Security Analyst II Boston, Massachusetts Boulder, Colorado Chi
Listed on 2026-02-16
-
IT/Tech
Cybersecurity
Boston, Massachusetts, United States, Boulder, Colorado, United States, Chicago, Illinois, United States, Glendora, California, United States, Remote - US, Richmond, Virginia, United States
Join the Market Leader in Electric Power Data and Analytics Solutions
The electrical grid is the largest and most complicated machine ever built. Yes Energy’s industry-leading electric power trading analytics software provides real-time visibility into the massive amount of data generated by the North American electrical grid daily. Our unique and innovative view of the data informs real-time trading decisions and mid-to-long-term investment decisions that keep utility prices low, support the energy transition, and keep the grid running.
It’s both challenging work and work with a purpose.
Be a part of our successful, growing business during international transformation.
Position SummaryAs a Security Analyst II, you will be helping keep the grid safe and our customers secure. You will be part of our growing Security & Compliance team, building security automations, creating baselines for on-premises and cloud environments, assisting teams with vulnerability scans and management, supporting our compliance team with evidence gathering and audits, and more. This is an opportunity to be part of a small team with increasing importance and responsibility.
You will help Yes Energy stay secure into the future.
- Salary range: 80,000 - 95,000
- Location:
Yes Energy Core Offices or Remote - Full-time
- Reporting to:
Senior Manager, IT and Compliance - Travel requirement: up to 15% to Yes Energy’s core offices
- Review and triage findings from vulnerability scans, penetration tests, and configuration assessments to identify potential security risks.
- Work with Dev Ops, engineers, and system owners to remediate vulnerabilities across multi-cloud and on-prem assets.
- Support secure configuration baselines for AWS, Azure, and Oracle Cloud resources.
- Monitor cloud environments for misconfigurations and suspicious activity.
- Assist with IAM policy reviews and privilege audits.
- Write scripts (Python, Power Shell, or Bash) to automate detection, reporting, or remediation of security issues.
- Integrate security tools and data into dashboards or workflow systems (e.g., Jira, SIEM, or ticketing).
- Provide technical evidence and control implementation support for SOC 2, ISO 27001, or customer security assessments.
- Partner with the compliance team to map technical controls to framework requirements.
- Assist with incident triage, response, and root cause analysis.
- Support endpoint protection, log monitoring, and threat intelligence initiatives.
- Bachelor’s degree in a related field or equivalent related experience
- Minimum of two years of experience with security exposure in information security, systems administration, or Dev Ops.
- Proficient in at least one scripting language (Python, Power Shell, or Bash).
- Strong understanding of operating systems, networking, and cloud fundamentals.
- Knowledge of security frameworks such as NIST
- Familiarity with vulnerability management tools (e.g., Tenable, Qualys, Rapid7, AWS Inspector, or Microsoft Defender).
- Working knowledge of AWS, Azure, and/or Oracle Cloud security controls and services.
- Comfortable working cross-functionally with engineering, IT, and compliance teams.
- Ability to travel up to 15% to assist in team building and planning exercises.
- Strong, professional communication skills, both verbal and written, including the skill in articulating and translating technical language to non-technical customers.
- Ability to plan for contingencies and anticipate problems.
- Ability to ask critical questions to assess needs and requirements
- Experience with SIEM or SOAR platforms (e.g., Splunk, Microsoft Sentinel).
- Familiarity with infrastructure as code (Terraform, Cloud Formation).
- Exposure to compliance frameworks such as SOC 2, ISO 27001, or NIST 800-53.
- Security certifications (Security+, GSEC, AWS Security Specialty, or similar).
- Endpoint Security/Patching/Inventory experience
At Yes Energy, we value connecting directly with candidates. We…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).