Senior Security Analyst

Blacksky Holdings LLC

Herndon (VA)

On-site

USD 80,000 - 90,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical, dental, vision
401(k) with matching
Paid time off
Parental leave

Job summary

BlackSky is seeking a Senior Security Analyst to monitor, defend, and secure our enterprise environment. You will analyze logs, perform DFIR, conduct threat hunting, and drive vulnerability remediation in collaboration with IT, product, and security teams.

The role can be based in Herndon, VA or Seattle, WA, with hybrid expectations and travel as needed. A US citizenship is required for ITAR/compliance.

Qualifications

  • At least seven (7) years of security analyst and DFIR experience.
  • Seven+ years in IT security.
  • Candidates should hold at least one listed security certification.
  • Must document processes, procedures, and results.

Responsibilities

  • Perform security monitoring and DFIR across environments by reviewing events/IOCs/IOAs and CTI.
  • Review multiple sources of CTI to inform and secure the enterprise.
  • Conduct regular threat hunting across environments.
  • Document procedures for job duties to formalize ad-hoc processes.
  • Analyze data from logs, network traffic, and SaaS security tools.
  • Perform malware analysis using standard sandbox tools.
  • Support continuous monitoring to identify security threats.
  • Assist vulnerability management with prioritization of critical issues.
  • Collaborate with product owners on remediation of vulnerabilities.

Skills

Security analysis
DFIR
Threat hunting
Incident response
Log analysis
Scripting

Education

Security certifications (CISSP, GCIH, CHFI, GCFE, GCFA, GREM, GNFA, GCSA, GCPN, GPCS, GSOC, GCDA, ACE, EnCE, AWS Certified Security - Specialty)

Tools

Cisco Duo
Nessus
OpenSCAP
CrowdStrike XDR/MDR
ManageEngine
Cisco Umbrella
Active Directory / Entra ID
Netskope

Job description

Senior Security Analyst

About Us:

BlackSky is a real-time intelligence company. We own and operate the world's most advanced space-based intelligence platform and provide customers satellite imagery, automated analytics and high-frequency monitoring of strategic locations, economic assets and events from around the globe. BlackSky is trusted by the most demanding allied military and intelligence organizations and commercial companies to deliver foresight into critical matters that affect national security and the economy. BlackSky's data enables governments and businesses to see, understand and anticipate change as it happens, giving them the ultimate strategic advantage so they can act quickly. Our global team works with cutting-edge technology to make a difference around the world and prides itself on being people-first, customer-focused and fun.

The Senior Security Analyst position reports to the Manager of Security Analysis Team (i.e., Security Operations Center (SOC)) with rollup to the Director of Security and plays a vital role in monitoring, defending, and securing the BlackSky enterprise environment against cyber threats.

You will perform continuous monitoring of network, managed devices and identities, cloud services, business systems, and application traffic in support of BlackSky's Security Operations Center (SOC). You will conduct analysis of these logs within an integrated Security Information and Event Management (SIEM) platform and work to develop novel searches, dashboards, and alerts to improve the SOC's detection and response timelines. You will leverage cyber threat intelligence (CTI) reporting in conjunction with internal digital forensics and incident response (DFIR) activities to ensure BlackSky is properly positioned to defend against security threats to our enterprise networks.

The Security Team is geographically distributed across our Herndon, VA and Seattle, WA offices therefore the role can be based at either of these two locations, surrounding areas, or anywhere in the United States.

Responsibilities:

  • Perform security monitoring and digital forensics and incident response (DFIR) activities across corporate, product, and mission environments by reviewing events and alerting attributed to indicators of compromise (IOCs), indicators of attack (IOAs), cyber threat intelligence (CTI) reporting, and non-compliance activities
  • Review multiple sources of cyber threat intelligence and apply the insights appropriately to inform and secure the enterprise
  • Conduct regular threat hunting across the corporate, product, and mission environments
  • Document procedures for performance of job duties to formalize ad-hoc processes
  • Conduct security analysis of data from many sources - system/event logs, network traffic, and SaaS security tools.
  • Perform analysis, and digital forensics of potential malware using Industry standard Sandbox tools.
  • Support continuous monitoring of network, operating system, and application log traffic to identify potential security threats related to the industry.
  • Support vulnerability management process through identification and prioritization of critical security concerns in collaboration with IT or Product owners to drive vulnerability or misconfiguration remediation activities.
  • Work with product owners to define offensive testing scope requirements and constraints and to support the remediation process on any identified vulnerabilities.
  • Monitor operational systems for continuous compliance with hardened baseline images against industry checklists such as CIS Benchmarks and/or DISA STIGs,
  • Develop solutions to automate reoccurring tasks and improve adversary detection.
  • Complete compliance assessments and report findings to management.
  • Document findings (anomalies, incidents, concerns) and share widely with security, IT, and product teams as appropriate to enable enhanced understanding of security posture.
  • Strong Linux security background with Ubuntu, Amazon Linux, and/or CentOS preferred.
  • Support security training and manage tabletop scenarios to other employees
  • Support SOX/ITGC, CMMC 2.0 Level 2, NIST 800-171 r3, UK Cyber Essentials, and customer-specific compliance requirements.
  • Other responsibilities as assigned.

Required Qualifications:

  • A minimum of seven (7) years' experience performing security analyst and DFIR activities.
  • A minimum of seven (7) years' experience in IT security.
  • Candidates should hold at least one of the following security certifications:
    • Certified Information Systems Security Professional (CISSP),
    • GIAC Certified Incident Handler (GCIH),
    • Computer Hacking Forensic Investigator (CHFI),
    • GIAC Certified Forensic Examiner (GCFE),
    • GIAC Certified Forensic Analyst (GCFA),
    • GIAC Reverse Engineering Malware (GREM),
    • GIAC Network Forensic Analyst (GNFA),
    • GIAC Cloud Security Automation (GCSA),
    • GIAC Cloud Penetration Tester (GCPN),
    • GIAC Public Cloud Security (GPCS),
    • GIAC Security Operations Certified (GSOC),
    • GIAC Certified Detection Analyst (GCDA),
    • Access Data Certified Examiner (ACE), and/or
    • Encase Certified Examiner (EnCE), AWS Certified Security - Specialty.
  • Ability to document processes, procedures, and results of technical analysis for review by peers.
  • Experience with implementing, troubleshooting, and sustaining endpoint security mechanisms (e.g., EDR, CASB, and others) in at least one of the following Operating Systems - Windows, MacOS, and/or Linux.
  • Experience performing at least one of the following activities - Incident Response, Digital Forensics, Malware Analysis, Network Traffic Collection, or Reverse Engineering.
  • Must be a U.S. Citizen.

Preferred Qualifications:

  • Endpoint Security for Windows, MacOS, and Linux environments.
  • Enterprise Security Tools: Cisco Duo, Nessus, OpenSCAP, Crowdstrike XDR/MDR, ManageEngine, Cisco Umbrella, Active Directory / Entra ID, Netskope.
  • Extensive incident response, security analysis, and digital forensics experience performing event log, PCAP, and NetFlow data analysis, malware analysis, and data collection.
  • Cloud Solutions: Microsoft GCC High, AWS Commercial, AWS GovCloud, VMware ESXi.
  • Infrastructure as Code: AWS CloudFormation, HashiCorp Terraform.
  • Coding & Scripting: Python, Java, JavaScript, BASH, PowerShell.
  • Knowledge of Secure DevOps Processes.
  • Container Technologies: Docker, ECS, Nomad, HashiCorp product stack.

Life at BlackSky for full-time US benefits eligible employees includes:

  • Medical, dental, vision, disability, group term life and AD&D, voluntary life and AD&D insurance
  • BlackSky pays 100% of employee-only premiums for medical, dental and vision and contributes $100/month for out-of-pocket expenses!
  • 15 days of PTO, 11 Company holidays, four Floating Holidays (pro-rated based on hire date), one day of paid volunteerism leave per year, parental leave and more
  • 401(k) pre-tax and Roth deferral options with employer match
  • Flexible Spending Accounts
  • Employee Stock Purchase Program
  • Employee Assistance and Travel Assistance Programs
  • Employer matching donations
  • Professional development
  • Mac or PC? Your choice!
  • Awesome swag

The anticipated base salary range for candidates in Seattle, WA and Herndon, VA is$80,000 - 90,000 per year. The final compensation package offered to a successful candidate will be dependent on specific background and education. BlackSky is a multi-state employer, and this pay scale may not reflect salary ranges in other states or locations outside of Seattle, WA.

BlackSky is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity Employer. All Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, sexual orientation, gender identity, disability, protected veteran status or any other characteristic protected by law.

To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.

EEO/Pay Transparency Statements:

https://www.dol.gov/ofccp/regs/compliance/posters/pdf/eeopost.pdf

https://www.dol.gov/ofccp/regs/compliance/posters/pdf/OFCCP_EEO_Supplement_Final_JRF_QA_508c.pdf

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Analyst
Senior Security Analyst

InvestedintheMission • Virginia (MN)

On-site
USD 80,000 - 90,000
Medical, dental, vision benefits
401(k) with employer match
Professional development
Senior Security Analyst
Senior Security Analyst

Telemetry Today LLC • Seattle (WA), Northern (KY)

Hybrid
USD 80,000 - 90,000
Medical benefits
401(k)
Paid time off
+1
Senior Security Analyst job at BlackSky in US National
Senior Security Analyst job at BlackSky in US National

BlackSky • United States

On-site
USD 80,000 - 90,000
Medical, dental, vision insurance
401(k) with company match
Paid time off and holidays
+1
Principal DevSecOps Architect
Principal DevSecOps Architect

BlackSky • United States

Hybrid
USD 190,000 - 215,000
Medical, dental, vision
401(k) plan
PTO and holidays
+2
Senior Security Analyst
Senior Security Analyst

Linuxconfig • Seattle (WA), Northern (KY)

Hybrid
USD 80,000 - 90,000
Medical, dental, vision
401(k) with match
Employee stock purchase program
+3
Principal DevSecOps Architect
Principal DevSecOps Architect

Blacksky Holdings LLC • United States

Hybrid
USD 190,000 - 215,000
Medical, dental, vision
401(k) match
Stock Purchase Program
+3
Principal DevSecOps Architect
Principal DevSecOps Architect

Telemetry Today LLC • Herndon (VA), Northern (KY)

Hybrid
USD 190,000 - 215,000
Medical, dental, vision
Premium employee premiums
PTO & holidays
+2
Senior Analytics Product Manager (Remote)
Senior Analytics Product Manager (Remote)

Blacksky Holdings LLC • United States

Remote
USD 145,000 - 165,000
Medical, dental, vision insurance
15 days of PTO
401(k) with employer match
+3
Senior Product Manager, Analytics
Senior Product Manager, Analytics

Blacksky Holdings LLC • United States

On-site
USD 145,000 - 165,000
Medical, dental, vision insurance
15 days of PTO
401(k) with employer match
+3
Senior Product Manager, Analytics
Senior Product Manager, Analytics

Blacksky Holdings LLC • Herndon (VA)

On-site
USD 145,000 - 165,000
Medical, dental, vision insurance
401(k) with employer match
15 days PTO and additional holidays
+1