Senior Security Analyst

CoLab

Washington (District of Columbia)

On-site

USD 120,000 - 190,000

Full time

27 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Stock options
Comprehensive health benefits
Unlimited paid vacation
401K matching
Remote work from anywhere in the USA

Job summary

CoLab in the United States is seeking a Senior Security Analyst to help shape and mature our enterprise security program. You will protect CoLab's AWS‑based cloud infrastructure, corporate systems, and customer data, while leading detection, investigation, and response efforts.

You will design and refine security controls, develop monitoring rules, coordinate incident response, and work with Technology and Product teams to implement secure solutions.

Qualifications

  • 5+ years in security operations or related cybersecurity role.
  • US Citizenship, living on US soil.
  • Experience with security monitoring, incident response, threat detection, and forensics.
  • Cloud and on‑premises security knowledge; AWS architecture and services.

Responsibilities

  • Lead investigation and response activities for security incidents and threats.
  • Design, implement, and improve security monitoring and detection across our AWS environment.
  • Develop and maintain detection rules, alerting strategies, and incident procedures.
  • Conduct post‑incident reviews to identify root causes and preventative measures.
  • Collaborate with Technology and Product teams to design secure solutions.
  • Support FedRAMP, SOC 2, and ISO 27001 compliance efforts and evidence gathering.

Skills

Security operations
Security engineering
Incident response
Threat detection
Forensic investigations
Cloud security
AWS security
Log analysis
Security procedures
FedRAMP
SOC 2
ISO 27001
GDPR
Communication

Tools

AWS

Job description

About CoLab

At CoLab, we help mechanical engineering teams bring life-changing products to market years sooner.

CoLab is the AI platform for driving stronger engineering decisions. Every design review in CoLab builds a knowledge repository of design feedback, decisions, and lessons learned - which AI agents draw from to flag issues on future designs before they compound. The more your team works in CoLab, the smarter it gets and the faster you arrive at the ideal design. Companies like Ford, Komatsu, and Johnson Controls use CoLab to catch issues earlier, eliminate rework cycles, and bring products to market faster.

Founded in St. John's, Newfoundland, CoLab has grown quickly from our first customer in 2019 to a rapidly scaling company. We've recently been recognized on Deloitte's Fast 50™ and Fast 500™, and named a Canadian company to watch by The Globe and Mail and Financial Post.

About the Role

Security at CoLab isn't a compliance exercise. It's a core part of earning and maintaining the trust of some of the world's largest engineering organizations.

As a Senior Security Analyst, you'll help shape the future of our enterprise security program. You'll be a key member of our Blue Team, responsible for protecting CoLab's cloud infrastructure, corporate systems, and customer data while continuously improving how we detect, investigate, and respond to threats.

This is a hands-on technical role reporting to our VP Enterprise Security. You'll spend time investigating alerts, leading incident response efforts, refining detection capabilities, improving security controls, and helping teams make sound security decisions before problems emerge.

You won't be handed a mature playbook and asked to follow it. You'll help build it. If you enjoy solving complex security problems, taking ownership, and balancing strong technical judgment with practical business decisions, you'll likely find this role rewarding.

Our Ideal Candidate

You're the type of person who sees an alert and is compelled to understand the full story—not just close the ticket.

You can move comfortably between technical investigation, risk discussions, and stakeholder communication. During an incident, you're calm, methodical, and focused on facts. Afterward, you're just as interested in improving systems and processes to prevent it from happening again.

You’ll thrive here if you enjoy:

  • Solving difficult security problems with incomplete information
  • Taking ownership of outcomes, not just tasks
  • Learning continuously as technologies and threats evolve
  • Working closely with Security, Technology, and Product teams and stakeholders
  • Balancing strong security practices with business realities
Job Responsibilities
  • Lead and support investigation and response activities for security incidents, suspicious activity, and emerging threats
  • Design, implement, and improve security monitoring, detection, and response capabilities across our AWS environment
  • Develop and maintain effective detection rules, alerting strategies, and investigation procedures
  • Conduct post-incident reviews to identify root causes, lessons learned, and preventative measures
  • Identify security exposures, vulnerabilities, misconfigurations, and non‑compliance risks and communicate recommendations clearly
  • Perform security assessments of third‑party vendors, services, and technologies
  • Partner with Technology and Product teams to design secure solutions and strengthen existing controls
  • Support Compliance initiatives by providing evidence and supporting material
  • Support vulnerability management, threat modeling, and endpoint security initiatives
  • Create and maintain security documentation, standards, and operational procedures
  • Contribute to security awareness efforts and provide guidance on secure business practices
  • Stay current on evolving threats, attacker techniques, and defensive technologies
  • Authorize/approve user access to CoLab
  • Coordinate with relevant CoLab AI teams for program functions wholly or partially implemented at the corporate level (i.e., general security training)
  • Develop and maintain an accurate and up‑to‑date System Security Plan (SSP)Package for the FedRAMP‑designated system
  • Distribute copies of SSP Package elements to relevant team members, on a need‑to‑know basis
  • Designate key personnel as responsible for core program functions (i.e., incident handling, disaster recovery, etc.)
  • Receive operational alerts, updates, and status reports from team members and critical system components
  • Oversee the Continuous Monitoring Program for CoLab in US jurisdictions
  • Report the security and privacy state of CoLab to external entities (i.e., Customer Agencies, FedRAMP Program Management Office (PMO), Third Party Assessment Organizations (3PAOs))
Qualifications
Required
  • 5+ years of experience in security operations, security engineering, or a similar cybersecurity role
  • US Citizenship, living on US soil
  • Strong experience with security monitoring, incident response, threat detection, and forensic investigations
  • Deep understanding of network security, application security, infrastructure hardening, and vulnerability management
  • Experience deploying, managing, and automating security solutions in cloud environments
  • Strong knowledge of AWS architecture, security services, and cloud security best practices
  • Experience working with macOS, Linux, and Windows environments
  • Strong understanding of log collection, analysis, and security event investigation
  • Experience developing and maintaining security procedures and operational processes
  • Ability to communicate technical risks and recommendations clearly to both technical and non‑technical audiences
  • Proven experience supporting FedRAMP certification including ConMon activities, preferably Class D (High) or Class C (Moderate)
  • Experience supporting compliance initiatives such as SOC 2, ISO 27001, GDPR, or other relevant frameworks
Nice to Have
  • Experience with threat modeling programs
  • Experience building security automation workflows
  • Experience assessing third‑party vendors and SaaS platforms
  • Security certifications such as CISSP, GCIH, GSEC, Security+, AWS Certified Security – Specialty, or AWS Certified Solutions Architect
The Extra Details
  • This is a full‑time, permanent position with a competitive compensation package that includes stock options
  • Comprehensive health and benefits coverage
  • Unlimited paid vacation
  • 401K matching
  • This role can be performed remotely from anywhere in the United States of America
Equity Note

Frequently cited statistics show that people who identify with historically marginalized groups are likely to apply to jobs only if they meet 100% of the qualifications. We encourage you to help us break that statistic and apply even if you don't meet every single qualification—your potential is what matters most to us.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Analyst
Senior Security Analyst

colabsoftware • United States

On-site
USD 110,000 - 140,000
Senior Security Engineer
Senior Security Engineer

Cohere • New York (NY)

Hybrid
USD 130,000 - 180,000
Weekly lunch stipend
Health and dental benefits
RRSP matching / Pension scheme
+4
Manager, Security Engineering
Manager, Security Engineering

Cohere • United States

On-site
USD 120,000 - 160,000
Inclusive culture
Weekly lunch stipend
Full health and dental benefits
+2
Manager, Security Engineering
Manager, Security Engineering

Visa Hunt • United States

On-site
CAD 320,000 - 385,000
Weekly lunch stipend
Health and dental benefits
RRSP matching
+5
Senior Security Engineer
Senior Security Engineer

Jaide Health • San Francisco (CA)

On-site
USD 120,000 - 160,000
Inclusive culture
Weekly lunch stipend
Full health and dental benefits
+4
Strategic Account Director
Strategic Account Director

Visa Hunt • United States

On-site
USD 140,000 - 180,000
Gitlab: Staff Product Security Architect
Gitlab: Staff Product Security Architect

CloudDevs • Northern (KY)

Hybrid
USD 140,000 - 260,000
Cybersecurity Engineer (DevSecOps)
Cybersecurity Engineer (DevSecOps)

Arcfield • Home Creek (VA)

On-site
USD 120,000 - 170,000
Health Insurance
Life Insurance
Paid Time Off
+6
Security Engineer - Corporate Security (Senior)
Security Engineer - Corporate Security (Senior)

Cogent • All (MO)

On-site
USD 100,000 - 300,000
Senior Security Assurance Engineer
Senior Security Assurance Engineer

GitLab Inc. • Northern (KY)

Hybrid
USD 140,000 - 210,000