Security Analyst II
Listed on 2026-02-28
-
IT/Tech
Cybersecurity
At Sensiba, we're more than just a Top 75 Accounting Firm - we're a purpose-driven organization committed to making a meaningful impact for our clients, our people, and our communities. Recognized as a Top Workplace USA, we're proud of our culture of exceptional employee engagement, collaboration, and continuous growth.
We help clients solve problems, navigate complexity, and build a foundation for sustainable success. Whether supporting fast-growing startups or established enterprises, we bring deep expertise and a people-first approach to every engagement.
In 2018, Sensiba became a certified B Corporation (B Corp) - a designation that reflects our commitment to using business as a force for good. This certification holds us accountable to high standards of social and environmental performance, transparency, and ethical governance. It's not just a badge - it's a reflection of how we operate, make decisions, and support our stakeholders.
SummaryThe Security Analyst works directly with clients across a variety of industries to perform hands‑on security assessments, identify vulnerabilities, and support remediation validation and retesting efforts. This role focuses on identifying—and when appropriate, exploiting—weaknesses in systems, applications, and networks through structured penetration testing activities.
Working under the guidance of managers and senior lead pentesters, the Security Analyst collaborates closely with client security teams to interpret findings, answer questions, and provide actionable recommendations. Strong written and verbal communication skills are essential, as this role includes preparing professional reports and presenting results to both technical and executive stakeholders.
This is an excellent opportunity for an early‑career cybersecurity professional to gain hands‑on experience, develop technical and analytical skills, and grow within a collaborative, client‑focused consulting environment.
Job Responsibilities- Perform penetration testing of web applications, APIs, mobile applications, infrastructure, and cloud environments.
- Simulate real‑world attack scenarios to identify security weaknesses and provide actionable remediation recommendations.
- Analyze and document vulnerabilities using industry‑recognized frameworks and methodologies (e.g., OWASP, MITRE ATT&CK, CIS).
- Prepare clear, professional technical reports and executive summaries communicating findings, risks, and remediation guidance.
- Participate in client meetings, walkthroughs, and presentations to explain results and answer questions.
- Support remediation validation and retesting efforts.
- Stay current with emerging threats, tools, and security best practices through ongoing research and professional development.
- Contribute to the development and continuous improvement of internal testing methodologies, checklists, and procedures.
- Leverage scripting and coding skills to automate tasks and develop custom security tools where appropriate.
- Bachelor's degree in Computer Science, Information Security, or related field, or an equivalent combination of education and experience.
- 1-2+ years of experience performing penetration testing and/or defensive security operations.
- Foundational knowledge of network protocols, operating systems (Windows and Linux), and cloud environments (AWS, Azure, or GCP).
- Familiarity with common security frameworks and standards (e.g., OWASP Top 10, MITRE ATT&CK, NIST, CIS).
- Ability and willingness to learn programming languages such as Python, Java, C#, or similar.
- Strong analytical and problem‑solving skills.
- Excellent written and verbal communication skills.
- High level of integrity, professionalism, and commitment to ethical standards.
- Familiarity with penetration testing tools such as Burp Suite, Metasploit, Nmap, and Wireshark preferred.
- Exposure to defensive technologies including SIEM platforms, EDR solutions, firewalls, and IDS/IPS preferred.
- Experience translating technical findings into business risk impacts for non‑technical audiences preferred.
This role offers a competitive base salary along with a comprehensive benefits package. Pay ranges for U.S.
-based positions are…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).