CoLab Software - Senior Security Analyst
Requirements
• You're the type of person who sees an alert and wants to understand the full story—not just close the ticket. • You can move comfortably between technical investigation, risk discussions, and stakeholder communication. During an incident, you're calm, methodical, and focused on facts. Afterward, you're just as interested in improving systems and processes to prevent it from happening again. • You'll thrive here if you enjoy: • Solving difficult security problems with incomplete information • Taking ownership of outcomes, not just tasks • Learning continuously as technologies and threats evolve • Working closely with Security, Technology, and Product teams • Balancing strong security practices with business realities • US Citizenship, living in the USA • 5+ years of experience in security operations, security engineering, or a similar cybersecurity role • Strong experience with security monitoring, incident response, threat detection, and forensic investigations • Deep understanding of network security, application security, infrastructure hardening, and vulnerability management • Experience deploying, managing, and automating security solutions in cloud environments • Strong knowledge of AWS architecture, security services, and cloud security best practices • Experience working with macOS, Linux, and Windows environments • Strong understanding of log collection, analysis, and security event investigation • Experience developing and maintaining security procedures and operational processes • Ability to communicate technical risks and recommendations clearly to both technical and non-technical audiences • Experience supporting compliance initiatives such as SOC 2, ISO 27001, GDPR, FedRAMP or PIPEDA • Experience with threat modelling programs • Experience building security automation workflows • Experience assessing third-party vendors and SaaS platforms • Security certifications such as CISSP, GCIH, GSEC, Security+, AWS Certified Security – Specialty, or AWS Certified Solutions Architect • The Extra Details • The Extra Details • This is a full-time, permanent position with a competitive compensation package that includes stock options • Comprehensive health and benefits coverage • Unlimited paid vacation • This role can be performed remotely from anywhere in the United States of America • Equity Note • Equity Note • Frequently cited statistics show that people who identify with historically marginalized groups are likely to apply to jobs only if they meet 100% of the qualifications. We encourage you to help us break that statistic and apply even if you don’t meet every single qualification—your potential is what matters most to us.
Responsibilities
• Lead investigation and response activities for security incidents, suspicious activity, and emerging threats • Design, implement, and improve security monitoring, detection, and response capabilities across our AWS environment • Develop and maintain effective detection rules, alerting strategies, and investigation procedures • Conduct post-incident reviews to identify root causes, lessons learned, and preventative measures • Identify security exposures, vulnerabilities, misconfigurations, and non-compliance risks and communicate recommendations clearly • Perform security assessments of third-party vendors, services, and technologies • Partner with Technology and Product teams to design secure solutions and strengthen existing controls • Support vulnerability management, threat modeling, and endpoint security initiatives • Create and maintain security documentation, standards, and operational procedures • Contribute to security awareness efforts and provide guidance on secure business practices • Stay current on evolving threats, attacker techniques, and defensive technologies • Authorizes/approves user access to CoLab • Coordinates with relevant CoLab AI teams for program functions wholly or partially implemented at the corporate level (i.e., general security training) • Develops and maintains an accurate and up-to-date System Security Plan (SSP)Package for the FedRAMP-designated system • Distributes copies of SSP Package elements to relevant team members, on a need-to-know basis • Designates key personnel as responsible for core program functions (i.e., incident handling, disaster recovery, etc.) • Receives operational alerts, updates, and status reports from team members and critical system components • Oversees the Continuous Monitoring Program for CoLab • Reports the security and privacy state of CoLab to external entities (i.e., CustomerAgencies, FedRAMP Program Management Office (PMO), Third Party AssessmentOrganizations (3PAOs)
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT