> Markdown version of [/jobs/ext/177111-security-analyst](https://www.wearedevelopers.com/jobs/ext/177111-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Analyst - **Company:** Core Health & Fitness, LLC - **Location:** Vancouver, WA, United States - **Experience:** Experienced - **Salary:** $85,000.0 - $100,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Systems Engineering, BASIC (Programming Language), Business Software, Software as a Service, Cloud Computing Security, Configuration Management, Cyber Security, Information Systems, Linux, Domain Name System (DNS), Identity and Access Management, IT Management, Networking Hardware, Intrusion Detection Systems, Virtual Private Networks (VPN), Python (Programming Language), Log Analysis, Routing, Network Segmentation, Windows PowerShell, Role-Based Access Control, Phishing, Security Information and Event Management, Data Streaming, Systems Integration, TCP/IP, Virtualization Technology, Software Vulnerability Management, Data Logging, Data Processing, In-Plane Switching (IPS), Firewalls (Computer Science), Web Filtering, Information Technology, Vulnerability Analysis - **Published:** May 30, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=08329708eadad0ed ## About the Role Do you have experience in Windows?, Do you have a Bachelor's degree?, * Bachelor's degree in Information Security, Computer Science, Information Systems, or equivalent practical experience. * 3+ years in an information security, SOC analyst, or infrastructure role with hands-on responsibility for multiple security tools in a small or mid-sized enterprise. * Experience supporting mixed environments with on-prem servers, SaaS, and distributed business applications. Technical Skills * Practical experience with several of the following categories: SIEM/log management, EDR/XDR, email security, IDS/IPS, next-gen firewalls/VPN, web filtering/proxy, vulnerability scanning, DLP, MDM/endpoint management, identity security (SSO/MFA), and secure backup/DR. * Strong understanding of network and system fundamentals (Windows and virtualization, basic Linux, TCP/IP, DNS, routing, VPNs) and how attacks traverse these layers. * Familiarity with data protection and privacy practices (GDPR and PII handling) and at least one security or compliance framework. * Ability to use scripting or automation (PowerShell, Python, or similar) for log analysis, enrichment, and small workflow automations is preferred. Required Soft Skills * Strong analytical and problem-solving skills with the ability to interpret noisy alerts from many tools into clear, prioritized actions. * Effective communication with both technical and non-technical stakeholders, including concise incident and risk reporting. * Comfortable working in a lean team, balancing operational workload with project and improvement work, and taking ownership of issues from detection through closure. * Independent thinker. Can operate independently within the guidance and priorities set by IT leadership and prioritizes production issues over administrative tasks. * Proactive, self-motivated, and organized with attention to detail. * Open, honest, and transparent approach to dealing with any issue. Certifications (preferred) * One or more: Security+, CySA+, CISSP, SSCP, GSEC, or similar practitioner-level security certifications. * Additional plus: privacy/compliance-focused credentials (e.g., ISO 27001 lead implementer/auditor, CIPP/E) or vendor certifications for SIEM/EDR or other core tools. ## Description The Security Analyst is a hands-on role within IT responsible for daily operation and continual improvement of the company's security and privacy posture across on-prem and SaaS environments and global user base. This role focuses on monitoring and tuning a 13+ tool security stack, detecting and responding to threats, and supporting growing regulatory and customer compliance demands (GDPR, PII, and industry frameworks.) Roles and Responsibilities Security Monitoring, Tools & Incident Response * Monitor and manage alerts across a multi-tool ecosystem (e.g., MDR/XDR, email security, IDS/IPS, firewall, MDM, vulnerability scanner, DLP, password/privileged access tools, cloud security, backup/DR, and threat-intel feeds). * Normalize, correlate, and tune alerts from 13+ tools to reduce noise and focus on high-value events, maintaining clear runbooks for triage and escalation. * Lead initial investigation and containment of incidents (phishing, malware, account compromise, ransomware, data exfiltration), coordinating with Helpdesk, systems engineer, and network architect as needed. * Maintain case records, evidence, and post-incident reports that feed into continual improvement of rules, playbooks, and configurations. Vulnerability, Configuration Management & Auditing * Operate vulnerability management tools to scan servers, endpoints, network devices, and key applications; track remediation with system owners and prioritize based on business impact. * Work with the technical architect/network engineer to implement and validate secure configurations, hardening baselines, network segmentation, and logging on firewalls, VPN, and other perimeter tools. * Monitor vendor security advisories, CVEs, and threat bulletins and recommend patching or compensating controls for high-risk exposures. * Audit work for IAM/access management, RBAC roles. Tool Integration, Automation & Optimization * Administer day-to-day operations of the security toolset: manage access, policies, rules, connectors, and integrations with infrastructure and identity platforms. * Collaborate with IT to integrate security tools with ticketing, identity, and logging platforms, and help design lightweight automation/playbooks where supported (e.g., auto-quarantine, IP blocking, user notifications). * Evaluate overlapping capabilities across the 13+ tools and provide recommendations to simplify, consolidate, or better utilize existing investments. Compliance, Privacy & Customer Demands * Support implementation and ongoing operation of controls for GDPR, PII protection, and security frameworks (e.g., SOC 2-like controls, ISO/NIST-aligned practices as pursued by the business). * Use SIEM and related tools for log retention, evidence gathering, and reporting to support audits, customer due-diligence requests, and data-privacy impact assessments. * Maintain and update security documentation (asset lists, data flows, risk registers, control matrices, and tool inventories) to reflect the current environment. * Participate in CAB process as appropriate. Policies, Awareness & Support for Small Teams * Contribute to security and privacy policies, standards, and procedures that are practical for a lean infrastructure team while meeting regulatory expectations. Evaluate and update IT policies as needed. * Prepare targeted awareness content and simulations focusing on phishing, account security, data handling, and secure use of manufacturing/warehouse systems. * Serve as a security point of contact for Helpdesk and application owners, providing guidance embedded into day-to-day processes and changes. ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Creating a routing app with Google Maps API from scratch](https://www.wearedevelopers.com/videos/831-creating-a-routing-app-with-google-maps-api-from-scratch) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [A Technical Introduction to Bitcoin's 2nd Layer- The Lightning Network](https://www.wearedevelopers.com/videos/15-a-technical-introduction-to-bitcoin-s-2nd-layer-the-lightning-network) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)