Skip to content
ValonValon

Senior Security Analyst

The Senior Security Analyst will manage security governance, risk, and compliance activities, including audits, risk assessments, remediation, vendor reviews, and operational security. The role requires 5+ years of relevant experience, a bachelor’s degree, cloud-security knowledge, and hands-on AI-assisted GRC automation experience.

About the job

Responsibilities

  • Implement and maintain compliance with security frameworks including SOC 2, NIST CSF, and CIS, plus regulatory requirements such as NYDFS, GLBA Safeguards, and CCPA.
  • Support internal and external security audits and examinations, including evidence collection and remediation tracking.
  • Build AI-assisted GRC workflows to scale governance, risk, and compliance functions.
  • Maintain the security risk register, conduct risk assessments, and manage remediation processes.
  • Manage security governance and compliance projects and support related project-management efforts.
  • Track security metrics, KPIs, and reporting.
  • Support customer security due-diligence processes.
  • Review, manage, and monitor security policies for compliance.
  • Facilitate remediation of security and compliance issues across stakeholders.
  • Manage vendor security risk assessments.
  • Support operational security activities, including security monitoring, incident management, security reviews, security awareness, and training.

Requirements

  • 5+ years of experience as a security analyst or security program manager in relevant security compliance, risk management, issue management, or program management work.
  • Bachelor's degree in Computer Science, Information Security, Technology, or a related field.
  • Experience with security compliance frameworks and risk assessments.
  • Experience with operational security activities, including issue management, security reviews, control monitoring, incident management, and reporting.
  • Experience with frameworks and requirements such as OWASP, SOC 2, NIST CSF, NIST 800-53, ISO 27001/2, CIS, NYDFS, and CCPA.
  • Basic knowledge of cloud security and public cloud environments.
  • Experience maintaining security risk registers and issue-management processes.
  • Hands-on experience with AI tooling and AI-assisted workflows.
  • Relevant security certifications such as CompTIA Security+, CC, SSCP, CISSP, CISM, or CRISC, depending on career experience.
  • Strong communication, collaboration, organization, and project-management skills.
  • Ability to explain security concepts to technical and non-technical stakeholders and work autonomously across multiple projects.

Nice to Have

  • Experience in startup environments.
  • Experience in financial services or technology organizations.

Compensation and Benefits

  • Base salary: $115,000–$145,000.
  • Equity and 401(k) plan.
  • Medical, dental, and vision benefits.
  • Commuter benefits.
  • Learning and development opportunities.
  • Flexible paid time off, sick days, and 11 company holidays.
  • 12 weeks of fully paid parental leave for birthing and non-birthing parents.

Skills

SOC 2, Nist Csf, Cis, Owasp, Nist 800-53, ISO 27001, Nydfs, CCPA, Cloud Security, Risk Assessments, Incident Management, Security Monitoring, AI Tools, Security Audits, Security Policies

Supernova Technology

Supernova Technology

Chicago, IL

Senior Information Security Engineer
$110k+/yrOn-site5+ YOESecurity Engineering

The Senior Information Security Engineer will lead threat hunting, detection engineering, incident response, vulnerability management, and security-platform ownership across cloud and enterprise environments. The role requires 5+ years of security experience, strong attacker-TTP knowledge, and hands-on expertise with enterprise security technologies and automation.

Chainguard

Chainguard

United States

Senior Security Analyst
$110k+/yrRemote5+ YOESecurity Engineering

Build and operate Chainguard’s public-sector governance and trust capabilities, translating federal security requirements into automated controls, evidence systems, and risk-based decisions. The role requires hands-on federal, defense, or intelligence experience and strong technical fluency in cloud-native environments.

Ontic

Ontic

United States

Senior Cloud Security Engineer
$110k+/yrRemote5+ YOESecurity Engineering

Leads the maturation of an AWS cloud security program by designing and automating controls, integrating security into CI/CD workflows, and developing continuous compliance evidence. The role requires AWS security expertise and experience with infrastructure as code, automation, regulated SaaS, and cloud compliance initiatives.

Reltio

Reltio

United States

Senior Cloud Security Engineer
$122k+/yrRemote5+ YOESecurity Engineering

Senior Cloud Security Engineer responsible for designing, implementing, and assessing security controls across a multi-cloud environment. The role requires 5+ years of security solution implementation experience, strong cloud and cybersecurity expertise, and proficiency in risk assessment, infrastructure as code, and security technologies.

BlackCloak

BlackCloak

United States

Senior Incident Responder
$105k+/yrRemote5+ YOESecurity Engineering

Leads end-to-end response to sophisticated compromises, account takeovers, device threats, and related financial fraud for high-profile clients. Requires 5–8+ years of incident response or DFIR experience, broad device forensics expertise, strong client communication, and fraud-remediation experience.