Senior Security Analyst
Colabsoftware · United States, Remote · 2026-07-31
About this role
<h3><strong>About CoLab</strong></h3> <p>At CoLab, we help mechanical engineering teams bring life-changing products to market years sooner.</p> <p>We build AI for engineers designing cars, medical devices, and jet engines. Products this complex aren't sketched and sent to production. Teams spend months on iterations, reviews, and tests, predicting how every part performs before anything is built. CoLab is where those reviews happen, and we capture the rationale behind every change. Other tools show what changed between versions. Only CoLab knows why. That's how our AI helps manufacturers like Bobcat, Triumph Motorcycles, and GE Appliances make better decisions, eliminate rework cycles, and get to market faster.</p> <p>Proudly based in St. John’s, Newfoundland, CoLab started with one customer in 2018. Since then we’ve raised a<a href="https://financialpost.com/pmn/business-wire-news-releases-pmn/ai-is-changing-engineering-colab-just-raised-72m-to-lead-the-transformation"> $72M Series C</a>, been named the 57th fastest growing company in North America by Deloitte (<a href="https://financialpost.com/pmn/business-wire-news-releases-pmn/colab-ranked-number-57-fastest-growing-company-in-north-america-on-the-2025-deloitte-technology-fast-500">Fast 500™</a>), signed multi-year<a href="https://www.theglobeandmail.com/business/article-bombardier-signs-contract-colab-ai-software/"> AI partnerships with companies like Bombardier</a>, and grown to a team of 250+.</p> <h3><strong>About the Role&nbsp;</strong></h3> <p>Security at CoLab isn't a compliance exercise. It's a core part of earning and maintaining the trust of some of the world's largest engineering organizations.</p> <p>As a Senior Security Analyst, you'll help shape the future of our enterprise security program. You'll be a key member of our Blue Team, responsible for protecting CoLab's cloud infrastructure, corporate systems, and customer data while continuously improving how we detect, investigate, and respond to threats.</p> <p>This is a hands-on technical role reporting to our CISO. You'll spend time investigating alerts, leading incident response efforts, refining detection capabilities, improving security controls, and helping teams make sound security decisions before problems emerge.</p> <p>You won't be handed a mature playbook and asked to follow it. You'll help build it. If you enjoy solving complex security problems, taking ownership, and balancing strong technical judgment with practical business decisions, you'll likely find this role rewarding.</p> <h3><strong>Our Ideal Candidate</strong></h3> <p>You're the type of person who sees an alert and wants to understand the full story—not just close the ticket.</p> <p>You can move comfortably between technical investigation, risk discussions, and stakeholder communication. During an incident, you're calm, methodical, and focused on facts. Afterward, you're just as interested in improving systems and processes to prevent it from happening again.</p> <p>You'll thrive here if you enjoy:</p> <ul> <li>Solving difficult security problems with incomplete information</li> <li>Taking ownership of outcomes, not just tasks</li> <li>Learning continuously as technologies and threats evolve</li> <li>Working closely with Security, Technology, and Product teams</li> <li>Balancing strong security practices with business realities</li> </ul> <h3><strong>Job Responsibilities</strong></h3> <ul> <li>Lead investigation and response activities for security incidents, suspicious activity, and emerging threats</li> <li>Design, implement, and improve security monitoring, detection, and response capabilities across our AWS environment</li> <li>Develop and maintain effective detection rules, alerting strategies, and investigation procedures</li> <li>Conduct post-incident reviews to identify root causes, lessons learned, and preventative measures</li> <li>Identify security exposures, vulnerabilities, misconfigurations, and non-compliance risks and communicate recommendations clearly</li> <li>Perform security assessments of third-party vendors, services, and technologies</li> <li>Partner with Technology and Product teams to design secure solutions and strengthen existing controls</li> <li>Support vulnerability management, threat modeling, and endpoint security initiatives</li> <li>Create and maintain security documentation, standards, and operational procedures</li> <li>Contribute to security awareness efforts and provide guidance on secure business practices</li> <li>Stay current on evolving threats, attacker techniques, and defensive technologies</li> <li>Authorizes/approves user access to CoLab</li> <li>Coordinates with relevant CoLab AI teams for program functions wholly or partially implemented at the corporate level (i.e., general security training)</li> <li>Develops and maintains an accurate and up-to-date System Security Plan (SSP)Package for the FedRAMP-designated system</li> <li>Distributes copies of SSP Package elements to relevant team members, on a need-to-know basis</li> <li>Designates key personnel as responsible for core program functions (i.e., incident handling, disaster recovery, etc.)</li> <li>Receives operational alerts, updates, and status reports from team members and critical system components</li> <li>Oversees the Continuous Monitoring Program for…
Skills asked for
- aws
- cybersecurity
- linux
Similar jobs
- Senior Software Engineer - Security - ElasticsearchElastic · United States
- Senior Infrastructure Security EngineerMatter Labs · United States
- Senior Security ResearcherHuman · United States
- Senior Analyst, Security ComplianceKraken Com · United States
- Senior Security ArchitectAquia · United States
- Senior Offensive Security EngineerA3c41b8b71eff8c4 · United States
- Senior Security Compliance Analyst - Public Sector - Information SecurityElastic · United States
- Senior Application Security Engineer (Remote)Brex · United States
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.