remote

Salary
$120,000–$170,000
Posted
Jul 26, 2026
Location
Last confirmed open
Jul 28, 2026

What this job asks for AI summary

This role is responsible for owning and continuously improving security operations at a SaaS company serving public safety agencies. Day-to-day work spans penetration testing, SIEM management, antivirus tooling, compliance framework maintenance (SOC2 Type 2, NIST, CJIS), vendor security assessments, and responding to security questionnaires and RFPs. It suits an experienced security analyst comfortable operating independently across both technical security work and compliance processes, with some exposure to AI system security considerations.

Senior level · 5+ years · Remote · Full-time

Quick apply — this platform usually takes a CV and a few fields.

Must have (6)
penetration testingSIEMantivirusSOC2NIST or Iso 27001AI security
Nice to have (2)
CJISLLMs

“or” means any one of them counts — you don't need all of them.

Posted 2 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 6,100 people nationally plausibly meet what this posting asks for (information security analysts). range 2,550–9,100

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
SIEM55%antivirus40%NIST40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (6)

The posting requires US citizenship and passing an FBI fingerprint and background check in multiple states. This is not a traditional US government security clearance (no DoD/IC clearance level is named), so the clearance requirement is set to None — but candidates must be US citizens and pass the background check as a hard gate.

CJIS compliance is mentioned in the responsibilities narrative alongside SOC2/NIST/ISO but is not explicitly called out as a required qualification; it is listed as a preferred/nice-to-have area of experience given the public safety context.

LLMs appear only in the 'Why Join' section as context about the tech stack, not as a stated requirement or qualification.

'AI security' and 'experience using AI in workflows' are both listed as Must-Haves in the qualifications; AI security is captured as a required skill. 'Experience using AI in workflows' is a general practice rather than a named tool and is omitted per guidelines.

The role is remote-US with an optional hybrid arrangement in Denver, CO; the Denver CBSA is used as the anchor metro.

Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): third-party vendor security assessment, Business Continuity / Disaster Recovery.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗