AI Jobs Map

Analog Devices · Wilmington, MA

Senior Staff Engineer, Infrastructure Security and Compliance

directorfull time$139,370 – $201,815 / yearPosted today
Apply on IndeedOpens the original posting. AI Jobs Map never asks for your details.

Stack mentioned

vulnerability-managementcybersecurityidentity-and-access-managementlinuxthreat-intelligenceincident-response

About Analog Devices

Analog Devices, Inc. (NASDAQ: ADI ) is a global semiconductor leader that bridges the physical and digital worlds to enable breakthroughs at the Intelligent Edge. ADI combines analog, digital, AI, and software technologies into solutions that combat climate change, reliably connect humans and the world, and help drive advancements in automation and robotics, mobility, healthcare, energy and data centers. With revenue of more than $11 billion in FY25, ADI ensures today's innovators stay Ahead of What's Possible. Learn more at www.analog.com and on LinkedIn and X .

Senior Staff Engineer, Infrastructure Security and Compliance

Position Summary

Reporting to the Global Head of IT Infrastructure and Operations, the Senior Staff Engineer, Infrastructure Security and Compliance is responsible for leading the enterprise infrastructure security and compliance program across Information Technology (IT) and Operational Technology (OT) environments. This role serves as the technical and program leader for vulnerability management, secure configuration, system hardening, patch governance, critical threat response, and compliance remediation across enterprise IT infrastructure.

The position operates across infrastructure operations, endpoint engineering, cloud platforms, cybersecurity, manufacturing technology teams, enterprise architecture, and managed service partners to establish governance, technical standards, measurable controls, and remediation programs that reduce organizational risk, improve cyber resilience, and maintain audit readiness across the global technology environment.

Role Scope and Key Relationships

Reporting Relationship

- Reports to the Global Head of IT Infrastructure and Operations.

Key Business Relationships

- Cybersecurity

- Enterprise Architecture

- IT Risk and Compliance

- Internal Audit

- Manufacturing / OT Technology Teams

- Cloud and Platform Engineering Teams

- Application Owners

- Business Technology Leaders

External Relationships

- Managed Service Providers

- Technology Vendors

- Security Partners

- External Auditors / assessors

Scope

- Global enterprise infrastructure spanning IT and OT environments, including enterprise endpoints, servers, cloud platforms, network services, identity systems, collaboration platforms, virtualization technologies, mobile platforms, manufacturing technologies, and digital workforce technologies.

Key Responsibilities

Program Leadership and Governance

- Own and mature the enterprise infrastructure security and cyber resilience program.

- Establish governance frameworks, standards, processes, and operational controls that reduce technology risk and improve enterprise resilience.

- Guide technical discussions, risk assessments, and solution design reviews across infrastructure platforms.

- Lead cross-functional remediation review boards and infrastructure security councils.

- Partner with architecture, cybersecurity, and operations teams to ensure security requirements are incorporated into infrastructure technology decisions.

- Influence strategic investments that strengthen enterprise security, operational resilience, and regulatory compliance.

- Represent infrastructure security, compliance, and operational risk at Architecture Review Boards (ARB) and other governance forums.

- Define and track measurable program objectives and key performance indicators.

Vulnerability and Patch Management

- Own the enterprise infrastructure vulnerability management program.

- Establish risk-based methodologies for vulnerability prioritization, remediation planning, exception management, and risk acceptance.

- Lead identification, assessment, tracking, and remediation of vulnerabilities across:

- End-user computing platforms

- Infrastructure services

- Cloud platforms

- Identity and access management systems

- Collaboration technologies

- Network and connectivity services

- Operational technology environments

- AI and digital workforce technologies

- Govern enterprise patch management strategy, execution oversight, and compliance reporting.

- Drive closure of critical and high-risk vulnerabilities within established remediation service-level objectives.

- Monitor remediation effectiveness and continuously improve vulnerability management practices.

Secure Configuration and System Hardening

- Define and maintain enterprise security baselines and hardening standards across Windows, macOS, Linux, cloud, virtualization, mobile, network, and OT platforms.

- Establish governance processes for secure configuration management and infrastructure control compliance.

- Partner with platform engineering teams to implement and operationalize secure configuration standards.

- Monitor configuration drift and drive remediation activities to maintain compliance with approved baselines.

- Develop and govern exception management processes and compensating control requirements.

- Regularly assess security and compliance gaps and drive corrective actions and risk reduction plans.

- Promote infrastructure security best practices across engineering and operational teams.

Critical Vulnerability and Zero-Day Response

- Partner with Cybersecurity, which provides enterprise threat intelligence, security policy, and incident response direction, to lead infrastructure exposure assessments, remediation planning, technical execution, and operational reporting for critical vulnerabilities and zero-day events.

- Coordinate response activities involving cybersecurity, infrastructure, application, cloud, OT, vendor, and managed service teams.

- Conduct impact analysis and exposure assessments for emerging threats.

- Develop emergency remediation strategies and oversee accelerated deployment activities when required.

- Serve as the infrastructure technical lead during vulnerability-related crisis situations and major security events.

- Drive lessons learned and continuous improvement activities following significant vulnerability remediation efforts.

Compliance, Audit, and Risk Remediation

- Serve as the technical leader for infrastructure-related compliance programs and regulatory assessments.

- Support internal and external audits, including CMMC, TISAX, SOX, and customer-specific cybersecurity assessments.

- Ensure infrastructure controls align with enterprise security policies, standards, and compliance requirements.

- Maintain audit evidence readiness and support ongoing compliance monitoring activities.

- Drive remediation plans, corrective actions, and closure of audit findings.

- Partner with cybersecurity and risk teams to improve infrastructure control maturity and governance effectiveness.

Metrics, Reporting, and Continuous Improvement

- Develop executive-level dashboards and reporting that provide clear visibility into vulnerability exposure, compliance status, remediation performance, and operational risk.

- Establish measurable security and compliance metrics across infrastructure platforms.

- Present program status, key risks, and remediation progress to senior leadership.

- Identify opportunities for automation, process optimization, and operational efficiency.

- Benchmark infrastructure security practices against industry frameworks and leading practices.

- Drive a culture of continuous improvement and proactive risk management.

Required Qualifications

- Bachelor's degree in Computer Science, Information Technology, Engineering, Cybersecurity, or a related discipline, or equivalent practical experience.

- 8+ years of experience in Infrastructure Engineering, Security Engineering, Infrastructure Architecture, Endpoint Engineering, or IT Operations.

- 5+ years of experience leading enterprise-scale security, vulnerability management, compliance remediation, or cyber resilience programs.

- Experience operating in large, complex, global enterprise environments.

- Demonstrated experience coordinating security remediation activities across multiple technology teams.

- Experience managing risk reduction programs involving managed service providers and outsourced operational teams.

- Experience supporting major security incidents, critical vulnerabilities, or enterprise-wide remediation initiatives.

Technical Capabilities

- Strong understanding of vulnerability management, system hardening, patch governance, configuration management, and operational security controls.

- Knowledge of enterprise infrastructure platforms, including endpoint management, server technologies, cloud services, networking, identity services, collaboration platforms, and virtualization technologies.

- Experience with infrastructure security controls, risk management, compliance frameworks, and audit processes.

- Ability to assess technical risk and translate findings into actionable business and operational recommendations.

- Working knowledge of IT and OT security principles and cyber resilience practices.

- Strong analytical, troubleshooting, and problem-solving capabilities.

Leadership Capabilities

- Demonstrated ability to lead through influence in a global matrixed environment.

- Strong communication skills with the ability to engage engineers, operational teams, executives, auditors, and external partners.

- Experience leading cross-functional programs and driving accountability across multiple teams.

- Ability to facilitate technical decision-making and build consensus among diverse stakeholder groups.

- Strong organizational, governance, and program management skills.

- Proven ability to prioritize competing demands and execute in a fast-paced environment.

Preferred Qualifications

- Experience supporting manufacturing, semiconductor, industrial, or highly regulated environments.

- Experience securing both enterprise IT and operational technology environments.

- Familiarity with NIST, CIS Benchmarks, IEC 62443, CMMC, TISAX, SOX, and similar industry frameworks.

- Experience with digital workforce technologies, AI-enabled platforms, and emerging infrastructure security models.

Measures of Success

Success in this role will be measured through:

- Reduction in critical and high-risk vulnerability exposure.

- Improved infrastructure patch compliance and remediation performance.

- Increased adoption of secure configuration and system hardening standards.

- Effective response and mitigation of zero-day and critical vulnerability events.

- Reduced audit findings and timely closure of corrective actions.

- Improved visibility of infrastructure security posture through executive reporting and metrics.

- Consistent governance of security exceptions, risk acceptance, and remediation activities.

- Increased cyber resilience across enterprise IT and OT infrastructure environments.

#LI-BF1

For positions requiring access to technical data, Analog Devices, Inc. may have to obtain export licensing approval from the U.S. Department of Commerce - Bureau of Industry and Security and/or the U.S. Department of State - Directorate of Defense Trade Controls. As such, applicants for this position – except US Citizens, US Permanent Residents, and protected individuals as defined by 8 U.S.C. 1324b(a)(3) – may have to go through an export licensing review process.

Analog Devices is an equal opportunity employer. We foster a culture where everyone has an opportunity to succeed regardless of their race, color, religion, age, ancestry, national origin, social or ethnic origin, sex, sexual orientation, gender, gender identity, gender expression, marital status, pregnancy, parental status, disability, medical condition, genetic information, military or veteran status, union membership, and political affiliation, or any other legally protected group.

EEO is the Law: Notice of Applicant Rights Under the Law .

Job Req Type: Experienced

Required Travel: Yes, 10% of the time

Shift Type: 1st Shift/Days

The expected wage range for a new hire into this position is $139,370 to $201,815.

-
Actual wage offered may vary depending on work location , experience, education, training, external market data, internal pay equity, or other bona fide factors.

-
This position qualifies for a discretionary performance-based bonus which is based on personal and company factors.

-
This position includes medical, vision and dental coverage, 401k, paid vacation, holidays, and sick time , and other benefits.

More jobs at Analog Devices