Senior Security Analyst BlackSky in US National
Listed on 2026-10-09
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations, Network Security
Senior Security Analyst
Seattle, WA, Herndon, VA, Remote
The Senior Security Analyst position reports to the Manager of Security Analysis Team (i.e., Security Operations Center (SOC)) with rollup to the Director of Security and plays a vital role in monitoring, defending, and securing the Black Sky enterprise environment against cyber threats.
You will perform continuous monitoring of network, managed devices and identities, cloud services, business systems, and application traffic in support of Black Sky’s Security Operations Center (SOC). You will conduct analysis of these logs within an integrated Security Information and Event Management (SIEM) platform and work to develop novel searches, dashboards, and alerts to improve the SOC’s detection and response timelines.
You will leverage cyber threat intelligence (CTI) reporting in conjunction with internal digital forensics and incident response (DFIR) activities to ensure Black Sky is properly positioned to defend against security threats to our enterprise networks.
The Security Team is geographically distributed across our Herndon, VA and Seattle, WA offices therefore the role can be based at either of these two locations, surrounding areas, or anywhere in the United States.
Responsibilities:- Perform security monitoring and digital forensics and incident response (DFIR) activities across corporate, product, and mission environments by reviewing events and alerting attributed to indicators of compromise (IOCs), indicators of attack (IOAs), cyber threat intelligence (CTI) reporting, and non-compliance activities
- Review multiple sources of cyber threat intelligence and apply the insights appropriately to inform and secure the enterprise
- Conduct regular threat hunting across the corporate, product, and mission environments
- Document procedures for performance of job duties to formalize ad-hoc processes
- Conduct security analysis of data from many sources - system/event logs, network traffic, and SaaS security tools.
- Perform analysis, and digital forensics of potential malware using Industry standard Sandbox tools.
- Support continuous monitoring of network, operating system, and application log traffic to identify potential security threats related to the industry.
- Support vulnerability management process through identification and prioritization of critical security concerns in collaboration with IT or Product owners to drive vulnerability or misconfiguration remediation activities.
- Work with product owners to define offensive testing scope requirements and constraints and to support the remediation process on any identified vulnerabilities
- Monitor operational systems for continuous compliance with hardened baseline images against industry checklists such as CIS Benchmarks and/or DISA STIGs,
- Develop solutions to automate reoccurring tasks and improve adversary detection.
- Complete compliance assessments and report findings to management.
- Document findings (anomalies, incidents, concerns) and share widely with security, IT, and product teams as appropriate to enable enhanced understanding of security posture.
- Strong Linux security background with Ubuntu, Amazon Linux, and/or CentOS preferred.
- Support security training and manage tabletop scenarios to other employees
- Support SOX/ITGC, CMMC 2.0 Level 2, NIST 800-171 r3, UK Cyber Essentials, and customer-specific compliance requirements.
- Other responsibilities as assigned.
- A minimum of seven (7) years’ experience performing security analyst and DFIR activities.
- A minimum of seven (7) years’ experience in IT security.
Candidates should hold at least one of the following security certifications:
- Certified Information Systems Security Professional (CISSP),
- GIAC Certified Incident Handler (GCIH),
- Co…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).