Description:
As a Senior Analyst on the Security & Risk team, you are charged with helping protect a company that secures the most secure. You will safeguard both our production corporate environments and the product and R&D space, helping security act as an enabler of the business rather than a brake on it.
Principal Responsibilities
- Serve as second level Incident Response interacting with our third-party SOC and be a security SME on a shared on-call rotation.
- Operate and tune core detection and response tooling — such as SIEM, SOAR, XDR/EDR, WAF, and NGFW — to sharpen signal and cut noise.
- Apply identity-centric and Zero Trust controls — access, MFA, and least privilege — alongside the IT platform and product teams.
- Support security as an enabler in the product and R&D lifecycle, advising engineering on secure-by-design patterns.
- Be an advocate and enabler for maturing the security controls around data, AI services and our products
- Maintain clear documentation, runbooks, develop metrics, and present findings to both technical and non-technical audiences.
- Deep-dive into security systems as needed to investigate issues and automate recurring tasks through scripting or AI Agents as appropriate.
- Act as the bridge between technical and non-technical contributors
Education & Experience
- 4 - 6 years of related cybersecurity operations experience with a bachelor’s degree; or 2 or more years with a master’s degree.
- Hands-on production operation of multiple security technologies in public cloud (Azure and/or AWS) and on-premises environments — including vulnerability scanning and management, SIEM/logging, WAF, network segmentation and security groups, system hardening/STIG, malware prevention, and incident response.
- Intermediate grasp of identity and access management and Zero Trust principles — authentication and authorization standards (MFA, SAML, OAuth, OIDC), directory services, and least-privilege access — reflecting identity’s role as the modern control point.
- Working knowledge of networking concepts and of both Linux and Windows host operating systems.
- Critical-thinking drive — asking what could be, how it could be done better, and pursuing continuous improvement and efficiency through automation — paired with a collaborative work style.
- Strong written, spoken, and presentation skills, with the ability to communicate security decisions clearly and to translate between technical and non-technical audiences.
- US Citizen / US Soil