Sr IT Security Analyst - G&A and Business Applications
Dynatrace
- Location
- Remote
- Work model
- Hybrid
- Level
- Senior
- H-1B history
- 5 approvals (FY2023)
Skills
About this role
Your role at Dynatrace
Dynatrace is seeking an experienced IT Security Analyst with a strong focus on business application and enterprise (G&A) system security. This role is responsible for evaluating, and implementing security controls across critical enterprise platforms such as NetSuite, SAP SuccessFactors, and other SaaS-based business systems. The ideal candidate brings hands-on experience securing enterprise applications, understands how business systems integrate within the IT ecosystem, and can align security controls with compliance requirements (e.g., ISO 27001, SOC 2, SOX, FedRAMP). Key Responsibilities Business Application Security
Assess and strengthen security controls for enterprise applications including:
NetSuite (ERP) SAP SuccessFactors (HRIS)
Review system configurations, access models, and integrations to identify security risks Partner with application owners to implement least privilege access and secure configuration standards
Integration & Data Flow Security
Analyze and secure data flows between business systems and internal platforms Evaluate API and middleware integrations (e.g., Boomi) for:
Authentication and authorization risks Data exposure risks Logging and monitoring gaps
Recommend and enforce secure integration patterns across the IT landscape
Security Controls & Risk Management
Perform security reviews and risk assessments for new and existing G&A applications Define and recommend compensating controls where platform limitations exist Support threat modeling and identify combination risks across interconnected systems
Compliance & Governance
Align application security controls with regulatory and audit requirements:
FedRAMP (where applicable to systems in scope) ISO 27001 and SOC 2 control frameworks SOX (financial controls, user access reviews)
Support audit activities including
Evidence collection Control validation Remediation tracking
Cloud & Platform Security (Optional)
Contribute to securing SaaS and cloud-hosted applications within AWS environments Review IAM configurations, network exposure, and platform-level risks Partner with cloud and platform teams to ensure consistent security control implementation
This is a remote eligible position. Candidates who live within a 45 mile radius of Boston, MA; Detroit, MI; and Denver, CO will be required to work hybrid (2 days per week) out of our Dyntrace office. Candidates are required to work EST hours for this position. What will help you succeed
Minimum Requirements
2+ years of experience in IT security, application security, or enterprise systems security
Preferred Requirements
Hands-on experience securing or administering one or more of the following:
NetSuite SAP SuccessFactors
Strong understanding of
Identity and access management (IAM) principles Role-based access control (RBAC) and segregation of duties (SoD) Secure system integration and API security
Experience working with compliance frameworks
Familiarity with FedRAMP, ISO 27001, and SOC 2
Experience with AWS security controls (IAM, logging, network security) Knowledge of enterprise logging/monitoring practices (SIEM integration, audit logging) Experience supporting audits or working with internal/external auditors Experience with Dell Boomi or similar iPaaS solutions Familiarity with identity providers (e.g., Okta, Azure AD) and SSO integrations Familiarity with SOX controls for financial systems Ability to translate business processes into security control requirements Strong analytical mindset with focus on risk identification and mitigation Experience working cross-functionally with IT, Security, and business stakeholders Clear communication skills with ability to explain risks and recommendations Why you will love being a Dynatracer
A one-product software company creating real value for the largest enterprises and millions of end customers globally, striving for a world where