ExtraHop logo
ExtraHop

Security Uncompromised

Product Security Analyst III

Security AnalystSecurity AnalystFull TimeRemoteSeniorTeam 501-1,000H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

2 days ago

Salary

$135K - $149K / year

Seniority

Senior

Bachelor Degree5 yrs expEnglishCloudCyber Security

Job Description

Product Security Analyst III

ExtraHop

• Run FedRAMP Continuous Monitoring (ConMon) processes and ensure successful monthly reviews with ExtraHop and agency stakeholders; manage asset inventory, vulnerability scan findings, and the Plan of Action & Milestones (POA&M) document • Manage vulnerability detection and response pipelines, including tools, reporting and tracking • Lead the vulnerability management lifecycle: triage, reporting, coordination with system owners, and remediation tracking • Develop and provide vulnerability findings and responses for internal and external stakeholders, including customers • Collaborate with the Director of Product Security to handle customer and pre-sales security inquiries • Assist in addressing compliance requirements for various standards, (e.g., CSA STAR, ISO 27001, DoDIN APL, NIAP, FIPS, CMMC, IL4), supporting gap assessments and facilitating audits (including coordinating evidence collection and submission) • Develop a product security compliance roadmap and coordinate key activities across the organization to achieve milestones • Collaborate with Product Security team members to develop and improve standards, policies, procedures, documentation, and training • Work with security information & event management (SIEM) tooling and other systems to perform security investigations • Perform and/or lead security incident response activities • Participate in an on-call rotation with occasional after-hours paging to review carefully prioritized security detections

Job Requirements

  • 5+ years of experience in cybersecurity, with a focus on compliance frameworks like FedRAMP, SOC 2, or similar
  • 2+ years of which should be hands-on experience specifically managing compliance programs, security assessments, or cloud security initiatives
  • Bachelors degree in a related field such as Cybersecurity, Computer Science, Information Systems, Engineering or other technical field
  • Direct experience with the FedRAMP compliance framework, including security control requirements, documentation and assessment methodologies
  • Technical knowledge of web application security and cloud security, including best practices and controls for cloud-based environments
  • Proficient with security tools, including vulnerability scanners, ticketing systems (e.g., Jira), compliance reporting platforms, and SIEM tools
  • Exceptional analytical skills to effectively manage and resolve security and compliance issues
  • Proven ability to communicate complex security concepts to technical and non-technical audiences
  • All R&D Employees will be required to attend 2 mandatory in-person events every year. These events are typically held in our offices in downtown Seattle and run 4-5 days each
  • Must be a U.S. citizen or national, U.S. permanent resident (current Green Card holder) or lawfully admitted into the U.S. as a refugee or granted asylum.

Benefits

  • Health, Dental, and Vision Benefits
  • Flexible PTO, Sick Time Prorated Based on Date of Hire, and All Federal Holidays (US Only) + 3 Days of Paid Volunteer Time
  • Non-Commissioned Positions may be eligible to participate in the Annual Discretionary Bonus Plan
  • FSA and Dependent Care Accounts + EAP, where applicable
  • Educational Reimbursement
  • 401k with Employer Match or Pension where applicable
  • Pet Insurance (US Only)
  • Parental Leave (US Only)
  • Hybrid and Remote Work Model

Related Job Pages

More Security Analyst Jobs

Information Security Analyst

Machinify

Machinify focuses on providing machine learning solutions to businesses and was created to help companies integrate artificial intelligence into everyday practices. The company pro

Role Description At Machinify, we’re building a robust security program to protect our clients’ sensitive healthcare data and maintain the highest standards of information security. As part of the Security team, you will play a central role in managing our security assurance operations — helping ensure that customer requests, audit activities, and compliance processes run smoothly and efficiently. This is an entry-level role suited for someone detail-oriented, hardworking, and intellectually curious. A background in cybersecurity is helpful but not required. We’ll consider candidates with experience in business operations, finance, accounting, or related fields who demonstrate strong organizational instincts and a commitment to doing things right. What You’ll Do - Security Assurance Operations (60% of role) - Own the intake process for security assurance requests: review incoming tickets, triage and prioritize work, assign tasks to the appropriate team members, and track requests to resolution. - Resolve routine and straightforward security inquiries and questionnaire items independently. - Communicate clearly with internal stakeholders and customers throughout the assurance process, setting expectations and providing status updates. - Respond to customer security questionnaires and audit requests with accuracy and timeliness, escalating complex items as appropriate. - Maintain the security documentation repository and ensure materials are current and accessible. - Support customer-facing security calls and presentations alongside senior team members. - Audit and Compliance Support (25% of role) - Assist with HITRUST r2 and SOC 2 audit preparation and evidence collection. - Help coordinate audit activities across internal teams, tracking open items and deadlines. - Support access review processes and other recurring compliance activities. - Assist with security policy and procedure maintenance. - General Security Program Support (15% of role) - Track and report on security metrics and assurance request status. - Support vendor risk assessment activities. - Assist with security awareness efforts and documentation as needed. - Participate in security incident response when needed. Qualifications - Bachelor’s degree in Information Security, Business, Operations, Finance, Accounting, or a related field, or equivalent work experience. - Strong attention to detail and follow-through — you catch things others miss and see tasks through to completion. - Excellent written and verbal communication skills, including comfort communicating with external clients. - Ability to manage multiple concurrent requests and prioritize effectively in a fast-paced environment. - Strong problem-solving orientation; you approach unfamiliar situations with curiosity and good judgment. - Proficiency with productivity and work-tracking tools (ticketing systems, spreadsheets, document management). Requirements - 1–2 years of experience in operations, compliance, audit support, finance, or a related field. - Exposure to information security concepts, frameworks (NIST, HITRUST, SOC 2), or HIPAA compliance. - Experience in healthcare, healthcare technology, or working with regulated data environments. - Familiarity with GRC or security assurance workflows. Benefits - Work from anywhere in the US! Machinify is digital-first. - Top Medical/Dental/Vision offerings. - FSA/HSA. - Tuition reimbursement. - Competitive salary, 401(k) with company match. - Additional health and wellness benefits and perks. - Flexible and trusting environment where you’ll feel empowered to do your best work.

United States
$70K - $95K / year
Teltec Solutions logo

Analista de Segurança III

Teltec Solutions

Transforming your business in the face of the challenges of the digital economy with experience, competence, and innovat

Full TimeRemoteTeam 201-500Since 1991H1B No Sponsor

• Apoiar a equipe comercial na qualificação, apresentação e proposição de soluções de segurança que sejam aderentes a necessidade dos clientes; • Realizar adoção de soluções de segurança implantadas, potencializando o benefício das soluções para os clientes; • Desenvolver projetos técnicos detalhados, prezando pela aderência e adequação às características de cada cliente; • Realizar a implantação de soluções de segurança no ambiente dos clientes de acordo com boas práticas recomendadas e procedimentos internos da Teltec; • Executar atividades corretivas ou evolutivas no ambiente de infraestrutura dos clientes; • Documentar atividades e trabalhos realizados nos projetos durante a fase comercial e após a implantação dos projetos; • Realizar treinamentos técnicos orientados a soluções específicas dos clientes; • Atender solicitações técnicas de 3º nível originadas pelo Service desk; • Promover conhecimento aos analistas, transferindo e multiplicando seu conhecimento e experiência dentro da equipe.

Brazil
Valsoft Corporation logo

Compliance, Security & AI Governance Analyst

Valsoft Corporation

Valsoft Corporation acquires and builds market software solutions. The company invests in stable businesses and aims to foster an entrepreneurial environment po

Role Description Responsible for day-to-day operation of the company’s compliance and AI governance program in a regulated, government-facing environment. This role focuses on translating regulatory, cybersecurity, AI governance, and audit requirements into actionable internal processes, coordinating audit readiness, maintaining documentation, and ensuring ongoing compliance alignment. The position partners closely with the CTO, Cloud Hosting Manager, Engineering, and Security stakeholders to support secure operations, responsible AI usage, and adherence to applicable regulatory frameworks and data protection standards. - Interpret regulatory, contractual, cybersecurity, and AI governance requirements (e.g., SOC 2, CJIS, NIST-based controls, ISO 27001, AI governance standards, state/local requirements) into internal tasks and control activities - Coordinate audit readiness efforts, including evidence collection, organization, validation, and remediation tracking - Serve as primary internal point of contact for auditors; support external audit processes, security assessments, and follow-up activities - Maintain and update policies, procedures, control narratives, risk assessments, AI governance documentation, and compliance records - Track compliance status, findings, risks, and remediation efforts; ensure timely closure of identified gaps - Partner with Hosting, Engineering, Security, and Product teams to validate implementation of security, privacy, and AI-related controls - Support governance and oversight of AI-related processes, including data handling, model usage, vendor assessments, and responsible AI practices - Assist in identifying and mitigating cybersecurity, privacy, and AI-related operational risks - Escalate ambiguous, high-risk, or non-compliant requirements and coordinate resolution activities - Support vendor compliance reviews, security questionnaires, and third-party risk documentation requests as needed - Assist in maintaining control mappings across multiple compliance and security frameworks - Contribute to continuous improvement of compliance, information security, and AI governance processes Qualifications - 3–7+ years of experience in compliance, risk management, cybersecurity governance, audit coordination, or related function - Working knowledge of at least one framework (SOC 2, NIST, CJIS, ISO 27001, or similar) - Familiarity with cybersecurity governance principles, access controls, data protection practices, and risk management methodologies - Exposure to AI governance, responsible AI practices, data privacy considerations, or emerging AI regulatory requirements preferred - Experience supporting audits (internal or external), including evidence collection and auditor interaction - Strong documentation skills; ability to produce clear, structured policies, procedures, and governance documentation - Ability to interpret technical and regulatory requirements and translate them into operational tasks and controls - Comfortable working cross-functionally with technical, security, and operational teams - Detail-oriented with strong organizational and follow-through capabilities Requirements - Experience in government, public sector, healthcare, or other regulated environments - Exposure to multiple frameworks or control mapping activities - Familiarity with compliance and security tools (e.g., Vanta, Drata, Wiz, Microsoft Purview, Defender, or similar platforms) - Experience supporting cloud security governance in Azure or AWS environments - Understanding of AI security, data governance, or vendor risk management practices related to AI-enabled solutions Benefits - Health care benefits and Insurance benefits (e.g., vision, dental, life, disability) - Retirement benefits (e.g., 401(k)) - Paid time off - 11 Paid holidays

United States
Orlando Health logo

Epic Security Analyst I

Orlando Health

Orlando Health is a nonprofit healthcare provider with a network of facilities throughout Orlando, Florida. The provider’s network of facilities consists of specialty hospitals f

Role Description Under the direction of the Manager, Identity Access Management and in support of the Chief Information Security Officer (CISO) and Orlando Health organizational business units, the Epic Security Analyst I provides consultation and guidance to the development, internal application and technical teams, and the third-party Epic EMP/SER provisioning vendor to maintain optimal protocols for granting and revoking appropriate end-user access for supported applications. The Epic Security Analyst I is responsible for the administration and coordination of all tasks related to SER, security tools, and policies and processes for Epic. This position provides outstanding client service and must be very knowledgeable about policies, procedures, and business operations. Responsibilities - Establishes Epic security protocols, in consultation with appropriate organizational stakeholders, and maintains the security of the Epic application. - Understands the foundational structures of Epic software, including profiles, roles, menus, and security classes, as well as network and device security relating to Epic and Epic end users. - Performs daily Epic security administration functions, including managing customer access requests, creating and/or deleting user profiles and accounts, maintaining appropriate documentation, and monitoring and auditing access logs. - Performs provider import/build as needed and cross-references user lists. - Works with Epic application teams to design system-level access, such as logout times, and leads decisions related to ownership and change delegation guidelines. - Takes ownership of process improvement in Epic Security provisioning, monitoring, and auditing. - Provides day-to-day troubleshooting, analysis, and resolution related to provider record issues. - Works with Epic project representatives to complete design, build, and test tasks in accordance with the project plan. - Identifies issues that arise within security and provider configuration, as well as issues that affect other application teams, and works to reach resolution. - Builds and maintains the Knowledge Base and any other Epic Security related processes, procedures, and policies. - Identifies and implements requested changes to the system. - Maintains effective communication with the Information Services Security Risk and Compliance Team and understands business needs and security concerns and communicates effectively with management. - Coordinates with the Epic Hosting Team and supports technical teams. - Takes the lead on implementation, including but not limited to presentations, Q&As, policies, and coordination of training. - Maintains regular communication with Epic representatives, including participation in weekly project team meetings. - Analyzes, interprets, and presents audit findings in clear, concise reports. - Maintains reasonably regular, punctual attendance consistent with Orlando Health policies, the ADA, FMLA and other federal, state and local standards. - Maintains compliance with all Orlando Health policies and procedures. Qualifications - Associate’s degree from a 2-year college or university. Requirements - Preferred: Security 101-Epic Fundamentals Certification - Preferred: Security 200-Epic Security Administration Certification - Preferred: IT Security industry certification (i.e., Security+, A+, CCNA) - Preferred: Certified Identity and Access Manager (CIAM) - Preferred: Certified Identity Management Professional (CIMP) - Preferred: Microsoft Identity and Access Administrator Associate - Two (2) years of information technology experience. - Two (2) years of customer support experience. Benefits - All Inclusive Benefits (start day one) - Student loan repayment, tuition reimbursement, FREE college education programs, retirement savings, paid paternity leave, fertility benefits, back up elder and childcare, pet insurance, PTO/Holidays, and more for full time and part time employees. - Forbes Recognizes Orlando Health as a Best-In-State Employer - Employee-centric: Orlando Health has been selected as one of the “Best Places to Work in Healthcare” by Modern Healthcare.

United States
Job Closed