Job Description
Security Analyst
As a Security Analyst, you will be part of our growing Security & Compliance team, building security automations, creating baselines for on-premises and cloud environments, assisting teams with vulnerability scans and management, supporting our compliance team with evidence gathering and audits, and more. This is an opportunity to be part of a small team with increasing importance and responsibility.
Primary Responsibilities
- Review and triage findings from vulnerability scans, penetration tests, and configuration assessments to identify potential security risks.
- Work with DevOps, engineers, and system owners to remediate vulnerabilities across multi-cloud and on-prem assets.
- Support secure configuration baselines for AWS, Azure, and Oracle Cloud resources.
- Monitor cloud environments for misconfigurations and suspicious activity.
- Assist with IAM policy reviews and privilege audits.
- Write scripts (Python, PowerShell, or Bash) to automate detection, reporting, or remediation of security issues.
- Integrate security tools and data into dashboards or workflow systems (e.g., Jira, SIEM, or ticketing).
- Provide technical evidence and control implementation support for SOC 2, ISO 27001, or customer security assessments.
- Partner with the compliance team to map technical controls to framework requirements.
- Assist with incident triage, response, and root cause analysis.
- Support endpoint protection, log monitoring, and threat intelligence initiatives.
Minimum Qualifications
- Bachelor's degree in a related field or equivalent related experience
- Minimum of two years of experience with security exposure in information security, systems administration, or DevOps.
- Proficient in at least one scripting language (Python, PowerShell, or Bash).
- Strong understanding of operating systems, networking, and cloud fundamentals.
- Knowledge of security frameworks such as NIST
- Familiarity with vulnerability management tools (e.g., Tenable, Qualys, Rapid7, AWS Inspector, or Microsoft Defender).
- Working knowledge of AWS, Azure, and/or Oracle Cloud security controls and services.
- Comfortable working cross-functionally with engineering, IT, and other teams as needed.
Knowledge, Skills, and Abilities
- Ability to travel up to 15% to assist in team building and planning exercises.
- Strong, professional communication skills, both verbal and written, including the skill in articulating and translating technical language to non-technical customers.
- Ability to plan for contingencies and anticipate problems.
- Ability to ask critical questions to assess needs and requirements
Preferred Qualifications
- Experience with SIEM or SOAR platforms (e.g., Splunk, Microsoft Sentinel).
- Familiarity with infrastructure such as code (Terraform, CloudFormation).
- Exposure to compliance frameworks such as SOC 2, ISO 27001, or NIST 800-53.
- Security certifications (Security+, GSEC, AWS Security Specialty, or similar).
- Endpoint Security/Patching/Inventory experience
Compensation Range
$175,000 - $200,000+
Equal Opportunity Statement: QuEra is an equal opportunity employer. We recruit, hire, and promote without regard to legally protected characteristics. Where project work requires access to controlled information or facilities, employment is contingent on the ability to obtain and maintain appropriate authorizations. All hiring complies with applicable federal and state laws.