Skip to content

Senior Security Analyst

Analyzes insureds’ cybersecurity posture, investigates incidents and claims, and recommends prioritized risk-reduction measures. The role requires 2–4 years of security experience, strong network and threat knowledge, familiarity with assessment tools and security frameworks, and a bachelor’s degree or equivalent experience.

About the job

Responsibilities

  • Review and analyze the security posture of insureds and prospective insureds quickly and efficiently.
  • Evaluate customer security programs, technologies, controls, and business environments; recommend and help develop enhancements to reduce risk.
  • Analyze the root cause of cyber insurance claims and loss events, and identify ways to detect and mitigate exposures that could have prevented those claims.
  • Triage security incidents and claims, understand root cause, and develop detection tradecraft informed by threat intelligence and real-world attacks.
  • Provide practical, prioritized recommendations to help customers manage information security risk and strengthen their security programs.
  • Track emerging security practices, threat trends, and vulnerabilities and contribute those insights to internal processes, playbooks, and product capabilities.
  • Stay current on the regulatory landscape and industry standards, including NIST, ISO, HIPAA, and PCI, and interpret their implications for Coalition and its customers.
  • Collaborate cross-functionally with underwriting, claims, product, and engineering teams to translate security insights into scalable solutions and customer value.

Requirements

  • 2–4 years of hands-on experience in security analysis, blue-team or defensive security operations, and/or penetration testing or red-team engagements.
  • Deep understanding of network threat lifecycles, common attack vectors, exploitation methods, and intrusion-set tactics, techniques, and procedures (TTPs).
  • Strong knowledge of TCP/IP protocols, network analysis, and network/security applications, including log and network traffic capture and analysis.
  • Experience with vulnerability assessment and offensive security tools such as Nmap, Nessus, Nexpose, Qualys, Burp Suite, Kali Linux, or Metasploit.
  • Working knowledge of security and risk frameworks such as NIST CSF, ISO 27001, HIPAA, and PCI DSS.
  • Clear, confident verbal and written communication skills, including the ability to translate technical concepts for non-technical audiences.
  • Ability to learn new technical concepts quickly and manage multiple tasks or projects in a fast-paced environment.
  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related field, or equivalent practical experience.

Nice-to-haves

  • Experience securing cloud-based platforms such as Microsoft Azure or Amazon Web Services, including hardening Windows, Linux, and/or Unix systems.
  • Familiarity with forensic, log analysis, and network analysis tools such as EnCase, FTK, SIFT, Volatility, Splunk, Graylog, ELK/Logstash, Wireshark, or Zeek.
  • Programming or scripting experience with Python, PowerShell, or Bash for security tooling, automation, or framework implementation.
  • Experience with SCADA, ICS, or control-systems networks.
  • Background in cyber insurance, risk quantification, or work with underwriting or claims teams.

Compensation and benefits

  • Remote-first organization.
  • In Alberta, British Columbia, and Ontario, the base salary ranges from $118,600 to $163,075 per year.
  • In all other locations, the base salary ranges from $106,700 to $146,763 per year.
  • Salary within the applicable range depends on education, skills, job-related knowledge, qualifications, experience, credentials, and geographic location.
  • 100% medical, dental, and vision coverage.
  • Flexible paid time off.
  • Annual home-office stipend and WeWork access.
  • Mental and physical health wellness programs.
  • Competitive compensation and advancement opportunities.

Skills

TCP/IP, Network Analysis, Threat Intelligence, Nmap, Nessus, Qualys, Burp Suite, Kali Linux, Metasploit, Nist Csf, ISO 27001, Microsoft Azure, Amazon Web Services, Splunk, Python

Coalition Security

Coalition Security

United States
Senior Security Support Analyst
$94k+/yrRemote5+ YOESecurity Engineering

Investigates cyber incidents and insurance claims, assesses security controls, and advises customers and security leaders on prioritized risk improvements. The role requires 2–4 years of security experience, strong network threat knowledge, and familiarity with major security and compliance frameworks.

OpenAI

OpenAI

Toronto, Canada

Cyber Operations Strategist, Critical Harm Operations
CA$140k+/yrRemote8+ YOESecurity Engineering

Senior individual contributor responsible for improving cyber operations, resolving complex dual-use safety decisions, and building scalable reviewer, quality, vendor, and automation systems. Requires 8+ years of hands-on cybersecurity experience and strong operational judgment.

GitLab

GitLab

United States
Senior Manager, Product Security Engineering
$168k+/yrRemote5+ YOESecurity Engineering

Leads the Product Security team responsible for security posture management, governed security rollouts, and software supply chain security across GitLab’s software factory. The role combines technical security leadership, organizational adoption, audit readiness, team building, and external thought leadership.

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

Instacart

Instacart

United States
Senior Detection Engineer II
$192k+/yrRemote6+ YOESecurity Engineering

Develops and operates detection engineering systems across endpoint, cloud, container, and SaaS environments. The role requires at least six years in detection, incident response, or offensive security, strong attacker TTP knowledge, macOS expertise, and detection-as-code experience.