> Markdown version of [/jobs/ext/1914370-sr-security-analyst](https://www.wearedevelopers.com/jobs/ext/1914370-sr-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Security Analyst - **Company:** BDA - **Location:** Woodinville, WA, United States - **Experience:** Expert - **Salary:** $120,000.0 - $130,000.0 - **Contract:** Permanent contract - **Skills:** HTML, Amazon Web Services, Application Firewall, Software System Penetration Testing, Application Testing, User Authentication, Microsoft Azure, Burp Suite, Cloud Computing, Cloud Computing Security, Cyber Security, System Configuration, Linux, DevOps, Distributed Systems, Elasticsearch, Networking Hardware, Intrusion Detection Systems, Virtual Private Networks (VPN), Linux System Administration, Oracle (Applications), PCI Data Security Standards, Security Information and Event Management, SQL Databases, Web Applications, Extensible Markup Language (XML), Transport Layer Security, Load Balancing, Cloud Platform System, Software Security, Malware, Firewalls (Computer Science), Falcon Platform, GWAPT, Information Technology, Tenable Nessus, Oracle Cloud Infrastructure, Vulnerability Analysis - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ba79fdc92aad2a58 ## About the Role * Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field. * Professional experience in information security, application security, infrastructure security, or a closely related area. * Hands-on experience with all of the following: Microsoft Defender, Microsoft Purview, CrowdStrike, Tenable Nessus, and Burp Suite * Proven experience with application and environment security, vulnerability testing, exploit testing, penetration testing, or vulnerability scanning. * Strong understanding of cloud security and experience securing environments such as AWS, OCI, or Azure. * Experience working with Linux environments and securing cloud-based or distributed infrastructure. * Knowledge of security frameworks and standards such as NIST, CIS, or ISO 27001. * Understanding of risk management practices and the ability to identify, prioritize, and communicate security risks. * Working knowledge of security technologies such as firewalls, IDS/IPS, endpoint security, SIEM, and enterprise intrusion-prevention systems. * Experience with system-hardening standards for servers, desktops, laptops, or network devices. * Understanding of malware, attack vectors, network threats, incident response, authentication, and access-control technologies. * Knowledge of internet protocols and security technologies, including HTTP, TLS, SSL, HTML, and XML. * Understanding of cloud, container-based, and virtualized architectures. * Knowledge of encryption techniques, standards, and appropriate encryption levels. * Strong analytical, problem-solving, and attention-to-detail skills. * Clear communication skills and the ability to work effectively across technical and nontechnical teams. * A collaborative and humble working style, with the ability to accept direction, execute priorities, and remain open to the perspectives of others. Preferred Qualifications * Previous experience in an IT infrastructure, systems administration, networking, DevOps, or engineering role before moving into security. * Experience that combines technical security with governance, risk, compliance, or privacy responsibilities. * Familiarity with privacy regulations such as GDPR, CPRA, or CCPA. * Experience with firewalls, load balancers, web application firewalls, or VPN concentrators. * Experience with databases and related technologies such as Elasticsearch, SQL, or Oracle. * Experience handling and protecting information across different sensitivity levels. * Familiarity with standards or regulations such as FISMA, GLBA, FERPA, PCI DSS, ISO, or NIST. * Higher education or government information-security experience. * Security certifications such as CISSP, CISA, CISM, CEH, GWAPT, GPEN, CSFA, or similar credentials. * Experience with SUMO Cloud or comparable security monitoring and log-analysis tools. ## Description BDA is looking for a Senior Security Analyst who can help us strengthen our security program and move from a primarily reactive approach to a more proactive, planned security strategy. This role will have a strong focus on application, cloud, and infrastructure security. You will identify vulnerabilities, test applications and environments, evaluate potential exploits, and work closely with IT and business partners to reduce risk across the organization. You will also have the opportunity to help define what the red-team security function looks like at BDA. We are open to an experienced mid-level professional who has strong application security skills and is ready to continue growing, as well as a more seasoned security professional seeking broad ownership and meaningful challenges. What You'll Do * Conduct vulnerability scans, penetration testing, and security assessments across applications, systems, cloud environments, and infrastructure. * Use tools including Tenable Nessus, Burp Suite, and CrowdStrike to identify vulnerabilities, investigate threats, and recommend remediation. * Test web applications to identify potential exploits, attack paths, and security weaknesses. * Evaluate the security of Linux-based and cloud environments, including AWS, OCI, and Azure. * Partner with infrastructure and engineering teams to improve system configurations, hardening standards, access controls, and overall security posture. * Monitor security events, investigate potential incidents, and support incident response and forensic activities. * Conduct account reviews, access reviews, risk assessments, and other security-related analysis. * Develop clear reports and recommendations for technical teams, business leaders, and executive stakeholders. * Help establish repeatable security processes, priorities, and testing practices that allow the organization to address risks proactively. * Collaborate with security team members, consultants, IT infrastructure, engineering, legal, compliance, and business teams across BDA. * Support the development and ongoing improvement of security policies, procedures, standards, and employee awareness initiatives. * Stay current on emerging threats, vulnerabilities, attack methods, and security best practices. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [The Resilience of the World Wide Web](https://www.wearedevelopers.com/videos/1281-the-resilience-of-the-world-wide-web) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [NoLoJS - Avoiding JavaScript Cruft with HTML and CSS - Aaron T. Grogg](https://www.wearedevelopers.com/videos/1806-nolojs-avoiding-javascript-cruft-with-html-and-css-aaron-t-grogg) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)