- Queracomputinginc
- Boston, MA
- 28 days ago
- $175,000 - $200,000+
Security Analyst.
Before you go
Before you leave us, sign up for our email alerts
We don't do job spam, just the best digital jobs delivered straight to your inbox.
Security Analyst: our view in 3 lines...
- The Role:This role is for a security analyst supporting security automation, cloud security, vulnerability management, and compliance work across on-premises and multi-cloud environments.
- The Person:The person will review security findings, help remediate vulnerabilities, support cloud baselines and IAM reviews, automate security tasks, and provide evidence for SOC 2, ISO 27001, and other security assessments.
- Requirements:The ideal candidate has at least two years of experience with information security, systems administration, or DevOps, plus Python, PowerShell, or Bash, AWS, Azure, Oracle Cloud, NIST, and vulnerability management tools.
About the role
Security Analyst
Position Summary
As a Security Analyst, you will be part of our growing Security & Compliance team, building security automations, creating baselines for on-premises and cloud environments, assisting teams with vulnerability scans and management, supporting our compliance team with evidence gathering and audits, and more. This is an opportunity to be part of a small team with increasing importance and responsibility.
Primary Responsibilities
- Review and triage findings from vulnerability scans, penetration tests, and configuration assessments to identify potential security risks.
- Work with DevOps, engineers, and system owners to remediate vulnerabilities across multi-cloud and on-prem assets.
- Support secure configuration baselines for AWS, Azure, and Oracle Cloud resources.
- Monitor cloud environments for misconfigurations and suspicious activity.
- Assist with IAM policy reviews and privilege audits.
- Write scripts (Python, PowerShell, or Bash) to automate detection, reporting, or remediation of security issues.
- Integrate security tools and data into dashboards or workflow systems (e.g., Jira, SIEM, or ticketing).
- Provide technical evidence and control implementation support for SOC 2, ISO 27001, or customer security assessments.
- Partner with the compliance team to map technical controls to framework requirements.
- Assist with incident triage, response, and root cause analysis.
- Support endpoint protection, log monitoring, and threat intelligence initiatives.
Minimum Qualifications
- Bachelor's degree in a related field or equivalent related experience
- Minimum of two years of experience with security exposure in information security, systems administration, or DevOps.
- Proficient in at least one scripting language (Python, PowerShell, or Bash).
- Strong understanding of operating systems, networking, and cloud fundamentals.
- Knowledge of security frameworks such as NIST
- Familiarity with vulnerability management tools (e.g., Tenable, Qualys, Rapid7, AWS Inspector, or Microsoft Defender).
- Working knowledge of AWS, Azure, and/or Oracle Cloud security controls and services.
- Comfortable working cross-functionally with engineering, IT, and other teams as needed.
Knowledge, Skills, and Abilities
- Ability to travel up to 15% to assist in team building and planning exercises.
- Strong, professional communication skills, both verbal and written, including the skill in articulating and translating technical language to non-technical customers.
- Ability to plan for contingencies and anticipate problems.
- Ability to ask critical questions to assess needs and requirements
Preferred Qualifications
- Experience with SIEM or SOAR platforms (e.g., Splunk, Microsoft Sentinel).
- Familiarity with infrastructure such as code (Terraform, CloudFormation).
- Exposure to compliance frameworks such as SOC 2, ISO 27001, or NIST 800-53.
- Security certifications (Security+, GSEC, AWS Security Specialty, or similar).
- Endpoint Security/Patching/Inventory experience
Compensation Range
$175,000 - $200,000+
Equal Opportunity Statement: QuEra is an equal opportunity employer. We recruit, hire, and promote without regard to legally protected characteristics. Where project work requires access to controlled information or facilities, employment is contingent on the ability to obtain and maintain appropriate authorizations. All hiring complies with applicable federal and state laws.
#LI-DA1

