Point your AI agent at freehire and let it find you a job.

Get the CLI →

jobgether

NewBe an early applicant

Senior Security Analyst

Posted Updated
Discussion

Summary

Hands-on security role protecting cloud infrastructure, corporate systems, and customer data: the analyst investigates threats, builds AWS detection and monitoring, leads incident response, and supports FedRAMP/compliance work (SOC 2, ISO 27001, GDPR). Fully remote anywhere in the United States.

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Analyst based in United States.

As a Senior Security Analyst, you will play a hands-on role in protecting cloud infrastructure, corporate systems, and sensitive customer data.
You’ll help strengthen security operations by investigating threats, improving detection capabilities, and leading incident response activities.
The role combines technical security analysis with risk management, compliance, and cross-functional collaboration.
You’ll work extensively across AWS environments while helping develop security controls, procedures, and monitoring capabilities.
You’ll also contribute to vulnerability management, threat modeling, third-party assessments, and security architecture decisions.
This is an opportunity to help build and mature security processes in a growing environment where ownership and sound judgment are highly valued.
Your work will directly support enterprise trust, regulatory readiness, and the resilience of critical systems.

Accountabilities

  • Lead and support investigations and response activities involving security incidents, suspicious activity, vulnerabilities, and emerging threats.

  • Design, implement, and continuously improve security monitoring, detection, alerting, and response capabilities across AWS environments.

  • Develop and maintain detection rules, investigation procedures, security workflows, and operational processes.

  • Conduct post-incident reviews to identify root causes, lessons learned, control gaps, and preventative measures.

  • Identify security exposures, vulnerabilities, misconfigurations, and compliance risks, and communicate practical recommendations to relevant stakeholders.

  • Perform security assessments of third-party vendors, SaaS platforms, services, and technologies.

  • Partner with Technology and Product teams to design secure solutions and strengthen existing security controls.

  • Support vulnerability management, threat modeling, endpoint security, and broader security engineering initiatives.

  • Provide evidence and supporting materials for compliance programs and regulatory activities.

  • Maintain security documentation, standards, operational procedures, and related governance materials.

  • Support security awareness initiatives and provide guidance on secure business practices.

  • Monitor evolving threats, attacker techniques, defensive technologies, and relevant security developments.

  • Authorize and approve user access in accordance with applicable security requirements and processes.

  • Coordinate with relevant AI and security teams on corporate-level security program functions.

  • Develop and maintain an accurate System Security Plan (SSP) package for the designated FedRAMP system and distribute relevant elements on a need-to-know basis.

  • Designate and coordinate personnel responsible for critical security program functions, including incident handling and disaster recovery.

  • Receive and assess operational alerts, updates, and status reports from team members and critical system components.

  • Oversee the continuous monitoring program for U.S. operations and report security and privacy status to relevant external entities, including customer agencies, FedRAMP program stakeholders, and third-party assessment organizations.

  • Requirements

    • 5+ years of experience in security operations, security engineering, cybersecurity, or a closely related field.

    • U.S. citizenship and residence within the United States.

    • Strong experience in security monitoring, incident response, threat detection, and forensic investigation.

    • Deep understanding of network security, application security, infrastructure hardening, vulnerability management, and defensive security practices.

    • Experience deploying, managing, and automating security solutions within cloud environments.

    • Strong knowledge of AWS architecture, AWS security services, and cloud security best practices.

    • Experience working across macOS, Linux, and Windows environments.

    • Strong understanding of log collection, analysis, security event monitoring, and investigation.

    • Experience creating, maintaining, and improving security procedures and operational processes.

    • Ability to communicate technical risks, findings, and recommendations clearly to both technical and non-technical stakeholders.

    • Demonstrated experience supporting FedRAMP certification and continuous monitoring activities, preferably within Class D (High) or Class C (Moderate) environments.

    • Experience supporting compliance frameworks such as SOC 2, ISO 27001, GDPR, or comparable standards.

    • Experience with threat modeling programs is a plus.

    • Experience building security automation workflows is a plus.

    • Experience evaluating third-party vendors and SaaS platforms is a plus.

    • Security certifications such as CISSP, GCIH, GSEC, Security+, AWS Certified Security – Specialty, or AWS Certified Solutions Architect are valued.

    • Strong ownership, analytical thinking, attention to detail, calm decision-making, and the ability to work effectively with incomplete information.

    • A continuous-learning mindset and the ability to balance strong security practices with practical business requirements.

    • Benefits

      • Competitive compensation package for a full-time, permanent position.

      • Stock options/equity participation.

      • Comprehensive health and benefits coverage.

      • 401(k) matching.

      • Unlimited paid vacation.

      • Fully remote work from anywhere in the United States.

      • Opportunity to work on cloud security, threat detection, incident response, compliance, and security operations at enterprise scale.

      • Exposure to AWS security, FedRAMP continuous monitoring, security automation, and evolving cybersecurity challenges.

How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

Skills

What Senior Security jobs ask for — and how much of it you have →

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available