{"id":1311684,"url":"https://alion.io/job/bbrown-senior-security-analyst","title":"Senior Security Analyst","company":{"id":1779108,"name":"Brown & Brown","domain":"bbrown.com","url":"https://alion.io/company/brown-and-brown","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"B","score":75,"open_postings":16,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-09-28T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Plano, United States","United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":86000,"max_usd":169000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":775},"experience_years_min":7,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"DLP","optional":false},{"name":"SIEM","optional":false},{"name":"Crowdstrike","optional":true},{"name":"Cyber Kill Chain","optional":true},{"name":"Google SecOps","optional":true},{"name":"Microsoft Entra ID","optional":true},{"name":"MITRE ATT&CK","optional":true},{"name":"ServiceNow","optional":true}],"status":"closed","first_seen_at":"2026-09-22T00:00:00Z","employer_posted_date":"2026-09-22","last_verified_at":"2026-09-28T21:42:54Z","board_verified":false,"closed_at":"2026-09-28T21:42:54Z","days_open":6,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":6},"description":"Built on meritocracy, our unique company culture rewards self-starters and those who are committed to doing what is best for our customers.\nBrown & Brown is seekingaSenior Security Analyst to join our growing team in Daytona Beach, FLor Plano, TX.\nThe Security Analyst supports the organization’s security posture through continuous monitoring, analysis, investigation, and response to cybersecurity threats and suspicious activity. This position within the Office of the CISO focuses on security operations, threat intelligence, incident triage, alert validation, log analysis, and coordination across security and technology teams to improve detection and response capabilities. The Security Analyst reports directly to the Global Director of Security Operations and Incident Response and helps the organization prevent, detect, contain, and respond to threats through disciplined analysis, documentation, and operational support. In addition, the security analyst is responsible forvarious security improvement projects.\nHow You Will Contribute:\nMonitor security alerts, events, and logs across endpoint, network, cloud, identity, email, and application security platforms\n\nPerform security triage, analysis, and investigation of suspicious activity to determinescope, impact, and appropriate responseactions\n\nValidate and escalate security incidents in accordance withincident response procedures, ensuring timelycommunication and documentation\n\nAnalyze data from SIEM, EDR, IDS/IPS, DLP, email security, and other monitoring tools to identifymalicious or anomalous behavior\n\nSupport incident response activities by collecting forensic evidence, preserving artifacts, analyzing forensic artifacts, tracking actions, and assistingwith containment and recovery efforts\n\nLeverage threat intelligence sources and internal context to assess emerging threats, attacker tactics, and indicators of compromise relevant to the organization\n\nReview and tune detection content, use cases, and alert logic in partnership with engineering and platform teams to improve detection quality and reduce false positives\n\nConduct recurring and ad hoc threat hunting activities using logs, endpoint telemetry, and threat intelligence to identifypreviously undetected threats\n\nTrack, document, and report security incidents, investigative findings, trends, and operational metrics to support management reporting and continuous improvement\n\nAssistwith vulnerability, exposure, and risk-related analysis by correlating findings with threat activity and business impact\n\nSkills & Experience to be Successful:\nB.S. in Information Security, Computer Science, Computer Engineering or similar technical program or equivalent experience\n\nAt least one active security certification preferred: GCIH, GCIA, CISSP, CEH or related\n\nPreferred experience using CrowdStrike, Google SecOps, Microsoft Log Analytics, and ServiceNow.\n\n7+ years in a security operations, incident response, threat monitoring, or cyber defense role supporting a large organization\n\nWorking knowledge of security monitoring and investigative technologies such as SIEM, EDR, IDS/IPS, DLP, vulnerability management, email security, and threat intelligence platforms\n\nStrong understanding of security operations concepts such as incident triage, alert validation, threat intelligence, kill-chain analysis, insider threat, risk assessment, and security metrics\n\nFamiliarity with attack paths, threat vectors, attacker TTPs, indicators of compromise, and investigative methodologies\n\nWorking knowledge of information security best practices, incident handling procedures, and common security frameworks such as NIST and MITRE ATT&CK\n\nExperience investigating activity in Microsoft security ecosystems, including Entra ID, Defender, and related cloud or hybrid environments preferred\n\nExperience with writing queries, analyzing logs, building reports, or using basic scripting for investigations and operational efficiency preferred\n\nTeammate Benefits & Total Well-Being\nWe go beyond standard benefits, focusing on the total well-being of our teammates, including:\nHealth Benefits: Medical/Rx, Dental, Vision, Life Insurance, Disability Insurance \nFinancial Benefits: ESPP; 401k; Student Loan Assistance; Tuition Reimbursement \nMental Health & Wellness: Free Mental Health & Enhanced Advocacy Services\nBeyond Benefits: Paid Time Off, Holidays, Preferred Partner Discounts and more. \nNot reflective of all benefits. Enrollment waiting periods or eligibility criteria may apply to certain benefits. Benefit details and offerings may vary for subsidiary entities or in specific geographic locations.\nRecruiting Vendor Disclosure Statement\nBrown & Brown does not accept unsolicited resumes from external recruiters, recruitment vendors or employment agencies (\"Recruiting Vendors\"). Recruiting Vendors must have a valid written agreement and received prior written authorization from an authorized Brown & Brown representative before submitting candidates for any publicly posted role. Any unsolicited resumes submitted to Brown & Brown or its employees become the property of Brown & Brown, and no fees will be paid for such submissions. Additional information regarding this policy can be found on our careers page.\nThe Power To Be Yourself\nAs an Equal Opportunity Employer, we are committed to fostering an inclusive environment comprised of people from all backgrounds, with a variety of experiences and perspectives, guided by our Diversity, Inclusion & Belonging (DIB) motto, “The Power to Be Yourself”.","description_format":"text","description_chars":5542,"description_truncated":false,"requirements":{"experience_years_min":7,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["401k plan","Life insurance"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Financial Services","Jewelry","Property & Casualty Insurance"],"lifecycle":[{"event":"open","at":"2026-09-26T16:45:48Z"},{"event":"close","at":"2026-09-28T21:42:54Z"}],"liveness":null,"pay":null,"html_url":"https://alion.io/job/bbrown-senior-security-analyst","json_url":"https://alion.io/job/bbrown-senior-security-analyst.json","meta":{"generated_at":"2026-09-29T02:19:54Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1996,"day_limit":5000,"remaining_today":3004,"minute_limit":60,"resets_at":"2026-09-30T00:00:00Z"}}}