A growing cloud-first technology organization operating in a highly regulated environment is seeking a Senior Cybersecurity Analyst to help mature its cybersecurity program.
This is a broad security position for someone who combines hands-on technical expertise with governance, risk, compliance, automation, and cross-functional leadership. The successful candidate will independently own initiatives spanning vulnerability remediation, incident response, cloud security, audits, policy development, risk assessments, and AI-enabled security workflows.
This is not a traditional alert-monitoring or vulnerability-scanning role. The analyst will take ownership of security issues from initial identification through remediation and validated closure.
** Considering applicants in Waltham, MA / Boston, MA - Hybrid / New York / Florida / Texas / Virginia / Washington **
RESPONSIBILITIES- Own vulnerability-remediation activities from initial finding through validated closure.
- Prioritize vulnerabilities and coordinate remediation timelines and SLAs with engineering and infrastructure teams.
- Participate in security and privacy incidents, including investigation, evidence collection, root-cause analysis, and post-incident activities.
- Coordinate incident work across security, engineering, legal, customer-facing, and business teams.
- Review cloud-security findings and recommend practical corrective actions.
- Perform security-design reviews, risk assessments, and control evaluations.
- Develop and maintain security policies, standards, procedures, runbooks, and recommendations.
- Support internal and external audits, control validation, and evidence collection.
- Identify opportunities to automate recurring security activities and reporting.
- Build Python and AI-assisted workflows that improve investigations, analysis, and operational efficiency.
- Help establish repeatable processes and mature the broader cybersecurity program.
- Communicate security risks and remediation requirements to technical and nontechnical stakeholders.
Role Requirements:- 5+ years of cybersecurity or information-security experience.
- Demonstrated ownership of vulnerability-remediation initiatives.
- Experience driving findings through prioritization, remediation, SLA tracking, and closure validation.
- Hands-on incident-response and investigation experience.
- Strong AWS or comparable cloud-security knowledge.
- Experience developing security policies, standards, or governance processes.
- Experience supporting security audits and compliance programs.
- Knowledge of ISO 27001, SOC 2, NIST CSF, CIS Controls, or similar frameworks.
- Python, scripting, or security-automation experience.
- Practical experience using AI-enabled tools in security or technical workflows.
- Experience independently leading projects or major workstreams.
- Strong communication and cross-functional stakeholder-management skills.
- Ability to influence engineering teams without direct reporting authority.
PREFERRED EXPERIENCE- Qualys experience.
- AWS-native security services such as GuardDuty, Security Hub, IAM, KMS, CloudTrail, Config, or Inspector.
- ISO 42001 or AI-governance exposure.
- Application-security, threat-modeling, or architecture-review experience.
- WAF, Cloudflare, or Akamai experience.
- Claude Code, GitHub Copilot, or comparable AI-development tools.
- Experience in a regulated, SaaS, healthcare, or financial-technology environment.
- CISSP, CISM, CCSP, GSEC, or comparable certification.