • Strong understanding of applicable practices and laws relating to data privacy and protection.
    • Familiarity with switches, routers, and Firewalls.

    • Personal Attributes
    • Proven analytical and problem-solving abilities.
    • Ability to effectively prioritize and execute tasks in a high-pressure environment.
    • Good written, oral, and interpersonal communication skills.
    • Ability to conduct research into IT security issues and products as required.
    • Ability to present ideas in business-friendly and user-friendly language.
    • Highly self-motivated and directed.
    • Keen attention to detail.
    • Team-oriented and skilled in working within a collaborative environment.
Wondering if you should apply?

At BPM we are people who value people. We are progressive and purposeful. We are a firm with flexibility. Our shared entrepreneurial spirit drives us to see and do things differently. And our passion for people makes BPM a place where everyone feels welcome, valued, and part of something bigger.


BPM provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

For positions based in San Francisco, consideration of qualified candidates with arrest and conviction records will be in a manner consistent with the San Francisco Fair Chance Ordinance.

Please note - this posting is for prospective candidates only. Unsolicited third-party resume submissions will be considered property of BPM and will not be acknowledged or returned.