American Family Insurance
American Family Insurance
American Family Insurance provides personal insurance coverage for homes, vehicles, life, and other protection needs. Founded in 1927 and headquartered in Madison, Wisconsin, the company serves more than 12 million customers and combines insurance expertise with digital tools such as the MyAmFam app, where customers can manage policies, pay bills, and file claims. Its business spans insurance, finance, and consumer services, with a focus on customer support, responsible business practices, and community involvement.

Senior Security and Risk Analyst (Boston Hybrid)

Advance American Family Insurance’s cyber threat intelligence program by turning emerging threats into actionable intelligence for security operations and technology leaders.

Description

  • Collect, assess, and convert threat intelligence into actionable guidance for security teams and leadership
  • Track emerging threats, adversary behavior, indicators of compromise, and tactics, techniques, and procedures across internal, open-source, commercial, and industry sources
  • Collaborate with Security Operations, Vulnerability Management, and other stakeholders to strengthen cyber defense capabilities
  • Create and present intelligence reports, threat briefings, and alerts for technical and executive audiences
  • Apply intelligence and analysis to incident response, threat hunting, and vulnerability management activities
  • Improve threat models, detection capabilities, and adversary-tracking frameworks using approaches such as MITRE ATT&CK
  • Continuously refine intelligence workflows, tools, and knowledge-management practices
  • Explain security risks and recommendations to both technical and non-technical stakeholders
  • Report to the Senior Manager, Cybersecurity
  • Attend New Employee Orientation during the first week
  • Travel up to 10%

Requirements

  • Proven experience delivering customer-focused solutions, support, and service
  • Advanced understanding of security analysis methods and reporting standards for technical and business audiences
  • Extensive knowledge of IT risk management and/or information systems auditing
  • Extensive knowledge of IT risk and control frameworks
  • Proven experience performing IT risk and control assessments
  • Strong grasp of IT risk management practices, reporting, and governance
  • Sound knowledge of risk management methods, standards, processes, governance models, and recognized risk analysis frameworks
  • Professional background in cyber threat intelligence, security operations, or a related cybersecurity function
  • Hands-on experience with threat intelligence platforms and incorporating threat data into SOC, incident response, or vulnerability management workflows
  • Experience creating clear, actionable intelligence reports, alerts, and briefings for varied audiences
  • Relevant certifications such as GCTI, CISSP, GSEC, CEH, CISM, or an equivalent credential
  • Experience using AI tools such as Claude, CoPilot, or OpenAI
  • Ability to work at least 10 days per month from the Madison, Wisconsin, or Boston, Massachusetts, office
  • Successful completion of applicable background checks
  • Agreement to sign a non-disclosure agreement
  • Sponsorship will not be considered unless the posting specifies otherwise

Benefits

  • Relocation assistance for eligible candidates
  • Comprehensive medical, dental, vision, and wellbeing coverage
  • Competitive 401(k) contribution
  • Pension plan
  • Annual incentive
  • Nine paid holidays
  • Paid time off program with 23 days accrued annually for full-time employees
  • Student loan repayment program
  • Paid family leave
  • Support for reasonable accommodations

Related Jobs