Post Job Free
Sign in

Information Security Risk Analyst - IAM & Access Governance

Location:
Lowell, MA
Posted:
October 04, 2026

Contact this candidate

Resume:

Younes Hnouch

Lowell, MA 617-***-**** ******.******@*****.***

SUMMARY

Information Security Risk Analyst with hands-on experience in identity and access management, access governance, and audit readiness across banking, pharmaceutical, and IT operations environments. Skilled at running periodic access reviews, supporting SOC 2 and regulatory audits, and applying least privilege to reduce risk in regulated settings. Seeking a direct-hire, permanent role to own security work end-to-end and grow with one team long term.

WORK EXPERIENCE

Cambridge Savings Bank (Long-Term Contract via WEI) Waltham, MA Information Security Risk Analyst May 2025 – Apr 2026

• Administered Sycorr Permission Assist to enforce CIS Control 6 (Access Control), managing user identities to ensure all application permissions strictly matched official job roles.

• Leveraged Varonis data governance tools to audit unstructured file shares, eliminating over-privileged user access and enforcing a strict least-privilege model.

• Orchestrated automated vulnerability scans using Tenable, prioritizing and accelerating the remediation of critical security flaws across enterprise assets.

• Validated vendor technical security controls via WolfPAC and Bitsight, managing third-party risk across the full lifecycle from onboarding through real-time auditing.

• Provided InfoSec oversight to the SOC team, auditing CrowdStrike and Taegis configurations to verify that detection templates were actively tuned against novel threats.

Per Scholas (Fellowship) Cambridge, MA

Cybersecurity and Infrastructure Fellow May 2024 – Mar 2025

• Mastered identity lifecycle mechanics by practicing zero-trust enterprise user provisioning and complex permission architecture within Active Directory and Microsoft 365.

• Monitored simulated enterprise endpoints to analyze security logs, detect anomalous behaviors, and practice structured incident response triage.

• Administered automated vulnerability assessments, coordinated patch deployments, and built robust tenant protections utilizing MFA and conditional access.

Bristol Myers Squibb (Project-Based Contract) Devens, MA IT System and Security Administrator Dec 2023 – Mar 2024

• Architected Role-Based Access Control (RBAC) and Privileged Identity Management (PIM) schemas in Microsoft Entra ID to restrict the attack surface of administrative accounts.

• Enforced stringent Microsoft 365 Conditional Access parameters and applied Data Loss Prevention (DLP) controls to safeguard intellectual property in a regulated pharma cloud ecosystem.

• Mapped and deployed compliance retention baselines across core cloud environments to ensure strict alignment with international data security standards.

Drivetech (Contract) Acton, MA

IT and Security Operations Specialist Jul 2023 – Aug 2023

• Managed Active Directory and Microsoft 365 environments, overseeing secure user provisioning/deprovisioning and deploying identity lifecycle baselines.

• Utilized ConnectWise RMM for continuous endpoint monitoring, automated software patching, and proactive troubleshooting to maintain core uptime.

• Drafted and implemented standardized security configurations across hybrid endpoints to reduce the organization's immediate attack surface.

American Consumer Credit Counseling (Project-Based Contract) Newton, MA Information Technology Specialist Jun 2022 – Jan 2023

• Hardened Active Directory domain infrastructure by deploying restrictive Group Policy Objects (GPOs) to systematically eliminate local endpoint vulnerabilities.

• Provisioned and maintained secure remote gateway infrastructure (VPN, MFA) ensuring uninterrupted, encrypted operations for a workforce of 100+ remote personnel.

• Managed threat detection workflows utilizing Cisco AMP endpoint agents to aggressively contain, isolate, and eliminate active malware exploits.

EDUCATION

University of Massachusetts Lowell Lowell, MA

Bachelor of Science, Electrical Engineering

Per Scholas Cambridge, MA

Fellowship, Cybersecurity and Infrastructure

CERTIFICATIONS

Certified in Cybersecurity (CC)

ISC2

Issued Jul 2026 · Expires Jul 2029

Credential ID 1538578

SKILLS

IAM & Identity Tools: Microsoft Entra ID (Azure AD) • Active Directory • Varonis • Sycorr • PIM • RBAC • JIT • SSO • MFA • Access Governance

Security & GRC Frameworks: CIS Critical Security Controls (CSC) • NIST CSF • ISO 27001 • SOC 2 • WolfPAC • Audit Readiness

• Least Privilege • Risk Assessment

SecOps & Endpoint Tools: CrowdStrike • Taegis • Tenable • Bitsight • Cisco AMP • Vulnerability Management • Incident Response



Contact this candidate