{"id":1771031,"url":"https://alion.io/job/spacenexus-senior-security-analyst","title":"Senior Security Analyst","company":{"id":2086894,"name":"SpaceNexus","domain":"spacenexus.us","url":"https://alion.io/company/spacenexus","size_band":"1-10","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Schema","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Seattle, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":80000,"max":90000,"currency":"USD","period":"year","gross":null,"usd_annual":90000},"salary_estimate":null,"experience_years_min":7,"visa_sponsorship":false,"relocation_package":false,"has_equity":true,"technologies":[{"name":"AWS","optional":false},{"name":"CentOS Stream","optional":false},{"name":"CIS Benchmarks","optional":false},{"name":"EnCase","optional":false},{"name":"Linux","optional":false},{"name":"NIST 800-171","optional":false},{"name":"SIEM","optional":false},{"name":"Ubuntu","optional":false},{"name":"Windows","optional":false},{"name":"Active Directory","optional":true},{"name":"Amazon ECS","optional":true},{"name":"CloudFormation","optional":true},{"name":"Crowdstrike","optional":true},{"name":"Docker","optional":true},{"name":"JavaScript","optional":true},{"name":"Microsoft Entra ID","optional":true},{"name":"Nessus","optional":true},{"name":"Nomad","optional":true},{"name":"PowerShell","optional":true},{"name":"Python","optional":true},{"name":"Terraform","optional":true},{"name":"VMWare","optional":true}],"status":"live","first_seen_at":"2026-10-02T15:45:58Z","employer_posted_date":"2026-10-02","last_verified_at":"2026-10-07T00:20:27Z","board_verified":true,"closed_at":null,"days_open":4,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":4},"description":"Senior Security Analyst\nAbout Us:\nBlackSky is a real-time intelligence company. We own and operate the world's most advanced space-based intelligence platform and provide customers satellite imagery, automated analytics and high-frequency monitoring of strategic locations, economic assets and events from around the globe. BlackSky is trusted by the most demanding allied military and intelligence organizations and commercial companies to deliver foresight into critical matters that affect national security and the economy. BlackSky's data enables governments and businesses to see, understand and anticipate change as it happens, giving them the ultimate strategic advantage so they can act quickly. Our global team works with cutting-edge technology to make a difference around the world and prides itself on being people-first, customer-focused and fun.\nThe Senior Security Analyst position reports to the Manager of Security Analysis Team (i.e., Security Operations Center (SOC)) with rollup to the Director of Security and plays a vital role in monitoring, defending, and securing the BlackSky enterprise environment against cyber threats.\nYou will perform continuous monitoring of network, managed devices and identities, cloud services, business systems, and application traffic in support of BlackSky’s Security Operations Center (SOC). You will conduct analysis of these logs within an integrated Security Information and Event Management (SIEM) platform and work to develop novel searches, dashboards, and alerts to improve the SOC’s detection and response timelines. You will leverage cyber threat intelligence (CTI) reporting in conjunction with internal digital forensics and incident response (DFIR) activities to ensure BlackSky is properly positioned to defend against security threats to our enterprise networks.\nThe Security Team is geographically distributed across our Herndon, VA and Seattle, WA offices therefore the role can be based at either of these two locations, surrounding areas, or anywhere in the United States.\nResponsibilities:\nPerform security monitoring and digital forensics and incident response (DFIR) activities across corporate, product, and mission environments by reviewing events and alerting attributed to indicators of compromise (IOCs), indicators of attack (IOAs), cyber threat intelligence (CTI) reporting, and non-compliance activities\nReview multiple sources of cyber threat intelligence and apply the insights appropriately to inform and secure the enterprise\nConduct regular threat hunting across the corporate, product, and mission environments\nDocument procedures for performance of job duties to formalize ad-hoc processes\nConduct security analysis of data from many sources - system/event logs, network traffic, and SaaS security tools.\nPerform analysis, and digital forensics of potential malware using Industry standard Sandbox tools.\nSupport continuous monitoring of network, operating system, and application log traffic to identify potential security threats related to the industry.\nSupport vulnerability management process through identification and prioritization of critical security concerns in collaboration with IT or Product owners to drive vulnerability or misconfiguration remediation activities.\nWork with product owners to define offensive testing scope requirements and constraints and to support the remediation process on any identified vulnerabilities.\nMonitor operational systems for continuous compliance with hardened baseline images against industry checklists such as CIS Benchmarks and/or DISA STIGs,\nDevelop solutions to automate reoccurring tasks and improve adversary detection.\nComplete compliance assessments and report findings to management.\nDocument findings (anomalies, incidents, concerns) and share widely with security, IT, and product teams as appropriate to enable enhanced understanding of security posture.\nStrong Linux security background with Ubuntu, Amazon Linux, and/or CentOS preferred.\nSupport security training and manage tabletop scenarios to other employees\nSupport SOX/ITGC, CMMC 2.0 Level 2, NIST 800-171 r3, UK Cyber Essentials, and customer-specific compliance requirements.\nOther responsibilities as assigned.\nRequired Qualifications:\nA minimum of seven (7) years’ experience performing security analyst and DFIR activities.\nA minimum of seven (7) years’ experience in IT security.\nCandidates should hold at least one of the following security certifications:\nCertified Information Systems Security Professional (CISSP),\nGIAC Certified Incident Handler (GCIH),\nComputer Hacking Forensic Investigator (CHFI),\nGIAC Certified Forensic Examiner (GCFE),\nGIAC Certified Forensic Analyst (GCFA),\nGIAC Reverse Engineering Malware (GREM),\nGIAC Network Forensic Analyst (GNFA),\nGIAC Cloud Security Automation (GCSA),\nGIAC Cloud Penetration Tester (GCPN),\nGIAC Public Cloud Security (GPCS),\nGIAC Security Operations Certified (GSOC),\nGIAC Certified Detection Analyst (GCDA),\nAccess Data Certified Examiner (ACE), and/or\nEncase Certified Examiner (EnCE), AWS Certified Security - Specialty.\nAbility to document processes, procedures, and results of technical analysis for review by peers.\nExperience with implementing, troubleshooting, and sustaining endpoint security mechanisms (e.g., EDR, CASB, and others) in at least one of the following Operating Systems - Windows, MacOS, and/or Linux.\nExperience performing at least one of the following activities - Incident Response, Digital Forensics, Malware Analysis, Network Traffic Collection, or Reverse Engineering.\nMust be a U.S. Citizen.\nPreferred Qualifications:\nEndpoint Security for Windows, MacOS, and Linux environments.\nEnterprise Security Tools: Cisco Duo, Nessus, OpenSCAP, Crowdstrike XDR/MDR, ManageEngine, Cisco Umbrella, Active Directory / Entra ID, Netskope.\nExtensive incident response, security analysis, and digital forensics experience performing event log, PCAP, and NetFlow data analysis, malware analysis, and data collection.\nCloud Solutions: Microsoft GCC High, AWS Commercial, AWS GovCloud, VMware ESXi.\nInfrastructure as Code: AWS CloudFormation, HashiCorp Terraform.\nCoding & Scripting: Python, Java, JavaScript, BASH, PowerShell.\nKnowledge of Secure DevOps Processes.\nContainer Technologies: Docker, ECS, Nomad, HashiCorp product stack.\nLife at BlackSky for full-time US benefits eligible employees includes :\nMedical, dental, vision, disability, group term life and AD&D, voluntary life and AD&D insurance\nBlackSky pays 100% of employee-only premiums for medical, dental and vision and contributes $100/month for out-of-pocket expenses!\n15 days of PTO, 11 Company holidays, four Floating Holidays (pro-rated based on hire date), one day of paid volunteerism leave per year, parental leave and more\n401(k) pre-tax and Roth deferral options with employer match\nFlexible Spending Accounts\nEmployee Stock Purchase Program\nEmployee Assistance and Travel Assistance Programs\nEmployer matching donations\nProfessional development\nMac or PC? Your choice!\nAwesome swag\nThe anticipated base salary range for candidates in Seattle, WA and Herndon, VA is $80,000 - 90,000 per year. The final compensation package offered to a successful candidate will be dependent on specific background and education. BlackSky is a multi-state employer, and this pay scale may not reflect salary ranges in other states or locations outside of Seattle, WA.\nBlackSky is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity Employer. All Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, sexual orientation, gender identity, disability, protected veteran status or any other characteristic protected by law.\nTo conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.\nEEO/Pay Transparency Statements:\nhttps://www.dol.gov/ofccp/regs/compliance/posters/pdf/eeopost.pdf\nhttps://www.dol.gov/ofccp/regs/compliance/posters/pdf/OFCCP_EEO_Supplement_Final_JRF_QA_508c.pdf","description_format":"text","description_chars":8319,"description_truncated":false,"requirements":{"experience_years_min":7,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Parental leave","Professional development"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Space & Aerospace"],"lifecycle":[{"event":"open","at":"2026-10-03T15:32:03Z"}],"visa":[],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.857,"p_room":1,"age_days":3,"expected_fill_days":11,"reasons":["conf:6","velocity","win:early","comp:brand"],"computed_at":"2026-10-06T05:45:30Z"},"pay":{"stated_usd_annual":90000,"is_top_pay":false},"html_url":"https://alion.io/job/spacenexus-senior-security-analyst","json_url":"https://alion.io/job/spacenexus-senior-security-analyst.json","meta":{"generated_at":"2026-10-07T02:09:19Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3534,"day_limit":5000,"remaining_today":1466,"minute_limit":60,"resets_at":"2026-10-08T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":2086894},"rest":"https://alion.io/mcp/rest/get_company?id=2086894"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fspacenexus-senior-security-analyst"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fspacenexus-senior-security-analyst"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fspacenexus-senior-security-analyst"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/spacenexus-senior-security-analyst\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fspacenexus-senior-security-analyst"}]}