Jobs · Information Technology

Security analyst

Gravity Payments · Boise, ID · 1 wk ago
RemoteRemoteInformation Technology$90k–$168k/yrFull-time

Join a collaborative team at Gravity Payments where creative leadership, passion for progress, and responsibility are paramount. Our team members focus on providing for clients and the community with deep care and commitment.

About the role

We are seeking a Security Analyst to operate and build security across our cloud, endpoint, identity, SaaS, and corporate environments. In this hands-on, high-trust role, you will triage and investigate alerts, respond to incidents on a 24x7 rotation, and hunt for threats that automated detections miss. You will directly impact the quality of our existing security systems and shape the future of our security program through operational excellence and innovation.

Success in this role

  • Within 3 months: Co-own first-line alert triage across our SIEM and connected tools. Serve as a confident first responder on the 24x7 on-call rotation, investigating and dispositioning alerts with prompt escalation of real incidents.
  • Within 6 months: Lead complex, sensitive investigations in our payments environment, such as analyzing fraud signals or account-takeover attempts, with discretion and sound evidence practice. Reduce the likelihood or impact of a tracked threat on our Risk Register, create or advance a SOAR playbook, and add a new, fully correlated signal source to our SIEM.
  • Within 1 year: Operate as a dual builder and operator, owning your corner of the security program. Lead significant threat investigations end-to-end, measurably reduce response times and false-positive pages through automation, and influence future automation investments. Support PCI DSS and SOC 2 audits while maturing our detection, defense, and reporting capabilities.

Responsibilities

  • Monitor, triage, investigate, and disposition security alerts across SIEM, endpoint, cloud, identity, email, SaaS, network, data loss prevention, and file integrity sources.
  • Participate in a shared 24/7 on-call rotation, perform initial containment, and escalate confirmed or complex incidents promptly.
  • Engineer automation and integrations across the security stack, developing code to connect and orchestrate tools, and advance SOAR playbooks to reduce manual intervention and speed response.
  • Apply agentic AI as a force multiplier with tested results, human oversight, and full auditability.
  • Investigate security incidents, malicious email, suspected fraud, insider threats, and data loss events. Conduct proactive threat hunts, preserve evidence, and contribute clear incident reports and follow-up actions.
  • Build and maintain SaaS, endpoint, and application security posture; operate file integrity monitoring; run phishing simulations; support penetration tests; and track identified gaps through remediation or risk acceptance.
  • Support PCI DSS and SOC 2 compliance through evidence collection automation and audit engagement interviews.
  • Maintain and iterate weekly and quarterly reporting for leadership. Document investigations and response procedures, and provide daily guidance to team members via company security help channels.
  • Continuously apply your expertise to evolve our detection and response paradigms.

Requirements

  • At least 3 years of hands-on experience in security operations, incident response, vulnerability management, systems administration, or a closely related role, including independent alert investigation and escalation or containment responsibility.
  • A bachelor's degree in cybersecurity, computer science, information technology, or a related field, or an equivalent combination of practical experience, training, and certification.
  • Hands-on experience with SIEM and EDR/XDR platforms and security telemetry from cloud, endpoint, identity, email, and SaaS systems. Familiarity with our environment, including CrowdStrike NG-SIEM, AWS CloudTrail and CloudWatch, AWS Security Hub, Okta, Microsoft Entra, Google Workspace, Keeper, Duo, UniFi, Microsoft Defender, Jira, and MintMCP.
  • Ability to query, interpret, and correlate logs using a SIEM query language such as LogScale/CQL, SPL, or comparable. Proficiency in Python, PowerShell, and shell scripts for repeatable actions and analysis.
  • Advanced working knowledge of Windows, macOS, and Linux system internals; patch and configuration management; endpoint hardening; network and internet protocols; and identity and access concepts.
  • Extensive experience with incident triage, containment, evidence collection, threat hunting, phishing analysis, and incident documentation. Strong understanding of MITRE ATT&CK and advanced attacker techniques.
  • Demonstrated experience with vulnerability management, including risk-based prioritization, remediation tracking, and use of CVSS, exploitability information, and service level targets.
  • Working knowledge of AWS security services and cloud investigation methods, including CloudTrail, CloudWatch, Security Hub, IAM, and cloud workload security.
  • Working knowledge of PCI DSS, SOC 2, or similar security and compliance frameworks, with experience collecting evidence or supporting control testing.
  • Ability to participate in a shared 24/7 on-call rotation and respond to time-sensitive events.
  • Must have access to a wired internet connection with at least 25 Mbps download and 20 Mbps upload speeds.

Preferred Skills

  • Experience working within or closely with Technology, Engineering, and DevOps teams at a small or midsize company, where cross-functional collaboration and shared ownership are expected.
  • Experience in the credit card payment services industry or another regulated financial services environment.
  • Strong judgment and attention to detail, with a calm, methodical approach under pressure and a sound sense of when to contain, escalate, or act on incomplete or uncertain data.
  • Clear written and verbal communication that explains findings, risk, and required actions to technical and non-technical audiences, and the ability to influence teams without direct authority.
  • Strong organization and follow-through, managing investigations, operational work, and remediation tracking simultaneously, with a continuous learning mindset toward current attacker methods and defenses.
  • A self-driven adopter of AI who treats it as a force multiplier, instinctively uses it to compare evidence, find gaps, and speed assessments, and verifies every output before use.

Benefits

  • Compensation: Competitive base pay with profit sharing, offering a unique opportunity to earn a share in company success.
  • Comprehensive Benefits: Medical, dental, and vision coverage.
  • Financial Security: 401(k) retirement plan and voluntary life insurance.
  • Wellbeing: Time off when you need it, supporting both personal and professional sustainability. Open PTO available after one year.
  • Career Growth: Training, mentorship, and development opportunities.
  • Support & Stability: Short-term and long-term disability coverage and wellness resources.

Pay

The salary for this position is $90,000 - $168,000. We may be open to negotiating outside of this range if the desired salary aligns with the needs of the candidate and the company.

Similar jobs

Security Analyst

Credit Control, LLC.Earth City, MO· 2 mo ago
Information Technologyapply on creditcontrolllc.bamboohr.com

Security Analyst

TALENT Software ServicesColumbia, SC· 1 mo ago
OTHRapply on www2.jobdiva.com

Security Analyst

VimoMountain View, CA· 2 mo ago
RemoteEngineeringapply on paycomonline.net

Security Analyst

Arista NetworksSanta Clara, CA· 2 mo ago
Engineering$103k–$154k/yrapply on jobs.smartrecruiters.com

Security Analyst

Target HospitalityThe Woodlands, TX· 1 mo ago
Information Technologyapply on recruiting2.ultipro.com