Senior Cybersecurity Analyst

Remote
Full time
About the project
They are a private equity-backed technology company focused on maximizing distribution and revenue for live event ticket inventory. Their end-to-end software platform supports the live ticketing industry by managing large volumes of tickets for sports, theater, and live music events on behalf of artists, promoters, sports teams, venues, and professional resellers. Their product suite includes an established B2B marketplace, a full-service solution, and an automated SaaS platform that streamlines the entire ticket sales lifecycle—from inventory ingestion and pricing to distribution, sales, and fulfillment.
About the role
As a Senior Cybersecurity Analyst, you will play a key role in protecting the organization's cloud and on-premises infrastructure. You will be responsible for monitoring, detecting, analyzing, and responding to cybersecurity threats and vulnerabilities across AWS, Azure, and on-premises environments using modern security tools and platforms. This role requires strong expertise in vulnerability management, threat detection, incident response, application and code security, and cloud security. You will collaborate closely with IT teams, security specialists, and cross-functional stakeholders to strengthen the organization's security posture and help defend against an evolving threat landscape.
Key Responsibilities

Threat Detection & Response:

  • Monitor security tools (e.g., CrowdStrike, Uptycs) for potential threats, malware, and other malicious activities.
  • Investigate security incidents and respond to detected threats using endpoint detection and response (EDR) tools such as CrowdStrike.
  • Collaborate with incident response teams to mitigate threats and vulnerabilities promptly
  • Participation in on-call rotation

Cloud Security:

  • Manage and monitor cloud infrastructure security in AWS and Azure environments.
  • Implement and maintain security controls across cloud platforms, ensuring compliance with organizational policies.
  • Monitor cloud environments for anomalies, misconfigurations, and threats

Email Security:

  • Manage and optimize email security systems, specifically Proofpoint, to detect and block phishing, spam, and email-based threats.
  • Respond to email security alerts and perform in-depth investigations on suspicious email / user activities.

Vulnerability Management & Scanning:

  • Perform vulnerability scanning using appropriate tools, identify security vulnerabilities in systems, and assist in remediation efforts.
  • Track and report on vulnerability management processes and ensure that vulnerabilities are mitigated or patched according to the organization’s security policies.
  • Conduct regular penetration testing to assess the security of applications and networks.

Security Monitoring & Analysis:

  • Use SIEM (Security Information and Event Management) systems to analyze security events, logs, and alerts.
  • Correlating threat intelligence feeds internal data to detect advanced threats.
  • Perform regular analysis and reporting on security incidents, including root cause analysis.
  • Build actionable runbooks, dashboards, secure integrations across multiple tools

Compliance & Risk Management:

  • Ensure compliance with industry standards and frameworks such as ISO 27001, NIST, SOC 2, and other applicable regulations.
  • Assist in audits and ensure that security policies and procedures are followed.
  • Conduct risk assessments to evaluate the organization’s exposure to cybersecurity risks.
  • Engage in Third Party Risk management, Supply Chain Attacks and Risks

Security Best Practices & Training:

  • Assist in developing and maintaining security policies, procedures, and best practices.
  • Provide security awareness training to employees, focusing on phishing, malware detection, and cloud security practices.

Security Automation Tools-Stack:

  • ProofPoint DLP
  • CrowdStrike XDR / NGSIEM
  • Uptycs CNAPP / XDR
  • Obsidian Security SSPM
  • Nord Security / Dark Web Threat Intelligencer
  • Cloudflare WAF
  • Claude Code / GitHub-Copilot
  • MCP
  • Visual Studio Code
Requirements

Experience & Education

  • Bachelor’s degree in computer science, Information Security, or a related field (or equivalent work experience).
  • Relevant security certifications such as OSCP, CEH, CISA, CSP, CCSP, CompTIA Security+, or equivalent are highly preferred.
  • 8+ years of “hands on” experience in cybersecurity or security operations.
  • Strong understanding of OSINT, OTX, MITTRE, IOAs, IOCs, OWASP, API security and Secure SDLC
  • Proven experience in working with security tools (Proofpoint, CrowdStrike, AWS/Azure security tools, Uptycs, Wiz, Obsidian Security SSPM, or similar technologies).
  • Ability to utilize offensive sec-tools: Kali/Metasploit/Burp/NMAP (or similar)
  • Technical understanding of Red team, Blue Team, and Purple Team functions
  • Strong knowledge of Zero trust framework, Identity management, Privileged access management
  • Strong knowledge of data loss protection, data encryption and data governance methodologies (including PKI management)
  • Strong knowledge of cloud security frameworks, vulnerability management, and incident response.
  • Experience with regulatory compliance and security frameworks (e.g., NIST, SOC 2, ISO 27001).
  • Knowledge of networking, operating systems (Linux, Windows), and security protocols.
  • Experience in cloud infrastructure (Well Architected Framework) security for AWS and Azure environments.
  • Strong scripting languages (e.g., Python, PowerShell, Git) is a plus.
  • Technical understanding of CICD and DevOps/SecOps frameworks
  • Excellent communication skills, with the ability to work across teams and explain security issues to non-technical stakeholders.

What We Offer
  • Physical activity covered by the company to promote a healthy lifestyle
  • English classes to support your professional growth
  • Sponsored training and learning opportunities
  • Paid Time Off (PTO) for rest, balance, and recharging
  • Your birthday off to celebrate your day