Cloud Security Analyst (Junior)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+8 more
Job description
Enterprise Box AI runs an AI-powered customer support SaaS platform on Google Cloud. We are looking for a junior analyst to work alongside our Security Lead on the day-to-day security operations of that environment: triaging findings from our cloud security tooling, determining which represent genuine risk, remediating those within scope, and escalating the remainder to the appropriate team.
This is a hands-on cloud security role, not a SOC seat. You will not be watching a dashboard waiting for red. You will be opening cloud configurations, reading logs, and answering the question “is this actually a problem, and what happens if we change it.”
What you’ll do
- Triage. Work cloud infrastructure security findings from our internal platform and our cloud scanners: confirm the finding is real, check it is not already tracked, set severity, and decide what happens next.
- Investigate. Read the live configuration and the logs to establish whether a finding is exploitable, already mitigated, or a false positive. Document everything.
- Remediate within scope. Close out the work that lives in cloud configuration - access controls, service exposure, credential hygiene and scanner coverage.
- Escalate what sits outside it. Findings that resolve to an application code change, and anything touching standing human access to production, go to the Security Lead with your investigation attached. This boundary is a starting point, not a ceiling.
- Hand off and follow through. Route work to the right engineer, then confirm the fix landed and that it held.
- Keep the queue honest. Mute or tune known-benign noise so the real findings stay visible.
- Assist on compliance. We have a compliance program that needs support, and part of this role is helping gather the evidence behind it - access reviews, training records, vendor reviews. It sits alongside the cloud security work; it is not a compliance role in itself.
- Pitch in on the rest of it. Security here is not only Google Cloud. On a small team the work goes where it is needed, so expect to be pulled into things that sit outside the cloud console - including the occasional thing that fits no category at all.
Requirements
- Hands-on experience with a major cloud platform - Google Cloud preferred, AWS or Azure considered. You should be comfortable with the core concepts in whichever you have used: identity and access management, service accounts, compute, managed databases, firewall rules. Day-to-day work here is in Google Cloud and we will support the ramp.
- Comfortable reading logs and running queries against them.
- Comfortable in a shell, such as PowerShell, bash or Cloud Shell.
- Security, networking and cloud fundamentals - common vulnerability classes, CVE and CVSS severity, authentication versus authorization and least privilege, DNS, TLS, ports and firewall rules, and the basics of incident response.
- Familiarity with AI tooling, and the habit of verifying what it produces rather than trusting it - you check its claims against the source before acting on them.
- One year of relevant experience, or equivalent coursework or a degree in cyber security.
Nice to have
- Coding ability. We are not asking you to build anything, but being able to read a script helps.
- Recognized security certifications - CompTIA Security+, Google Associate Cloud Engineer, AZ-500 or similar.
- Exposure to a cloud security posture tool - Security Command Center, Wiz, Prisma Cloud or Defender for Cloud. The concepts transfer even if the vendor does not.
- Container fundamentals - what an image is, the difference between a tag and a digest, and how registries and base images work.
- Exposure to a compliance framework such as SOC 2, ISO 27001 or NIST, including what evidence collection involves.
- Experience working findings or tickets through a lifecycle - deduplication, reassignment, reopening and closure.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
7 Cloud Computing Trends Coming in 2025 for Developers
Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud
9 Ways to Make Money Hacking
Dev Digest 134 - Where pixels sing?