Senior Security Analyst
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
The Senior Security Analyst position reports to the Manager of Security Analysis Team (Security Operations Center, SOC) with rollup to the Director of Security and plays a vital role in monitoring, defending, and securing the BlackSky enterprise environment against cyber threats.
You will perform continuous monitoring of network, managed devices and identities, cloud services, business systems, and application traffic in support of BlackSky’s Security Operations Center (SOC). You will conduct analysis of these logs within an integrated Security Information and Event Management (SIEM) platform and work to develop novel searches, dashboards, and alerts to improve the SOC’s detection and response timelines. You will leverage cyber threat intelligence (CTI) reporting in conjunction with internal digital forensics and incident response (DFIR) activities to ensure BlackSky is properly positioned to defend against security threats to our enterprise networks.
The Security Team is geographically distributed across our Herndon, VA and Seattle, WA offices therefore the role can be based at either of these two locations, surrounding areas, or anywhere in the United States.
Responsibilities:
- Perform security monitoring and digital forensics and incident response (DFIR) activities across corporate, product, and mission environments by reviewing events and alerting attributed to indicators of compromise (IOCs), indicators of attack (IOAs), cyber threat intelligence (CTI) reporting, and non-compliance activities.
- Review multiple sources of cyber threat intelligence and apply the insights appropriately to inform and secure the enterprise.
- Conduct regular threat hunting across the corporate, product, and mission environments.
- Document procedures for performance of job duties to formalize ad-hoc processes.
- Conduct security analysis of data from many sources - system/event logs, network traffic, and SaaS security tools.
- Perform analysis and digital forensics of potential malware using industry standard sandbox tools.
- Support continuous monitoring of network, operating system, and application log traffic to identify potential security threats related to the industry.
- Support vulnerability management process through identification and prioritization of critical security concerns in collaboration with IT or Product owners to drive vulnerability or misconfiguration remediation activities.
- Work with product owners to define offensive testing scope requirements and constraints and to support the remediation process on any identified vulnerabilities.
- Monitor operational systems for continuous compliance with hardened baseline images against industry checklists such as CIS Benchmarks and/or DISA STIGs.
- Develop solutions to automate recurring tasks and improve adversary detection.
- Complete compliance assessments and report findings to management.
- Document findings (anomalies, incidents, concerns) and share widely with security, IT, and product teams as appropriate to enable enhanced understanding of security posture.
- Strong Linux security background with Ubuntu, Amazon Linux, and/or CentOS preferred.
- Support security training and manage tabletop scenarios to other employees.
- Support SOX/ITGC, CMMC 2.0 Level 2, NIST 800-171 r3, UK Cyber Essentials, and customer-specific compliance requirements.
- Other responsibilities as assigned.
Required Qualifications:
- A minimum of seven (7) years’ experience performing security analyst and DFIR activities.
- A minimum of seven (7) years’ experience in IT security.
- Candidates should hold at least one of the following security certifications: Certified Information Systems Security Professional (CISSP), GIAC Certified Incident Handler (GCIH), Computer Hacking Forensic Investigator (CHFI), GIAC Certified Forensic Examiner (GCFE), GIAC Certified Forensic Analyst (GCFA), GIAC Reverse Engineering Malware (GREM), GIAC Network Forensic Analyst (GNFA), GIAC Cloud Security Automation (GCSA), GIAC Cloud Penetration Tester (GCPN), GIAC Public Cloud Security (GPCS), GIAC Security Operations Certified (GSOC), GIAC Certified Detection Analyst (GCDA), Access Data Certified Examiner (ACE), Encase Certified Examiner (EnCE), AWS Certified Security - Specialty.
- Ability to document processes, procedures, and results of technical analysis for review by peers.
- Experience with implementing, troubleshooting, and sustaining endpoint security mechanisms (e.g., EDR, CASB) in at least one of the following Operating Systems: Windows, MacOS, and/or Linux.
- Experience performing at least one of the following activities: Incident Response, Digital Forensics, Malware Analysis, Network Traffic Collection, or Reverse Engineering.
- Must be a U.S. Citizen.
Preferred Qualifications:
- Endpoint Security for Windows, MacOS, and Linux environments.
- Experience with Enterprise Security Tools: Cisco Duo, Nessus, OpenSCAP, Crowdstrike XDR/MDR, ManageEngine, Cisco Umbrella, Active Directory / Entra ID, Netskope.
- Extensive incident response, security analysis, and digital forensics experience performing event log, PCAP, and NetFlow data analysis, malware analysis, and data collection.
- Cloud Solutions: Microsoft GCC High, AWS Commercial, AWS GovCloud, VMware ESXi.
- Infrastructure as Code: AWS CloudFormation, HashiCorp Terraform.
- Coding & Scripting: Python, Java, JavaScript, BASH, PowerShell.
- Knowledge of Secure DevOps Processes.
- Container Technologies: Docker, ECS, Nomad, HashiCorp product stack.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
Train and Evaluate AI Agents in CAD Environments (Freelance)
Mindrift
United StatesTrain and Evaluate AI Agents in CAD Environments (Freelance)
Mindrift
United StatesSenior Engineer – DoD/U.S. Navy Energetics Facility Design and Construction
Eastern Research Group
United StatesSecurity Operations Specialist
HiddenLayer
United StatesMore Openings at BlackSky
Explore Top Companies in this Space
AST SpaceMobile
Aerospace & Satellite Telecom / Direct-to-Cell Infrastructure / SpaceTech & NTN SaaS / Global Wireless Connectivity
LeoLabs
Aerospace / SpaceTech / Data Analytics
BlueFlag Security
Enterprise Software / Cybersecurity / Developer Tools / AI Governance
Meds.com
Healthcare / Consumer Technology / Pharmaceuticals / Digital Health
BlackSky
View Company ProfileBlackSky is the premier, enterprise-grade real-time geospatial intelligence pioneer, high-revisit satellite constellation operator, and AI-driven tactical monitoring architect engineered to operate as the definitive, high-velocity space observation and situational awareness layer for global defense forces, national security agencies, and commercial enterprises worldwide. The company completely eliminates the severe systemic friction of traditional satellite imagery—where intelligence cells face multi-day imaging delays, slow manual analyst data pipeline bottlenecks, and rigid legacy tasking mechanics—by deploying an advanced, low-latency smallsat swarm. Moving far beyond traditional, passive Earth observation maps or slow aerospace registries, BlackSky natively unifies high-frequency dawn-to-dusk satellite imaging loops, fully automated programmatic constellation tasking via software, dynamic AI-powered object detection and pattern-of-life telemetry, and open-source intelligence (OSINT) data streams into its flagship cloud workspace, Spectra® AI. Publicly traded on the New York Stock Exchange (NYSE: BKSY), the platform empowers strategic operators to task a satellite and receive high-resolution imagery along with deep analytical assessments in under 90 minutes with production-hardened precision. Under the hood, its sophisticated technical core natively orchestrates automated multi-sensor data fusion nodes, orbital mechanics optimization models, and rapid cloud-to-edge distribution pipelines to manage massive geospatial intelligence architectures. What sets BlackSky apart is its uncompromising dedication to replacing static, historical imaging with absolute real-time tactical momentum; by bridging the gap between performance-intensive aerospace hardware and immediate, actionable on-the-ground visual intelligence, the firm remains the definitive cornerstone of modern space superiority and automated global event monitoring.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.
