Senior Security Analyst

Abby Care•San Francisco, CA
•$130,000 - $165,000•Hybrid

About The Position

Abby Care is seeking a Senior Security Analyst to enhance its security operations, threat detection, and risk management program. This role, reporting to the Director of IT, Information & Security, will be responsible for incident response, vulnerability management, and security monitoring across cloud, endpoint, and identity infrastructure. The position involves mentoring junior analysts and driving continuous improvement of the security posture. The ideal candidate will possess an attacker's mindset, strong communication skills, and the ability to translate alerts into actionable insights. This is a Full-Time Hybrid opportunity based in San Francisco, CA.

Requirements

  • 8+ years of experience in security operations, leading incident response end-to-end from detection through remediation.
  • Associate’s or Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent practical experience
  • Hands-on experience with SIEMs, EDR/XDR (e.g., SentinelOne), vulnerability scanners, cloud security, and core IAM concepts (SSO, MFA, RBAC).
  • Working knowledge of security frameworks (SOC 2, ISO 27001, NIST, CIS) with strong analytical skills to translate technical risk to business stakeholders.
  • Familiarity with emerging AI/LLM risks and an interest in evaluating AI capabilities for security use cases.
  • Excellent communication skills with the ability to prioritize competing incidents and operate calmly under pressure.

Nice To Haves

  • Hands-on experience with Okta, JAMF, or Google Workspace, alongside Infrastructure as Code (Terraform) for access/security policy management.
  • Scripting experience (Python, Bash), SOAR exposure, and familiarity with CSPM tools or native cloud security platforms (AWS/GCP/Azure).
  • Practical experience securing AI/ML pipelines and GenAI deployments, or operating AI-driven security tools.
  • Relevant credentials such as CISSP, GCIH, GCIA, OSCP, or Security+.

Responsibilities

  • Lead end-to-end incident response, threat hunting, and root cause analysis across SIEM, EDR (SentinelOne), and cloud security tooling.
  • Develop and maintain incident response playbooks, runbooks, and tabletop exercises.
  • Own the vulnerability management lifecycle, partnering with IT and Engineering to remediate scan, pen test, and audit findings.
  • Maintain the risk register, conduct third-party/vendor risk assessments, and communicate technical risks to business stakeholders.
  • Partner with IT to audit and enforce security controls across Okta (RBAC/MFA), Google Workspace (DLP/logs), JAMF, and SentinelOne.
  • Drive evidence collection and remediation for compliance audits (SOC 2, ISO 27001, HIPAA, PCI DSS) while aligning policies with NIST CSF and CIS frameworks.
  • Automate detection, response, and reporting workflows via SOAR, scripting, and APIs to improve alert quality and efficiency.
  • Mentor team members and contribute to cross-functional security knowledge sharing.
  • Establish guardrails and acceptable-use policies for enterprise AI tools (e.g., GenAI, Claude), mitigating shadow AI, data leakage, and third-party vendor risks alongside IT, Legal, and Compliance.
  • Partner with Product and Engineering to assess and remediate AI/LLM-specific vulnerabilities, including prompt injection, model abuse, and data exposure.
  • Pilot and evaluate AI-powered security capabilities (e.g., AI-assisted SIEM/EDR triage and anomaly detection) to boost response speed and operational efficiency.

Benefits

  • Competitive compensation packages
  • Comprehensive health coverage (medical, dental, vision)
  • Generous paid time off
  • 10 paid company holidays
  • Financial savings benefits (HSA contributions, optional FSA and commuter benefits)
  • Full coverage of all 401(k) account fees
  • Paid parental leave (up to 10 weeks based on tenure)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service