Security Analyst III

🏢 staritas · all staritas jobs
📍 United States
💰 USD 110,000 - 125,000 / annual
📅 Posted 2026-08-09 · via Himalayas
🏷 Security-Analyst,Cybersecurity-Operations,SOC2-Compliance,Security-Operations,Infosec,Senior-Information-Security-Analyst,Senior-Security-Analyst
Apply on original site ↗
About the Role The Security Analyst III at Staritas is responsible for leading the organization’s security operations, governance, and compliance programs. This role serves as a key contributor to the design, implementation, and enforcement of security policies and standards, ensuring alignment with SOC 2 and other regulatory frameworks. The Security Analyst III owns the security monitoring ecosystem, including SIEM operations, leads enterprise-wide security awareness initiatives (e.g., KnowBe4), and manages audit readiness and control effectiveness. This position partners closely with IT Operations, leadership, and the Information Security Officer to proactively reduce risk, improve security posture, and ensure compliance. Essential Functions - Lead security monitoring and response operations leveraging SIEM and integrated security platforms; tune alerts, develop use cases, and drive continuous improvement in detection capabilities - Own SIEM platform management, including onboarding new log sources, correlation rule development, and integration with endpoint, cloud, and network security tools - Develop, implement, and enforce security policies, standards, and procedures aligned with SOC 2 and industry best practices - Lead incident response activities, including investigation, containment, root cause analysis, and documentation; coordinate with internal and external stakeholders as required - Manage vulnerability management program, including scanning, prioritization, remediation tracking, and reporting to leadership - Own and administer the security awareness program, including KnowBe4 rollout, phishing simulations, reporting, and targeted training campaigns - Serve as primary owner for SOC 2 compliance activities, including control documentation, evidence collection, audit coordination, and continuous control monitoring - Develop and maintain security documentation, including policies, procedures, runbooks, and audit artifacts - Partner with IT Operations to implement and enforce secure configurations, access controls, and endpoint protection strategies - Lead evaluation, selection, and implementation of new security technologies, including cost analysis and operational integration planning - Manage third-party security services and vendors (e.g., MDR/eSOCproviders) and ensure contractual and operational expectations are met - Oversee BYOD and endpoint security programs, including MDM enforcement and secure access policies - Support client and regulatory security inquiries, including RFP responses and due diligence requests - Stay current with evolving threat landscape, compliance requirements, and security best practices Additional Responsibilities: - Other duties, as assigned. Experience: - 7–10+ years of experience in cybersecurity, IT security operations, or related fields - Demonstrated experience with SIEM platforms (e.g., Microsoft Sentinel, SUMO, or equivalent) including design, tuning, and operational ownership - Proven experience developing and enforcing security policies and governance frameworks (SOC 2 required) - Experience leading or supporting SOC 2 audits, including control ownership and evidence management a plus - Hands-on experience with security awareness platforms such as KnowBe4, including program rollout and management - Experience with incident response, vulnerability management, and endpoint security tooling - Experience working with managed security providers (MDR/eSOC) - Strong project management and cross-functional collaboration skills Education: - Bachelor’s degree in Info Tech, Cybersecurity, Computer Science, or related field is preferred but not required - Relevant experience may be considered equivalent Technical Skills: - SIEM platforms (Microsoft Sentinel, SUMO) - Endpoint protection and EDR tools - Vulnerability management platforms - Identity and access management controls - Cloud and SaaS security monitoring - ​Microsoft 365 security ecosyst

← All remote jobs