A leading national mortgage banker and direct mortgage lender, New American Funding specializes in personalized home loans. Founded in 2003, the company was est
Cybersecurity Analyst III
Location
United States
Posted
72 days ago
Salary
0
Seniority
Mid Level
Job Description
Cybersecurity Analyst III
New American Funding
Overview Position: Sr. Cybersecurity Analyst Salary: Starting at $124,400/year+ D.O.E *Actual compensation may vary from posting based on geographic location, work experience, education, and/or skill level. Location: Santa Ana, CA (on-site preferred; open to remote candidates located beyond a 31-mile radius) Position Summary: The Sr. Cybersecurity Analyst leads the protection of enterprise systems, networks, and data through advanced monitoring, detection, analysis, and response to security events. This role provides technical leadership to the security operations team, mentors junior analysts, collaborates with engineers, IT, and DevOps teams, and contributes to strategic improvements in threat detection, incident response, and overall security posture in a fast-paced, evolving environment. The position emphasizes hands-on expertise in SOC tools, proactive threat hunting, and team guidance to maintain a resilient defensive capability. *Disclaimer: Identity Verification checks are in place throughout the Candidate journey to prevent candidate fraud Responsibilities Monitoring & Detection - Oversee and perform advanced monitoring of alerts from SIEM, EDR/XDR, IDS/IPS, firewalls, and other security platforms. - Lead triage, escalation decisions, and quality assurance for security events across the team. - Develop, tune, and maintain detection rules; lead proactive threat hunting programs to uncover hidden threats. - Analyze security telemetry trends to identify emerging attack patterns and refine detection strategies. Incident Response Leadership - Lead investigations of complex suspicious activity, conduct in-depth root cause analysis, and coordinate multi-team response efforts. - Direct containment, eradication, and recovery during security incidents; serve as primary escalation point for major events. - Oversee documentation of incidents, findings, lessons learned, and corrective actions in incident management systems. - Develop, refine, and maintain incident response playbooks, procedures, and post-incident review processes. Automation and Integration - Develop scripts and automate routine security tasks using Python, PowerShell, or Bash to improve efficiency. - Collaborate with DevOps to embed security controls in systems, applications, and cloud environments. Mentorship and Collaboration - Mentor and develop junior security analysts and team members through technical guidance, training, and knowledge sharing. - Partner with IT, DevOps, and business teams to implement security best practices across the organization. - Lead or support company-wide cybersecurity awareness initiatives, including phishing simulations and training programs. Thought Leadership - Stay current with emerging threats, attack vectors, defensive techniques, and threat intelligence sources. - Share insights with the team and leadership to drive proactive security enhancements. - Contribute to security program strategy, tool evaluations, and process optimization. Qualifications - Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related discipline (or equivalent work experience). - 4–7+ years of experience in IT security, SOC operations, incident response, or related technical roles (with at least 2 years in a senior or lead capacity preferred). - Strong hands-on experience with SIEM platforms, EDR/XDR, vulnerability scanners, firewalls, and endpoint protection tools. - In-depth knowledge of networking protocols, operating systems (Windows/Linux), authentication mechanisms, and cloud security principles (AWS, Azure, O365). - Excellent analytical, troubleshooting, and problem-solving skills. - Proven ability to lead investigations, mentor team members, and communicate effectively with technical and non-technical stakeholders. - Attention to detail and demonstrate performance under pressure in high-stakes security situations. Education, Experience, and Certifications: - Security certifications such as CompTIA Security+, CySA+, CASP+, CEH, GCIH, GCIA, CISSP, or equivalent. - Scripting proficiency (Python, PowerShell, Bash) for automation, analysis, and orchestration. - Prior experience leading SOC operations, incident response teams, threat hunting programs, or shift supervision. - Familiarity with threat intelligence platforms and frameworks (e.g., MITRE ATT&CK). - Exposure cloud security tools and DevSecOps practices. Key Competencies - Exceptional analytical and strategic problem-solving ability. - Strong leadership and mentorship skills with a team-oriented mindset. - Ability to prioritize tasks, enforce procedures, and make sound decisions in high-pressure environments. - Commitment to continuous learning and passion for threat intelligence and advancing security operations. Work Authorization: Must be able to verify identity and employment eligibility to work in the U.S. This position does not offer visa sponsorship. Other Duties: This job profile is not intended to be an all-inclusive list of job duties and responsibilities, as one may perform additional related duties as assigned in order to meet the needs of the organization. Physical Demands: The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. Must be able to lift up to ten pounds. Primary functions require sufficient physical ability and mobility to work in an office setting; to stand or sit for prolonged periods of time; to occasionally stoop, bend, kneel, crouch, reach, and twist; to lift, carry, push, and/or pull light to moderate amounts of weight; to operate office equipment requiring repetitive hand movement and fine coordination including use of a keyboard; and to verbally communicate to exchange information. VISION: See in the normal visual range with or without correction. HEARING: Hear in the normal audio range with or without correction. Pay Transparency Disclosure: If based in New American Funding’s offices, this role has the annual base salary range stated below. Job level and actual compensation will be decided based on factors including, but not limited to, individual qualifications objectively assessed during the interview process (including skills and prior relevant experience, potential impact, and scope of role), market demands, and specific work location. The listed range is a guideline, and the range for this role may be modified. For roles that are available to be filled remotely, the pay range is localized according to employee work location by a factor of between 80% and 100% of range. Please discuss your specific work location with your recruiter for more information. New American Funding offers competitive package of additional benefits, including health, dental & vision, retirement with company contribution, parental leave , mental health & wellness benefits, and generous PTO. New American Funding also offers sales incentive pay for most sales roles and an annual bonus plan for eligible non-sales roles. New American Funding’s compensation and benefits are subject to change and may be modified in the future. [EOE/M/F/D/V. Drug-free workplace.] #LI-JS3 #REMOTE
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
• Monitor and triage security alerts and events across Microsoft security platforms • Conduct initial investigation and evidence collection for security incidents • Coordinate and track remediation efforts for security findings • Support identity and access security processes • Maintain and improve operational documentation based on trend analysis
CYBERSECURITY ASSESSMENT AND AUTHORIZATION SUBJECT MATTER EXPERT (SME) Position : Remote Serves as a cybersecurity Subject Matter Expert (SME) with regards to Assessment and Authorization (A&A) of information systems and all associated cybersecurity policies and procedures. Performs a DOD cybersecurity process while either authorizing an information system or serving as a SME for an information system undergoing authorization. Possess an understanding of how the security controls identified in the NIST 800-53 apply to the process of assessing and authorizing a large organization’s IT infrastructure such as DLA’s, in which there is a compilation of large and small enclaves, AIS applications and outsourced IT processes. Determines the applicable severity value for an identified vulnerability (e.g., non-compliant security control) and determines the possible ramifications on the system’s current or future authorization. Briefs senior management on the progress or results of an information system undergoing the Risk Management Framework (RMF) process. Minimum Requirements: - Five (5) years of relevant Risk Management Framework (RMF) and NIST A&A experience - DOD cybersecurity experience - Experience in assessing security controls and conducting authorization reviews for large, complex organizations. - Experienced in the general tenets supporting the overall DOD implementation of its authorization process, to include supporting cybersecurity policy, procedures, and processes. - Knowledgeable in the cybersecurity of emerging technology areas such as Cloud and Industrial Control Systems (ICSs), warehouse execution systems and - Operational Technology (OT) infrastructures. - DOD Top Secret Clearance and must possess IT-II Non-Critical Sensitive security clearance or Tier 3 (T3) at time of proposal submission. - CERT Personnel: Any team member assigned duties at DLA CERT shall possess a DOD TOP SECRET Clearance and must possess IT-I Critical Sensitive security clearance or Tier 5 (T5) at time of proposal submission. - Any team member assigned duties as DLA CERT Analyst will maintain CSSP-Analyst certification Contract Start is May 17th. 5 Year POP.
Head of Enterprise Security
Zoom Video CommunicationsZoom Video Communications was founded in 2011 to revolutionize the way teams communicate with its software-based conference room solution. Across all devices an
What you can expect Zoom is seeking a hands-on technical leader for our Enterprise Security team. In this role, you will lead the Enterprise Security team and drive corporate security initiatives across the organization including enterprise-wide tooling and policy implementation and process improvement projects. This role is responsible for defining, assessing, and supporting implementation of security policies and controls across Zoom’s Cloud, Network, Infrastructure, Endpoints and Business Applications. This role is also responsible for building and implementing Zoom’s Enterprise AI and Data security policies and governance. The role requires a collaborative approach towards security working with key stakeholders including DevOps, IT, Platform Engineering, Product, and other engineering and security teams. In this role, you are a strategic thinker, reporting directly to the CISO, responsible for defining strategy and requirements and overseeing execution of that strategy. In addition to strong leadership and communication skills, you will need to have deep technical expertise and risk management experience to understand, identify, and prioritize Risk and threats to Zoom. It is also important to have a strong understanding of business impact and be able to balance and align strategy with business priorities. About the Team The Enterprise Security team drives the design, implementation, and management of security programs across data, network, endpoint, infrastructure and cloud domains. They collaborate with technology, compliance, and business teams to integrate security into processes and projects, ensure regulatory compliance, and protect the organization’s systems and information at scale. Responsibilities - Leading and managing the enterprise security team made up of managers, engineers, and analysts. - Defining and executing on enterprise-wide security strategy, policies, and controls, including enterprise-wide security deployments and controls assessments. - Ensuring teams meet regulatory and customer requirements that minimize risks to Zoom. - Driving security risk remediation projects by partnering with internal Security teams, to include Security Assurance, Detection & Response, Security Operations, and Engineering Security teams. - Updating security leadership on Monthly and Quarterly Business Reviews for Enterprise Security. - Implementing data-driven process improvements that improve OKRs and KPIs. What we’re looking for - Have 8+ years of experience in cybersecurity, with at least 3 years experience specifically in an enterprise security leadership role. - Have previous experience at the Director or Senior Manager level, Information Security within a large enterprise security environment, leading and managing implementations, would be a bonus. - Demonstrate advanced technical experience in DevOps, Cloud, network, systems, data, and application security concepts. Apply tools to identify and protect IT assets, detect security events, and remediate discovered vulnerabilities. - Have knowledge and skills managing security of PC, Mac and Linux platforms in a physical, virtual or public cloud environment. - Have experience working in video communications or technical industry preferred. - Possess a Bachelor's or Master's degree in IT Security, Computer Science, or equivalent. - Possess CISSP, OSCP, CISM, CISA, GIAC, or equivalent certifications, would be an advantage. - Be available for occasional after-hours tasks. Salary Range or On Target Earnings: Minimum: $171 800,00 Maximum: $375 900,00 In addition to the base salary and/or OTE listed Zoom has a Total Direct Compensation philosophy that takes into consideration; base salary, bonus and equity value. Note: Starting pay will be based on a number of factors and commensurate with qualifications & experience. We also have a location based compensation structure; there may be a different range for candidates in this and other locations At Zoom, we offer a window of at least 5 days for you to apply because we believe in giving you every opportunity. Below is the potential closing date, just in case you want to mark it on your calendar. We look forward to receiving your application! Anticipated Position Close Date: 04/03/26 Ways of Working Our structured hybrid approach is centered around our offices and remote work environments. The work style of each role, Hybrid, Remote, or In-Person is indicated in the job description/posting. Benefits As part of our award-winning workplace culture and commitment to delivering happiness, our benefits program offers a variety of perks, benefits, and options to help employees maintain their physical, mental, emotional, and financial health; support work-life balance; and contribute to their community in meaningful ways. Click Learn for more information. About Us Zoomies help people stay connected so they can get more done together. We set out to build the best collaboration platform for the enterprise, and today help people communicate better with products like Zoom Contact Center, Zoom Phone, Zoom Events, Zoom Apps, Zoom Rooms, and Zoom Webinars. We’re problem-solvers, working at a fast pace to design solutions with our customers and users in mind. Find room to grow with opportunities to stretch your skills and advance your career in a collaborative, growth-focused environment. Our Commitment At Zoom, we believe great work happens when people feel supported and empowered. We’re committed to fair hiring practices that ensure every candidate is evaluated based on skills, experience, and potential. If you require an accommodation during the hiring process, let us know—we’re here to support you at every step. If you need assistance navigating the interview process due to a medical disability, please submit an Accommodations Request Form and someone from our team will reach out soon. This form is solely for applicants who require an accommodation due to a qualifying medical disability. Non-accommodation-related requests, such as application follow-ups or technical issues, will not be addressed. #LI-Remote
Threat Intelligence Analyst
VMRaySandboxing reinvented against the malware & phishing threats of today - and tomorrow.
• Deliver monthly threat intelligence reports on major events supported by our internal telemetry • Deliver internal briefings to technical teams and executive summaries to leadership • Take ownership of driving threat intelligence focused marketing content • Support threat-hunting and detection engineering by translating intelligence into detection opportunities • Present at relevant CTI-focused conferences and industry events




