
Senior Staff Security Analyst
Posted Jun 24

Posted Jun 24
This is a fully remote position, open to applicants in California, +2 more states.
⢠Engage in AI-assisted security operations by utilizing AI tools (such as Claude, copilots, and emerging agentic platforms) to enhance various aspects of the roleāspeeding up triage and investigation, drafting and refining detections, summarizing alerts and incidents, automating repetitive analyst tasks, and improving key metrics (MTTD, MTTR, dwell time, analyst throughput). Establish standards for the responsible use of AI within a PHI environment.
⢠Conduct threat hunting by developing and executing hypothesis-driven searches across endpoints, cloud workloads, identity, and SaaS. Convert hunt findings into sustainable detections. Leverage AI and automation to transform Threat Hunting into an effective and proactive tool.
⢠Oversee vulnerability management by driving the vulnerability lifecycle, which includes discovery, prioritization (based on risk rather than solely on CVSS), remediation tracking, and reporting. Collaborate with engineering teams to promptly address real risks.
⢠Manage attack surface visibility to ensure awareness of our external and internal attack surfaces across cloud, SaaS, third parties, and acquired entities. Identify exposures before they are exploited.
⢠Support incident response and digital forensics by assisting the Lead Incident Responder with investigations and security incidents, from triage through containment, eradication, recovery, and post-incident review. Conduct host, network, cloud, and memory forensics, and help with incident response playbooks and the evidence chain.
⢠Perform fraud assessments by conducting in-depth analyses on the origins of digital fraud. From payment card fraud to cyber-initiated fraud, gain insights into the mechanisms and motivations behind digital fraud.
⢠Foster cross-functional partnerships by collaborating directly with Engineering, IT, Operations, and Compliance. Translate security findings into clear action items with defined next steps. Focus on solving problems rather than assigning blame.
⢠Address healthcare-specific risks by implementing controls suitable for a HIPAA-regulated, PHI-handling environment. Assist in maintaining purposeful speed without compromising critical elements.
⢠10ā12 years of progressive experience in security operations, with extensive hands-on expertise in all areas including digital forensics, incident response, vulnerability management, attack surface management, threat hunting, and security analytics.
⢠Proven track record of owning major security incidents from start to finishāyou have acted as the technical lead, not merely a participant.
⢠Familiarity with cloud security, endpoint detection and response, SIEM platforms, identity providers, and modern attacker tradecraft (MITRE ATT&CK fluency is expected).
⢠Experience in detection engineeringācapable of writing, tuning, and retiring detections, and justifying your decisions with data.
⢠Proficiency in scripting and automation (Python, PowerShell, or similar)āenough to create necessary solutions independently rather than relying on others.
⢠Hands-on experience with AI tools (Claude, ChatGPT, GitHub Copilot, or equivalent) as part of daily security operationsānot just theoretical involvement. Be prepared to provide specific examples of how AI has enhanced your throughput, detection quality, or time-to-resolution.
⢠A clear perspective on AI safety and data handlingāespecially regarding what information is appropriate to send to which tools when dealing with PHI, credentials, or sensitive telemetry.
⢠Excellent written and verbal communication skills, enabling you to brief an engineer, a clinician, and an executive on the same incident, ensuring all three parties leave with the necessary understanding.
⢠Strongly preferred: Experience in healthcare, fintech, or other regulated fields with sensitive data handling requirements.
⢠Strongly preferred: Familiarity with HIPAA, HITRUST, or SOC 2 from the operational sideābeyond just the audit perspective.
⢠Strongly preferred: Relevant industry certifications such as GCFA, GCIH, GNFA, GCTI, OSCP, or equivalent demonstrated expertise.
⢠Strongly preferred: Experience in supporting M&A security integration or working in multi-entity environments (we operate across several subsidiaries).
⢠Strongly preferred: Experience in developing AI-assisted workflows or automations for security operations (including custom prompts, agentic workflows, and integrations with SIEM/EDR/ticketing systems).
⢠Strongly preferred: Familiarity with prompt engineering, retrieval-augmented patterns, or building internal tools using LLM APIs.
⢠Medical, Dental, and Vision plans
⢠Flexible Spending/Health Savings Accounts
⢠Flexible PTO
⢠401(k) + Company Match
⢠Life Insurance, Pet insurance, and more
Cresol Cooperativa
LTS
Equity Resources, Inc
IronArch Technology
Get handpicked remote jobs straight to your inbox weekly.