Information Security Analyst III

AllegiantMinneapolis, MN
Onsite

About The Position

An individual contributor that serves as a senior individual contributor on the cybersecurity operations team, responsible for the day-to-day operation, tuning, and continuous improvement of the enterprise cybersecurity toolset. This role owns advanced detection and response work across endpoint, identity, application and cloud surfaces; leads investigations of escalated alerts; builds automation that removes manual effort from repeatable security tasks; and translates threat intelligence and vulnerability data into prioritized, actionable remediation for platform and application owners.

Requirements

  • Bachelor's degree in Computer Science, Software Engineering or related field or equivalent combination of education and experience.
  • Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Offensive Security Certified Professional (OSCP), or any related industry certifications.
  • Minimum six (6) years of experience in information security.
  • Minimum two (2) years of project or team lead experience.
  • Must be authorized to work in the US as defined by the Immigration Act of 1986.
  • Must pass a Criminal Background Check.
  • Valid/Unexpired Passport Book: Yes
  • Valid/Unexpired Driver's License: Yes

Nice To Haves

  • Master's degree in Computer Science or relevant field.
  • Eight (8) or more years of cybersecurity experience, including time in a security operations center or incident response function.
  • Industry certification such as CISSP, GCIH, GCIA, GCFA, GSEC, CySA+, or vendor certification in EDR, SIEM, identity, or cloud security.
  • Experience building security automation and orchestration playbooks that integrate multiple tools through APIs.
  • Experience operating a threat intelligence program, including managing intelligence feeds, tracking threat actors relevant to the industry, and producing intelligence-driven detections.
  • Experience with detection-as-code practices: version control, peer review, and CI/CD pipelines for detection and automation content.
  • Experience integrating SAST, DAST, software composition analysis (SCA), and secrets scanning into CI/CD pipelines, including quality gates and build-breaking policy.
  • Experience with interactive application security testing (IAST), runtime application self-protection (RASP), API security testing, or bot and fraud mitigation capabilities layered with a WAF.
  • Secure code review ability in one or more languages used for web and API development, and familiarity with threat modeling for new features and services.
  • Experience with PCI DSS requirements applicable to public-facing web applications, including WAF or equivalent control requirements and application penetration testing obligations.
  • Cloud security experience in a major public cloud provider, including native logging and identity services.
  • Familiarity with identity threat detection and response concepts, including privileged access management and detection of identity-based attack techniques.
  • Experience in a regulated environment subject to requirements such as PCI DSS, SOX, or aviation-sector regulatory oversight.
  • Experience supporting operational technology or specialized business systems in addition to corporate IT.
  • Experience mentoring analysts, developing runbooks, and leading tabletop or purple team exercises.

Responsibilities

  • Operate and tune the enterprise EDR platform; investigate escalated detections, perform host triage and containment, and drive eradication and recovery actions.
  • Develop and maintain custom detections, exclusions, and response policies; validate coverage against known attacker techniques.
  • Monitor agent health and deployment coverage across the endpoint and server estate and work with platform teams to close gaps.
  • Design, build, test, and maintain automation and orchestration playbooks that reduce manual analyst effort in triage, enrichment, containment, and reporting.
  • Integrate security tools through APIs to move context automatically between detection, ticketing, identity, and asset systems.
  • Maintain automation content in version control with peer review; measure and report time saved and error reduction.
  • Develop, tune, and maintain correlation rules, use cases, dashboards, and alerts in the SIEM; reduce false positives while preserving detection coverage.
  • Onboard new log sources, validate parsing and field normalization, and confirm data completeness and retention against monitoring and compliance requirements.
  • Perform threat hunting and historical analysis across aggregated log data to identify activity that automated detections missed.
  • Consume, evaluate, and operationalize intelligence from commercial feeds, open sources, industry sharing groups, and government partners; convert relevant intelligence into detections, hunts, and blocking decisions.
  • Track threat actors, campaigns, and techniques targeting the aviation, travel, hospitality, and payment sectors and brief stakeholders on relevance and recommended action.
  • Produce concise written intelligence summaries for technical teams and leadership.
  • Operate scanning and assessment capabilities across endpoints, servers, cloud workloads, containers, and network devices; validate findings and eliminate false positives.
  • Prioritize vulnerabilities using severity, exploitability, threat intelligence, asset criticality, and exposure; partner with system owners to define remediation plans and track them to closure.
  • Report on remediation performance against defined service levels and escalate aging or high-risk exposures through the established risk process.
  • Operate the static analysis platform: onboard repositories, configure language and framework coverage, tune rulesets, and maintain baselines for legacy code.
  • Integrate static scanning into developer workflows and CI/CD pipelines; define and administer quality gates and policy thresholds in partnership with engineering.
  • Triage static findings to remove false positives, confirm exploitable issues, and provide developers with specific, code-level remediation guidance and secure coding patterns.
  • Support software composition analysis and secrets detection for third-party libraries, open-source dependencies, and credential leakage in source repositories.
  • Plan, schedule, and execute dynamic scans against web applications and APIs across pre-production and production environments, including authenticated scanning and API-definition-driven testing.
  • Validate and reproduce dynamic findings, assess real-world exploitability and business impact, and route prioritized results into the remediation and risk-tracking process.
  • Support and help scope third-party penetration tests and application assessments, and track resulting findings to closure.
  • Operate and tune the web application firewall protecting customer-facing and internal web applications and APIs: managed rule sets, custom rules, rate limiting, geo and reputation controls, and bot mitigation.
  • Move new rules through detection only to blocking mode using traffic analysis, minimizing false positives, and avoiding disruption to legitimate customer traffic.
  • Monitor and investigate WAF telemetry and blocked-event trends; correlate WAF logs into the SIEM and build detections for application-layer attack patterns, credential stuffing, scraping, and abuse.
  • Support onboarding new applications and domains behind the WAF, including policy design, exclusion management, and validation testing with application teams.
  • Maintain WAF configuration documentation and evidence supporting applicable regulatory and payment-industry control requirements.
  • Support and maintain SSO integrations for enterprise and third-party applications, including federation configuration, application onboarding, and access policy design.
  • Configure and tune multifactor authentication, conditional access, and identity risk policies; investigate identity-based alerts such as impossible travel, MFA fatigue, token theft, and privilege escalation.
  • Monitor privileged and service accounts, review access anomalies, and support access certification and least-privilege initiatives with the identity and access management team.
  • Act as an escalation point for security incidents; lead or support investigation, evidence preservation, containment, and post-incident documentation and lessons learned.
  • Maintain runbooks, detection documentation, and operational procedures; contribute to tabletop and purple team exercises.
  • Mentor junior analysts on investigative techniques, tooling, and quality of documentation.
  • Support audit, assessment, and regulatory evidence requests related to security monitoring, vulnerability management, and access controls.
  • Handle sensitive data — including payment, personal, and crew or employee data — in accordance with company policy and applicable regulatory requirements.
  • Clear written and verbal communication skills, including the ability to document investigative findings for both technical and non-technical audiences.
  • Ability to participate in an on-call rotation and respond to security events outside normal business hours.
  • Other duties as assigned.

Benefits

  • Profit Sharing
  • Medical/Dental/Vision/Life/ Disability Insurance
  • Medical Travel Reimbursement
  • Legal, Identity and Pet Insurance
  • 401K with an employer match
  • Employee Stock Purchase Plan
  • Employee Assistance Program
  • Tuition Reimbursement
  • Flight Benefits
  • Paid vacation, holidays, and sick time
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service