Senior Security Analyst

Performance Contracting, Inc. (PCI)

Lenexa (KS)

On-site

USD 95,000 - 110,000

Full time

13 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Competitive pay
Incentive bonus plan
ESOP
401(k) with match
Medical insurance
Dental & Vision insurance
Life insurance
AD&D

Job summary

Performance Contracting Group is seeking a Senior Security Analyst in Lenexa, KS, to lead security monitoring, incident response, and threat analysis across multi-domain environments. You will mentor peers and partner with Security Operations, Engineering, GRC, Privacy, Legal, and IT teams to strengthen the organization’s security posture.

The role emphasizes AI security and emerging technologies, requires 5+ years in cybersecurity, and offers a competitive package with comprehensive benefits.

Qualifications

  • Bachelor's degree or certifications in information security or related field; equivalent experience ok.
  • Five+ years of progressive cybersecurity experience including monitoring, IR, investigations, vulnerability analysis.
  • Knowledge of SIEM, EDR/XDR, cloud and network security concepts; strong analytical skills.

Responsibilities

  • Monitor security across SIEM, endpoint, email, identity, network, cloud, and applications.
  • Triage alerts, investigate incidents, determine business impact and respond accordingly.
  • Lead threat hunting, analyze threat intel, and update detection use cases and escalation criteria.
  • Provide senior-level analysis for complex security events and mentor junior analysts.
  • Maintain and improve incident response playbooks, runbooks, and lessons learned.
  • Collaborate with Security Operations, GRC, Privacy, Legal, IT, and business stakeholders.

Skills

Analytical thinking
Problem solving
Organizational skills
Written communication
Interpersonal skills
Independent & collaborative

Education

Bachelor's degree in information security / cybersecurity / CS / IT

Tools

SIEM
EDR/XDR
Email security
Identity security
Vulnerability management
Network security
Cloud security
Application security
Case-management systems

Job description

Company Overview

Performance Contracting Group is a national employee-owned specialty contractor that offers quality services and products to the commercial, industrial, and non-residential construction markets. We are committed to recruiting, developing, and advancing employees from a diversity of backgrounds and experiences, as well as supporting a culture of safety and inclusiveness that allows you to contribute to your fullest potential. We place high value on training and professional development, encouraging you to broaden and strengthen your unique skill sets so you can fully realize your potential.

Senior Security Analyst

The Senior Security Analyst is a senior individual contributor responsible for security monitoring, threat analysis, incident response, vulnerability and exposure management, security assessments, and continuous improvement of operational security practices. The role provides advanced analytical support for complex security events, evaluates technical risk, recommends practical controls, and helps improve the organization’s overall security posture.

In addition to broad Senior Security Analyst responsibilities, this position serves as a security subject matter resource for artificial intelligence, automation, citizen-developed applications, and other emerging technologies. AI security is an area of emphasis within the role, not its exclusive function. The position partners closely with Security Operations, Security Engineering, GRC, Data Governance, Privacy, Legal, IT Operations, application owners, platform teams, and business stakeholders.

Essential Functions
Security Monitoring and Threat Analysis
  • Perform advanced security monitoring and analysis across SIEM, endpoint, email, identity, network, cloud, application, and other security data sources.
  • Triage and investigate alerts, correlate activity across multiple platforms, determine business impact, and recommend appropriate response actions.
  • Conduct proactive threat hunting, review relevant threat intelligence, and identify emerging threats that may affect the organization.
  • Improve detection use cases, alert logic, triage guidance, escalation criteria, and analyst investigation procedures.
  • Provide senior-level analytical support for complex security events and mentor analysts through technical review and knowledge sharing.
Incident Response and Investigations
  • Identify, investigate, contain, and support recovery from cybersecurity incidents in coordination with Security Operations and business partners.
  • Analyze suspected unauthorized access, malware, phishing, account compromise, data exposure, policy violations, and other security events.
  • Collect and preserve relevant evidence, document investigative findings, assess impact, and communicate recommended actions clearly.
  • Maintain and improve incident response procedures, investigation playbooks, escalation paths, and lessons-learned activities.
  • Participate in tabletop exercises and readiness activities that strengthen organizational response capabilities.
Vulnerability, Exposure, and Security Control Analysis
  • Analyze vulnerabilities and security exposures, validate findings, assess applicability and risk, and coordinate remediation with system owners.
  • Review technical designs, configurations, authentication and authorization models, network paths, APIs, secrets management, logging, and security controls.
  • Perform or coordinate security assessments, threat modeling, control validation, abuse-case analysis, and technical risk reviews.
  • Track findings through remediation, verification, exception, or formal risk acceptance using established processes.
  • Evaluate new security products and technologies and recommend improvements to security controls, tooling, and operational practices.
AI and Emerging Technology Security
  • Assess AI platforms, generative AI tools, agents, copilots, machine learning solutions, automation, low-code applications, and citizen-developed technology as part of the broader security review function.
  • Evaluate risks involving prompts, model outputs, knowledge sources, connectors, retrieval methods, data flows, third-party processing, retention, identity, and access.
  • Analyze AI-specific threats such as prompt injection, data leakage, insecure output handling, excessive agency, unsafe tool use, unauthorized retrieval, and supply-chain compromise.
  • Provide practical security guidance and reusable control patterns for proof-of-concept, pilot, and production use of AI-enabled solutions.
  • Monitor relevant AI security research, standards, threat activity, and vendor capabilities and translate developments into appropriate security recommendations.
Security Advisory, Process Improvement, and Collaboration
  • Provide practical security guidance to IT teams, application owners, platform engineers, citizen developers, vendors, and business stakeholders.
  • Develop and maintain security procedures, review checklists, control requirements, knowledge articles, and repeatable assessment practices.
  • Identify automation and process improvement opportunities that increase consistency, reduce manual effort, and improve response quality.
  • Prepare clear reports, metrics, dashboards, and executive-ready summaries describing security risks, findings, trends, and remediation progress.
  • Partner with Security Engineering, GRC, Data Governance, Privacy, Legal, Procurement, and Vendor Risk Management to support coordinated security outcomes.

Salary range: $95,000-$110,000 annual salary plus non-guaranteed annualized bonus program.

Minimum Requirements
  • Bachelor's degree and/or certifications in information security, cybersecurity, computer science, information technology, or a related field, or equivalent practical experience.
  • Five or more years of progressive experience in cybersecurity, including security monitoring, incident response, investigations, vulnerability analysis, application security, cloud security, or technical risk assessment.
  • Experience performing security investigations, security assessments, threat modeling, vulnerability analysis, or security architecture reviews.
  • Working knowledge of SIEM, EDR/XDR, email security, identity security, vulnerability management, network security, cloud security, application security, and case-management technologies.
  • Foundational knowledge of generative AI, AI-enabled applications, APIs, automation, cloud services, identity and access management, and data security principles.
  • Ability to analyze complex technical activity and designs, identify realistic attack or abuse scenarios, and translate findings into clear business impact and actionable requirements.
  • Strong analytical, problem-solving, organizational, written communication, and interpersonal skills.
  • Ability to work independently and collaboratively across technical teams, business functions, leadership levels, and third-party providers.
  • High level of integrity, sound judgment, attention to detail, and professionalism.
Preferred Requirements
  • Hands-on experience with security monitoring, incident response, threat hunting, vulnerability management, application security testing, API security, or cloud security.
  • Experience assessing or securing generative AI platforms, AI agents, copilots, retrieval-augmented generation solutions, low- code applications, or citizen-developed technology.
  • Experience with Microsoft-focused enterprise environments, including Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Cloud, Microsoft Entra ID, Azure AI services, Microsoft Copilot, or Microsoft Power Platform.
  • Knowledge of common cybersecurity frameworks and guidance, including NIST Cybersecurity Framework, MITRE ATTCCK, CIS Controls, the NIST AI Risk Management Framework, OWASP guidance for large language model applications, or MITRE ATLAS.
  • Experience supporting vendor risk reviews, privacy assessments, data governance, security exceptions, or technology approval processes.
  • Relevant professional certification such as CISSP, CSSLP, CCSP, CISM, CySA+, Security+, GIAC certification, or a comparable cloud or security credential.
  • Experience supporting a geographically distributed organization with a mix of corporate, field, cloud, SaaS, and on-premises technology environments.
Benefits

At Performance Contracting, our employees are our greatest asset. We put our people first and are proud to provide a comprehensive benefits package designed to meet the needs of our employees at every stage of life.

In our commitment to fostering an environment where everyone can thrive personally and professionally, we offer:

  • Competitive pay
  • Incentive bonus plan
  • Employee stock ownership plan (ESOP)
  • 401(k) retirement savings plan with match
  • Medical, prescription drug, dental, and vision insurance plans with flexible spending account option
  • Life insurance, AD&D, and disability benefits
  • Employee assistance program (EAP)
  • Flexible paid time off policy and paid holidays

PCG provides equal employment and affirmative action opportunities to applicants and employees without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability.

PCG is a background screening, drug-free workplace. In accordance with the provisions of Tennessee Code Annotated (T.C.A.), Title 50, Chapter 9, PCG’s Drug-Free Workplace Program includes drug and alcohol testing as part of the hiring process and throughout employment, as applicable.

Please note this job description is not designed to contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Analyst
Senior Security Analyst

Performance Contracting Group • Lackmans (KS)

On-site
USD 95,000 - 110,000
Competitive pay
Incentive bonus plan
ESOP
+2
HR Generalist
HR Generalist

Performance Contracting Group • Lackmans (KS)

On-site
USD 56,000 - 77,000
Security Analyst 1
Security Analyst 1

Construction Partners, Inc. • Dothan (AL)

On-site
USD 52,000 - 76,000
Medical, Dental, Vision coverage
401(k) with employer match
Paid vacation and holidays
+3
Security Analyst
Security Analyst

AGS LLC • Atlanta (GA)

On-site
USD 70,000 - 100,000
Director, IT Engineering
Director, IT Engineering

Performance Contracting Group • Lackmans (KS)

On-site
USD 150,000 - 190,000
Competitive pay
Incentive bonus plan
Employee stock ownership plan (ESOP)
+5
Safety Administrator
Safety Administrator

Performance Contracting, Inc. • Zionsville (IN)

On-site
USD 71,635,000 - 82,656,000
401(k) Retirement Plan
Medical, dental, vision insurance
Life insurance & AD&D
+2
Security Analyst
Security Analyst

AGS LLC • Duluth (GA)

On-site
USD 70,000 - 100,000
Senior Cybersecurity GRC Engineer
Senior Cybersecurity GRC Engineer

Rippling, Inc. • Denver (CO)

On-site
USD 135,000 - 169,000
Medical coverage
401(k) plan
Life insurance
+1
Director, Cyber Defense
Director, Cyber Defense

Genuine Parts Company • Atlanta (GA)

On-site
USD 180,000 - 260,000
HR Generalist
HR Generalist

Performance Contracting, Inc. (PCI) • Lenexa (KS)

On-site
USD 56,000 - 77,000
Competitive pay
Incentive bonus
ESOP
+7