> Markdown version of [/jobs/ext/1768395-security-analyst-ii](https://www.wearedevelopers.com/jobs/ext/1768395-security-analyst-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Analyst II - **Company:** Lucid Inc. - **Location:** Salt Lake City, UT, United States (Remote available) - **Experience:** Starter - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing, Cyber Security, Cloud Platform System - **Published:** July 11, 2026 - **Apply:** https://dejobs.org/x/x/1A74034AD8D54A08A98037C89E53F359/job/ ## About the Role * Bachelor's degree in information security assurance, business management, or a related field * 2-3 years of experience with third party risk management, GRC, customer due diligence, etc. * Understanding of common security frameworks and principles (e.g. NIST 800-53, ISO 27001, SOC 2, etc). Strong organizational skills with the ability to manage tasks independently and meet deadlines with minimal oversight on daily routines. * Excellent verbal and written skills; comfortable translating security concepts into clear documentation. * Strong interpersonal skills with a track record of building positive relationships across non-technical teams (like Legal, HR, Finance) and technical teams (like IT and Engineering) to resolve security risks collaboratively., * Prior experience working within a modern SaaS environment or cloud-first technology company, with a basic familiarity of how cloud applications operate. * Prior knowledge of and skill in applying risk management principles and practices * One or more preferred Certification(s): CRISC, CISSP, CISA, SSCP, CC, Security+, CySA+, etc. * Basic understanding of cloud environments (AWS, GCP, or Azure). ## Description * Conduct third-party vendor risk assessments and internal risk evaluations; identify, document, and report on potential vulnerabilities and control gaps. * Respond directly to standard vendor security questionnaires and support internal teams (i.e. Sales, Customer Success, etc.) in answering security-related questions from prospects. * Assist in tracking and collecting evidence for ongoing SOC 2 and ISO 27001 compliance audits. * Proactively identify emerging threats and associated risks to existing business processes and corporate assets, and collaborate with senior team members to develop practical security solutions. * Coordinate and deliver security awareness training programs to employees to foster a strong security culture. * Assure compliance to outside regulations affecting the Company * Collect and maintain impactful security and compliance metrics for team dashboards. * Partner with Legal, Engineering, IT, Finance, and HR to ensure corporate security policies are understood and followed. * Identify operational inefficiencies and areas for improvement in our existing security controls, and help design smoother workflows. ## Related Videos - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)