IT Security Analyst at GovWorx
$120,000–$170,000
Jul 26, 2026
—
Jul 28, 2026
What this job asks for AI summary
This role is responsible for owning and continuously improving security operations at a SaaS company serving public safety agencies. Day-to-day work spans penetration testing, SIEM management, antivirus tooling, compliance framework maintenance (SOC2 Type 2, NIST, CJIS), vendor security assessments, and responding to security questionnaires and RFPs. It suits an experienced security analyst comfortable operating independently across both technical security work and compliance processes, with some exposure to AI system security considerations.
Senior level · 5+ years · Remote · Full-time
Quick apply — this platform usually takes a CV and a few fields.
“or” means any one of them counts — you don't need all of them.
Posted 2 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 6,100 people nationally plausibly meet what this posting asks for (information security analysts). range 2,550–9,100
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (6)
The posting requires US citizenship and passing an FBI fingerprint and background check in multiple states. This is not a traditional US government security clearance (no DoD/IC clearance level is named), so the clearance requirement is set to None — but candidates must be US citizens and pass the background check as a hard gate.
CJIS compliance is mentioned in the responsibilities narrative alongside SOC2/NIST/ISO but is not explicitly called out as a required qualification; it is listed as a preferred/nice-to-have area of experience given the public safety context.
LLMs appear only in the 'Why Join' section as context about the tech stack, not as a stated requirement or qualification.
'AI security' and 'experience using AI in workflows' are both listed as Must-Haves in the qualifications; AI security is captured as a required skill. 'Experience using AI in workflows' is a general practice rather than a named tool and is omitted per guidelines.
The role is remote-US with an optional hybrid arrangement in Denver, CO; the Denver CBSA is used as the anchor metro.
Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): third-party vendor security assessment, Business Continuity / Disaster Recovery.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.