Sr. Security Analyst
$120,000–$130,000 year
HybridWoodinville, Washington, United States
Job Summary
Conduct vulnerability scans, penetration testing, and security assessments across applications, systems, cloud environments, and infrastructure using tools like Tenable Nessus, Burp Suite, and CrowdStrike. Test web applications for exploits, evaluate Linux and cloud environments including AWS, OCI, and Azure, and partner with engineering teams to improve hardening standards and access controls. Monitor security events, investigate incidents, support response activities, and develop reports for stakeholders. Help establish repeatable security processes, define the red-team function, and improve policies and employee awareness initiatives. Collaborate with IT, legal, compliance, and business teams to reduce organizational risk proactively.
Required Qualifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field
- Professional experience in information security, application security, infrastructure security, or a closely related area
- Hands-on experience with Microsoft Defender
- Hands-on experience with Microsoft Purview
- Hands-on experience with CrowdStrike
- Hands-on experience with Tenable Nessus
- Hands-on experience with Burp Suite
- Proven experience with application and environment security
- Proven experience with vulnerability testing
- Proven experience with exploit testing
- Proven experience with penetration testing
- Proven experience with vulnerability scanning
- Strong understanding of cloud security
- Experience securing environments such as AWS, OCI, or Azure
- Experience working with Linux environments
- Securing cloud-based or distributed infrastructure
- Knowledge of security frameworks and standards such as NIST, CIS, or ISO 27001
- Understanding of risk management practices
- Ability to identify, prioritize, and communicate security risks
- Working knowledge of security technologies such as firewalls, IDS/IPS, endpoint security, SIEM, and enterprise intrusion-prevention systems
- Experience with system-hardening standards for servers, desktops, laptops, or network devices
- Understanding of malware, attack vectors, network threats, incident response, authentication, and access-control technologies
- Knowledge of internet protocols and security technologies, including HTTP, TLS, SSL, HTML, and XML
- Understanding of cloud, container-based, and virtualized architectures
- Knowledge of encryption techniques, standards, and appropriate encryption levels
- Strong analytical, problem-solving, and attention-to-detail skills
- Clear communication skills
- Ability to work effectively across technical and nontechnical teams
- A collaborative and humble working style
- Ability to accept direction
- Ability to execute priorities
- Ability to remain open to the perspectives of others
- Must be 18 years or older to apply
- Must live within commuting distance
- Must be able to work onsite 4 days per week
- Must be able to work 1 day remote
Desired Qualifications
- Previous experience in an IT infrastructure, systems administration, networking, DevOps, or engineering role before moving into security
- Experience that combines technical security with governance, risk, compliance, or privacy responsibilities
- Familiarity with privacy regulations such as GDPR, CPRA, or CCPA
- Experience with firewalls, load balancers, web application firewalls, or VPN concentrators
- Experience with databases and related technologies such as Elasticsearch, SQL, or Oracle
- Experience handling and protecting information across different sensitivity levels
- Familiarity with standards or regulations such as FISMA, GLBA, FERPA, PCI DSS, ISO, or NIST
- Higher education or government information-security experience
- Security certifications such as CISSP, CISA, CISM, CEH, GWAPT, GPEN, CSFA, or similar credentials
- Experience with SUMO Cloud or comparable security monitoring and log-analysis tools
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.