ActiveJobs
Analog Devices

Senior Staff Engineer, Infrastructure Security and Compliance

Analog Devices · US, MA, Wilmington

Full-timeOn-sitePosted 10 September 2026
Apply on Company Site →

Job description

About Analog Devices Analog Devices, Inc. (NASDAQ: ADI) is a global semiconductor leader that bridges the physical and digital worlds to enable breakthroughs at the Intelligent Edge. ADI combines analog, digital, AI, and software technologies into solutions that combat climate change, reliably connect humans and the world, and help drive advancements in automation and robotics, mobility, healthcare, energy and data centers. With revenue of more than $11 billion in FY25, ADI ensures today's innovators stay Ahead of What's Possible. Learn more at www.analog.com and on LinkedIn and X. Senior Staff Engineer, Infrastructure Security and Compliance Position Summary Reporting to the Global Head of IT Infrastructure and Operations, the Senior Staff Engineer, Infrastructure Security and Compliance is responsible for leading the enterprise infrastructure security and compliance program across Information Technology (IT) and Operational Technology (OT) environments. This role serves as the technical and program leader for vulnerability management, secure configuration, system hardening, patch governance, critical threat response, and compliance remediation across enterprise IT infrastructure. The position operates across infrastructure operations, endpoint engineering, cloud platforms, cybersecurity, manufacturing technology teams, enterprise architecture, and managed service partners to establish governance, technical standards, measurable controls, and remediation programs that reduce organizational risk, improve cyber resilience, and maintain audit readiness across the global technology environment. Role Scope and Key Relationships Reporting Relationship Reports to the Global Head of IT Infrastructure and Operations. Key Business Relationships Cybersecurity Enterprise Architecture IT Risk and Compliance Internal Audit Manufacturing / OT Technology Teams Cloud and Platform Engineering Teams Application Owners Business Technology Leaders External Relationships Managed Service Providers Technology Vendors Security Partners External Auditors / assessors Scope Global enterprise infrastructure spanning IT and OT environments, including enterprise endpoints, servers, cloud platforms, network services, identity systems, collaboration platforms, virtualization technologies, mobile platforms, manufacturing technologies, and digital workforce technologies. Key Responsibilities Program Leadership and Governance Own and mature the enterprise infrastructure security and cyber resilience program. Establish governance frameworks, standards, processes, and operational controls that reduce technology risk and improve enterprise resilience. Guide technical discussions, risk assessments, and solution design reviews across infrastructure platforms. Lead cross-functional remediation review boards and infrastructure security councils. Partner with architecture, cybersecurity, and operations teams to ensure security requirements are incorporated into infrastructure technology decisions. Influence strategic investments that strengthen enterprise security, operational resilience, and regulatory compliance. Represent infrastructure security, compliance, and operational risk at Architecture Review Boards (ARB) and other governance forums. Define and track measurable program objectives and key performance indicators. Vulnerability and Patch Management Own the enterprise infrastructure vulnerability management program. Establish risk-based methodologies for vulnerability prioritization, remediation planning, exception management, and risk acceptance. Lead identification, assessment, tracking, and remediation of vulnerabilities across:End-user computing platforms Infrastructure services Cloud platforms Identity and access management systems Collaboration technologies Network and connectivity services Operational technology environments AI and digital workforce technologies Govern enterprise patch management strategy, execution oversight, and compliance reporting. Drive closure of critical and high-risk vulnerabilities within established remediation service-level objectives. Monitor remediation effectiveness and continuously improve vulnerability management practices. Secure Configuration and System Hardening Define and maintain enterprise security baselines and hardening standards across Windows, macOS, Linux, cloud, virtualization, mobile, network, and OT platforms. Establish governance processes for secure configuration management and infrastructure control compliance. Partner with platform engineering teams to implement and operationalize secure configuration standards. Monitor configuration drift and drive remediation activities to maintain compliance with approved baselines. Develop and govern exception management processes and compensating control requirements. Regularly assess security and compliance gaps and drive corrective actions and risk reduction plans. Promote infrastructure security best practices across engineering and operational teams. Critical Vulnerability and Zero-Day Response Partner with Cybersecurity, which provides enterprise threat intelligence, security policy, and incident response direction, to lead infrastructure exposure assessments, remediation planning, technical execution, and operational reporting for critical vulnerabilities and zero-day events. Coordinate response activities involving cybersecurity, infrastructure, application, cloud, OT, vendor, and managed service teams. Conduct impact analysis and exposure assessments for emerging threats. Develop emergency remediation strategies and oversee accelerated deployment activities when required. Serve as the infrastructure technical lead during vulnerability-related crisis situations and major security events. Drive lessons learned and continuous improvement activities following significant vulnerability remediation efforts. Compliance, Audit, and Risk Remediation Serve as the technical leader for infrastructure-related compliance programs and regulatory assessments. Support internal and external audits, including CMMC, TISAX, SOX, and customer-specific cybersecurity assessments. Ensure infrastructure controls align with enterprise security policies, standards, and compliance requirements. Maintain audit evidence readiness and support ongoing compliance monitoring activities. Drive remediation plans, corrective actions, and closure of audit findings. Partner with cybersecurity and risk teams to improve infrastructure control maturity and governance effectiveness. Metrics, Reporting, and Continuous Improvement Develop executive-level dashboards and reporting that provide clear visibility into vulnerability exposure, compliance status, remediation performance, and operational risk. Establish measurable security and compliance metrics across infrastructure platforms. Present program status, key risks, and remediation progress to senior leadership. Identify opportunities for automation, process optimization, and operational efficiency. Benchmark infrastructure security practices against industry frameworks and leading practices. Drive a culture of continuous improvement and proactive risk management. Required Qualifications Bachelor's degree in Computer Science, Information Technology, Engineering, Cybersecurity, or a related discipline, or equivalent practical experience. 8+ years of experience in Infrastructure Engineering, Security Engineering, Infrastructure Architecture, Endpoint Engineering, or IT Operations. 5+ years of experience leading enterprise-scale security, vulnerability management, compliance remediation, or cyber resilience programs. Experience operating in large, complex, global enterprise environments. Demonstrated experience coordinating security remediation activities across multiple technology teams. Experience managing risk reduction programs involving managed service providers and outsourced operational teams. Experience supporting major security incidents, cr

Verified and listed by ActiveJobs. Applications are made directly on Analog Devices's own career page — we never sit in the middle.