64 security analyst jobs at 49 companies in Petaluma, CA
6d
Save
Mark Applied
Hide
6d
Security Analyst
San Francisco, California, United States
$144k-$162k/yrHybridFull Time
Discord: A platform providing voice, video, and text communication services.
4+ YOE4+ years in security compliance/GRC or related fields; familiarity with ISO 27001/27002,SOC 2,PCI DSS,GDPR/CPRA; hands-on compliance processes; automation-first mindset; strong writing and cross-team collaboration skills.
ISO 27001, ISO 27002, SOC 2, PCI DSS, GDPR, CPRA, GRC platform, ticketing, docs and wikis
Nscale: Vertically integrated AI infrastructure provider for high-performance computing.
3+ YOE3+ years in security operations or related roles; experience investigating endpoint, identity, SaaS, cloud, email, network telemetry; strong incident response and writing skills; comfortable with query languages, logs, dashboards, and case management.
Neumo: Provides integrated software and payment solutions for government agencies.
2+ YOE2–4 years in cybersecurity with SOC, vulnerability management, and incident response experience; bachelor’s preferred; equivalent work experience considered.
SIEM, EDR, Vulnerability Scanning, Cloud Security, PowerShell, Python, Microsoft Defender for Endpoint, Tenable, Microsoft Sentinel, Azure, AWS
United States or San Francisco or Washington or New York City or Seattle
$112k-$168k/yrRemoteFull Time
RubrikNYSE: RBRK: Secures enterprise data across cloud and on-premises environments.
3+ YOEBachelor's or equivalent experience, 3+ years SOC experience with incident response, familiarity with SIEM/EDR and cloud security (Azure Defender, Google SCC, AWS GuardDuty), strong communication and analytical skills.
SIEM, EDR, Azure Defender, Google Security Command Center, AWS GuardDuty, AWS, Azure, GCP
New York City or Seattle or Raleigh or San Francisco or Washington or London or Amsterdam
$134k-$214k/yrHybridFull Time
Plaid: Provides financial data connectivity and payment infrastructure via APIs.
6+ YOE6+ years in security assurance/GRC with ownership of customer-facing security workflows; experience reviewing security contract provisions; familiarity with SOC 2, ISO 27001, NIST frameworks, PCI, GLBA, GDPR/CCPA; program design, metrics ownership, and AI-assisted workflow experience.
Rippling: Unified platform managing workforce HR, IT, and finance operations
5+ YOE5+ years in security compliance, strong communication, experience with ISO 27001 and SOC 2, cloud security best practices, vendor due diligence, and information security policy development.
Boston or Austin or Washington or Seattle or San Francisco
$120k-$155k/yrRemoteFull Time
HackerOne: Connecting organizations with ethical hackers to find security vulnerabilities.
3+ YOE3+ years security testing/vulnerability research on web/mobile apps, strong OWASP Top 10 knowledge, experience with Burp Suite and CVSS, ability to reproduce/validate findings and communicate technical impact in English.
Burp Suite, Common Vulnerability Scoring System (CVSS)
RobloxNYSE: RBLX: Platform for creating and playing user-generated 3D digital experiences.
4+ YOE4+ years GRC experience, risk assessment and policy development, ability to work with engineers, knowledge of compliance frameworks and security controls.
Factor Analysis of Information Risk (FAIR), Roblox Studio
IT Security Analyst (5353C), Information Security Office #87490
Berkeley, California, United States
$92k-$120k/yrOnsiteFull Time
University of California, Davis: Public research university offering undergraduate and graduate education.
Experience with enterprise security logs, IDS/IPS, firewalls, SIEM, Linux (Redhat Enterprise Linux), automation with Ansible/Terraform, scripting, and incident response; bachelor's degree or equivalent.
IT Security Analyst (5353C), Information Security Office #87490
Berkeley, California, United States
$92k-$120k/yrOnsiteFull Time
University of California, Berkeley: Public research university offering undergraduate and graduate education.
Experience administering security systems (IDS/IPS, SIEM, EDR, scanners), reading logs, Linux (Red Hat Enterprise Linux), automation with Ansible/Terraform, scripting, and bachelor's degree or equivalent.
SIEM, IDS/IPS, EDR, Vulnerability Scanners, Red Hat Enterprise Linux, Ansible, Terraform, Kafka, Elasticsearch, Ruby, Python, Go, Logstash, Kibana, Elastic Security
Peregrine Technical Solutions: Federal government contractor providing IT and cybersecurity professional services.
5+ YOE5+ years relevant experience, DoD RMF knowledge, IAO/ISSO or IAM/ISSM experience, DoD 8570 certifications (CISSP, GSLC or equivalent), eligible for Public Trust, proficient with eMASS, ACAS, SCAP tools and Microsoft Office.
eMASS, ACAS, Security Content Automation Protocol (SCAP), SCAP Compliance Checker, Microsoft Excel, Microsoft Word, Microsoft PowerPoint, Microsoft Outlook, Microsoft Visio, Microsoft Access
Goldbelt: Provides government contracting, tourism operations, and marine transportation services.
5+ YOE5+ years relevant experience with DoD RMF, IAO/ISSO or IAM/ISSM background; DoD 8570.01 certification (CISSP, GSLC or equivalent); eligible for federal Public Trust; proficient with eMASS, ACAS, SCAP tools and Microsoft Office.
eMASS, Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol (SCAP) Compliance Checker, Microsoft Excel, Microsoft Word, Microsoft PowerPoint, Microsoft Outlook, Microsoft Visio, Microsoft Access
Goldbelt: Alaska Native providing government contracting and technology solutions.
5+ YOE5+ years relevant experience; detailed knowledge of DoD RMF; IAO/ISSO or IAM/ISSM experience; DoD 8570.01 certifications (CISSP, GSLC) or equivalent; eligible for Public Trust; strong communication, leadership, and MS Office skills.
Microsoft Excel, Microsoft Word, Microsoft PowerPoint, Microsoft Outlook, Microsoft Visio, Microsoft Access, eMASS, ACAS, Security Content Automation Protocol (SCAP) Compliance Checker, CDS
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
2+ YOE2–4 years GRC/compliance/audit or information security experience; working knowledge of at least two of SOC 2, HIPAA, ISO 27001, or GxP; proficiency with GRC/audit tools and Microsoft Office or Google Workspace; strong communication skills.
SOC 2, HIPAA, ISO 27001, GxP, Microsoft Office Suite, Google Workspace, Drata, Vanta, OneTrust, ServiceNow GRC
Information Security Operations Analyst (0661U), Berkeley IT - #87198
Berkeley, California, United States
$112k-$163k/yrOnsiteFull Time
University of California: Operates public universities, research centers, and medical systems.
5+ YOEMinimum 5 years general IT experience; 3+ years security operations preferred. Strong knowledge of EDR, SIEM, IDS/IPS, vulnerability scanning, cloud security, incident response, security frameworks (NIST, CIS). Strong communication and leadership.
firewalls, Network TAPs, Intrusion detection/prevention systems (IDS/IPS), Endpoint Detection and Remediation (EDR), Security Information and Event Management (SIEM), Network IDS, Cloud Security Posture Management, NIST, CIS, CSA, MITRE ATT&CK, SaaS, IaaS, PaaS
St. Petersburg or Rancho Cordova or Fort Lauderdale or New York or San Mateo
$116k-$158k/yrHybridFull Time
Franklin TempletonNYSE: BEN: Global investment firm providing asset and wealth management services.
3+ YOE3+ years industry experience supporting Microsoft 365 Purview and compliance archiving; PowerShell/automation experience; knowledge of FINRA/regulatory retention; strong communication and documentation skills.
Microsoft 365 Purview Compliance Portal, Microsoft 365, PowerShell, Azure Automation Runbook, Logic App, Outlook/Exchange Online, SharePoint, Microsoft Teams, ServiceNow, PowerPoint, Confluence, Microsoft Visio
Crisis24: Integrated risk management and global crisis response solutions.
OSINT-focused intelligence analyst with security and geopolitical knowledge, strong writing/briefing, investigative skills, and ability to work hybrid at client HQ.
Anthropic: Developing safe and reliable artificial intelligence systems.
Experience running end-to-end third-party/vendor risk assessments at a technology company; knowledge of risk fundamentals; ability to assess security, privacy, compliance, and operational risk; experience with LLM-backed workflows and procurement/GRC platforms.