Skip to content

Open nowPosted 26 hours ago

Senior Security Analyst

PCG178 open roles

Where
Lenexa, KS, USA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Security AnalystPCG · Lenexa, KS, USA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on PCG's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.2%30 days
This job: posted 26 hours ago

The posting

The Senior Security Analyst is a senior individual contributor responsible for security monitoring, threat analysis, incident response, vulnerability and exposure management, security assessments, and continuous improvement of operational security practices. The role provides advanced analytical support for complex security events, evaluates technical risk, recommends practical controls, and helps improve the organization’s overall security posture. In addition to broad Senior Security Analyst responsibilities, this position serves as a security subject matter resource for artificial intelligence, automation, citizen-developed applications, and other emerging technologies. AI security is an area of emphasis within the role, not its exclusive function. The position partners closely with Security Operations, Security Engineering, GRC, Data Governance, Privacy, Legal, IT Operations, application owners, platform teams, and business stakeholders. Essential Functions Security Monitoring and Threat Analysis

Perform advanced security monitoring and analysis across SIEM, endpoint, email, identity, network, cloud, application, and other security data sources. Triage and investigate alerts, correlate activity across multiple platforms, determine business impact, and recommend appropriate response actions. Conduct proactive threat hunting, review relevant threat intelligence, and identify emerging threats that may affect the organization. Improve detection use cases, alert logic, triage guidance, escalation criteria, and analyst investigation procedures. Provide senior-level analytical support for complex security events and mentor analysts through technical review and knowledge sharing.

Incident Response and Investigations

Identify, investigate, contain, and support recovery from cybersecurity incidents in coordination with Security Operations and business partners. Analyze suspected unauthorized access, malware, phishing, account compromise, data exposure, policy violations, and other security events. Collect and preserve relevant evidence, document investigative findings, assess impact, and communicate recommended actions clearly. Maintain and improve incident response procedures, investigation playbooks, escalation paths, and lessons-learned activities. Participate in tabletop exercises and readiness activities that strengthen organizational response capabilities.

Vulnerability, Exposure, and Security Control Analysis

Analyze vulnerabilities and security exposures, validate findings, assess applicability and risk, and coordinate remediation with system owners. Review technical designs, configurations, authentication and authorization models, network paths, APIs, secrets management, logging, and security controls. Perform or coordinate security assessments, threat modeling, control validation, abuse-case analysis, and technical risk reviews. Track findings through remediation, verification, exception, or formal risk acceptance using established processes. Evaluate new security products and technologies and recommend improvements to security controls, tooling, and operational practices.

AI and Emerging Technology Security

Assess AI platforms, generative AI tools, agents, copilots, machine learning solutions, automation, low-code applications, and citizen-developed technology as part of the broader security review function. Evaluate risks involving prompts, model outputs, knowledge sources, connectors, retrieval methods, data flows, third-party processing, retention, identity, and access. Analyze AI-specific threats such as prompt injection, data leakage, insecure output handling, excessive agency, unsafe tool use, unauthorized retrieval, and supply-chain compromise. Provide practical security guidance and reusable control patterns for proof-of-concept, pilot, and production use of AI-enabled solutions. Monitor relevant AI security research, standards, threat activity, and vendor capabilities and translate developments into appropriate security recommendations. Security Advisory, Process Improvement, and Collaboration Provide practical security guidance to IT teams, application owners, platform engineers, citizen developers, vendors, and business stakeholders. Develop and maintain security procedures, review checklists, control requirements, knowledge articles, and repeatable assessment practices. Identify automation and process improvement opportunities that increase consistency, reduce manual effort, and improve response quality. Prepare clear reports, metrics, dashboards, and executive-ready summaries describing security risks, findings, trends, and remediation progress. Partner with Security Engineering, GRC, Data Governance, Privacy, Legal, Procurement, and Vendor Risk Management to support coordinated security outcomes.

  Salary range: $95,000-$110,000 annual salary plus non-guaranteed annualized bonus program.    Minimum Requirements

Bachelor's degree and/or certifications in information security, cybersecurity, computer science, information technology, or a related field, or equivalent practical experience. Five or more years of progressive experience in cybersecurity, including security monitoring, incident response, investigations, vulnerability analysis, application security, cloud security, or technical risk assessment. Experience performing security investigations, security assessments, threat modeling, vulnerability analysis, or security architecture reviews. Working knowledge of SIEM, EDR/XDR, email security, identity security, vulnerability management, network security, cloud security, application security, and case-management technologies. Foundational knowledge of generative AI, AI-enabled applications, APIs, automation, cloud services, identity and access management, and data security principles. Ability to analyze complex technical activity and designs, identify realistic attack or abuse scenarios, and translate findings into clear business impact and actionable requirements. Strong analytical, problem-solving, organizational, written communication, and interpersonal skills. Ability to work independently and collaboratively across technical teams, business functions, leadership levels, and third-party providers. High level of integrity, sound judgment, attention to detail, and professionalism.

Preferred Requirements

Hands-on experience with security monitoring, incident response, threat hunting, vulnerability management, application security testing, API security, or cloud security. Experience assessing or securing generative AI platforms, AI agents, copilots, retrieval-augmented generation solutions, low- code applications, or citizen-developed technology. Experience with Microsoft-focused enterprise environments, including Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Cloud, Microsoft Entra ID, Azure AI services, Microsoft Copilot, or Microsoft Power Platform. Knowledge of common cybersecurity frameworks and guidance, including NIST Cybersecurity Framework, MITRE ATTCCK, CIS Controls, the NIST AI Risk Management Framework, OWASP guidance for large language model applications, or MITRE ATLAS. Experience supporting vendor risk reviews, privacy assessments, data governance, security exceptions, or technology approval processes. Relevant professional certification such as CISSP, CSSLP, CCSP, CISM, CySA+, Security+, GIAC certification, or a comparable cloud or security credential. Experience supporting a geographically distributed organization with a mix of corporate, field, cloud, SaaS, and on-premises technology environments.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against PCG's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on PCG's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    PCG's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.