Sr. Security Analyst
Listed on 2026-08-07
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Most companies claim to have the best people. We say to them, Keep dreaming. Our people are second to none. They set us apart with their entrepreneurial spirit and ambition. They come to us from the likes of Amazon, Microsoft, Nordstrom, Starbucks and the sports world, bringing energy, bold ideas and a willingness to dive into the unfamiliar. It's our people that make BDA the top global Merchandise Agency to work for.
Location:- This role is based in Woodinville, WA and requires you to work onsite 4 days per week, with 1 day remote.
- To be considered, you must live within commuting distance, as regular in-person collaboration is a key part of the role.
BDA is looking for a Senior Security Analyst who can help us strengthen our security program and move from a primarily reactive approach to a more proactive, planned security strategy.
This role will have a strong focus on application, cloud, and infrastructure security. You will identify vulnerabilities, test applications and environments, evaluate potential exploits, and work closely with IT and business partners to reduce risk across the organization.
You will also have the opportunity to help define what the red-team security function looks like are open to an experienced mid-level professional who has strong application security skills and is ready to continue growing, as well as a more seasoned security professional seeking broad ownership and meaningful challenges.
What You’ll Do- Conduct vulnerability scans, penetration testing, and security assessments across applications, systems, cloud environments, and infrastructure.
- Use tools including Tenable Nessus, Burp Suite, and Crowd Strike to identify vulnerabilities, investigate threats, and recommend remediation.
- Test web applications to identify potential exploits, attack paths, and security weaknesses.
- Evaluate the security of Linux-based and cloud environments, including AWS, OCI, and Azure.
- Partner with infrastructure and engineering teams to improve system configurations, hardening standards, access controls, and overall security posture.
- Monitor security events, investigate potential incidents, and support incident response and forensic activities.
- Conduct account reviews, access reviews, risk assessments, and other security-related analysis.
- Develop clear reports and recommendations for technical teams, business leaders, and executive stakeholders.
- Help establish repeatable security processes, priorities, and testing practices that allow the organization to address risks proactively.
- Collaborate with security team members, consultants, IT infrastructure, engineering, legal, compliance, and business teams across BDA.
- Support the development and ongoing improvement of security policies, procedures, standards, and employee awareness initiatives.
- Stay current on emerging threats, vulnerabilities, attack methods, and security best practices.
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Professional experience in information security, application security, infrastructure security, or a closely related area.
- Hands-on experience with all of the following:
Microsoft Defender, Microsoft Purview, Crowd Strike, Tenable Nessus, and Burp Suite - Proven experience with application and environment security, vulnerability testing, exploit testing, penetration testing, or vulnerability scanning.
- Strong understanding of cloud security and experience securing environments such as AWS, OCI, or Azure.
- Experience working with Linux environments and securing cloud-based or distributed infrastructure.
- Knowledge of security frameworks and standards such as NIST, CIS, or ISO 27001.
- Understanding of risk management practices and the ability to identify, prioritize, and communicate security risks.
- Working knowledge of security technologies such as firewalls, IDS/IPS, endpoint security, SIEM, and enterprise intrusion-prevention systems.
- Experience with system-hardening standards for servers, desktops, laptops, or network devices.
- Understanding of malware, attack vectors, network threats, incident response, authentication, and access-control technologies.
- Knowledge of internet protocols and security technologies, including HTTP, TLS, SSL, HTML, and XML.
- Understanding of cloud, container-based, and virtualized architectures.
- Knowledge of encryption techniques, standards, and appropriate encryption levels.
- Strong analytical, problem-solving, and attention-to-detail skills.
- Clear communication skills and the ability to work effectively across technical and nontechnical teams.
- A collaborative and humble working style, with the ability to accept direction, execute priorities, and remain open to the perspectives of others.
- Previous experience in an IT infrastructure, systems administration, networking, Dev Ops, or engineering role before moving into security.
- Experience that combines technical security with governance, risk, compliance, or privacy…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).