Senior Security Analyst
About the role
Lead investigation and response activities for security incidents, suspicious activity, and emerging threats.
Design, implement, and improve security monitoring, detection, and response capabilities across our AWS environment.
Develop and maintain effective detection rules, alerting strategies, and investigation procedures.
Conduct post-incident reviews to identify root causes, lessons learned, and preventative measures.
Identify security exposures, vulnerabilities, misconfigurations, and non-compliance risks and communicate recommendations clearly.
Perform security assessments of third-party vendors, services, and technologies.
Partner with Technology and Product teams to design secure solutions and strengthen existing controls.
Support vulnerability management, threat modeling, and endpoint security initiatives.
Create and maintain security documentation, standards, and operational procedures.
Contribute to security awareness efforts and provide guidance on secure business practices.
Stay current on evolving threats, attacker techniques, and defensive technologies.
Qualifications
- Required: US Citizenship, living in the USA
5+ years of experience in security operations, security engineering, or a similar cybersecurity role
Strong experience with security monitoring, incident response, threat detection, and forensic investigations
Deep understanding of network security, application security, infrastructure hardening, and vulnerability management
Experience deploying, managing, and automating security solutions in cloud environments
Strong knowledge of AWS architecture, security services, and cloud security best practices
Experience working with macOS, Linux, and Windows environments
Strong understanding of log collection, analysis, and security event investigation
Ability to communicate technical risks and recommendations clearly to both technical and non-technical audiences
Experience supporting compliance initiatives such as SOC 2, ISO 27001, GDPR, FedRAMP or PIPEDA - Nice to have: Experience with threat modelling programs
Experience building security automation workflows
Experience assessing third-party vendors and SaaS platforms
Security certifications such as CISSP, GCIH, GSEC, Security+, AWS Certified Security – Specialty, or AWS Certified Solutions Architect