> Markdown version of [/jobs/ext/284343-it-security-analyst](https://www.wearedevelopers.com/jobs/ext/284343-it-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Analyst - **Company:** Code - **Location:** San Francisco, CA, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Audit Trail, Microsoft Azure, Cloud Computing Security, Cyber Security, DevOps, Intrusion Detection and Prevention, Phishing, Security Information and Event Management, Software Vulnerability Management, Information Technology, Cybercrime - **Published:** May 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d130f280905fe2dd ## About the Role Do you have experience in Threat detection & response?, Do you have a Bachelor's degree?, * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent professional experience. * 2+ years of experience in a security analyst or similar role. * Experience working with security tools such as SIEM, EDR, and vulnerability management platforms. * Strong understanding of common attack techniques, threat detection, and incident response workflows. * Experience analyzing logs and correlating events across multiple data sources. * Familiarity with endpoint security controls, including application whitelisting and privilege management. * Ability to assess and prioritize security alerts and escalate appropriately. * Strong communication and documentation skills. * Eligible to obtain and maintain an active U.S. Top Secret security clearance, * Experience working in both enterprise and secure (e.g., enclave or regulated) environments. * Familiarity with compliance frameworks such as SOC 2, NIST, or FedRAMP. * Experience with threat hunting methodologies and tools. * Knowledge of cloud security principles (AWS, Azure, or GCP). * Experience conducting or supporting phishing simulations and security awareness programs. * Relevant certifications (e.g., Security+, CySA+, GCIH, or similar). * Active U.S. security clearance (Secret or Top-Secret) ## Description We are seeking a mid-level Security Analyst to join our team. This role will focus on monitoring, analyzing, and improving the security posture of Code Metal's enterprise and enclave environments. In this role, you will work closely with engineering, DevOps, and leadership to detect threats, investigate security events, and escalate incidents as needed. You will help operationalize security across the organization while supporting vulnerability management, compliance initiatives, and continuous security improvement. Requirements Core Responsibilities * Monitor and analyze alerts from SIEM, EDR, and other security tools to detect suspicious or malicious activity. * Investigate security events and incidents, perform triage, and escalate issues to appropriate teams for remediation. * Conduct threat hunting activities to proactively identify potential risks and anomalous behavior. * Support vulnerability management processes, including scanning, analysis, prioritization, and tracking remediation efforts. * Assist in the execution and improvement of incident response procedures and runbooks. * Analyze system, network, and audit logs across enterprise and enclave environments. * Support endpoint security controls, including application whitelisting and privilege/elevation management. * Participate in phishing simulations and user awareness initiatives to improve organizational security posture. * Collaborate with DevOps and engineering teams to communicate findings and support remediation efforts. * Assist with compliance activities, including evidence collection and control validation. * Maintain clear and accurate documentation of incidents, processes, and standard operating procedures. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk)