Senior Information Security Analyst - Compliance - InfoSec at Referral Board
$133,100–$210,600
Jul 30, 2026
—
Sep 24, 2026
What this job asks for AI summary
A Senior Information Security Analyst role within Elastic's Infosec organization, focused on leading and maturing the company's compliance and governance programs across a range of industry and regulatory frameworks. The position involves managing audits, owning the security awareness program, translating regulatory requirements into operational controls, and identifying opportunities to automate and modernize compliance workflows — including through AI-driven tooling. Suited to someone with hands-on experience running compliance certifications in cloud-native or SaaS environments.
Senior level · Remote · Full-time
Pay in the description: $133,100–$210,600
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 4,350 people nationally plausibly meet what this posting asks for (information security analysts). range 1,250–6,500
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 1, 2026. It is a model, not a headcount.
Why we read it this way (5)
The posting lists a standard national salary range of $133,100–$210,600 USD and a higher alternate range of $159,900–$252,900 USD for select metros (Seattle WA, Los Angeles CA, San Francisco Bay Area CA, and New York City Metro Area). The figures reported here reflect the national range.
No specific total years of experience are stated; seniority is inferred from the 'Senior' title and the scope of responsibilities described.
The compliance frameworks (SOC 2, ISO 27001, PCI DSS, FedRAMP, TISAX, Cyber Essentials Plus) are listed under the 'What You Bring' requirements section as experience the candidate must have in 'some combination of' — meaning not every framework is individually mandatory, but collectively they gate the role. They are marked required as a group consistent with their placement in the requirements block.
Experience evaluating or adopting AI technologies for compliance/governance purposes appears in the 'What You Bring' section but is framed descriptively rather than with firm gating language, so it is treated as a supporting requirement rather than a hard gate.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): AI governance.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.