Senior Security Analyst
Bozeman, MT - USA
Job Summary
Were a team of builders adventurers and risk takers using technology to help people confidently explore the outdoors. Driven by our mission to awaken the adventurer inside everyone we build products that optimize every outdoor experience and inspire confidence to get out and go further.
Were a high-growth tech company. The pace is fast the work takes grit and ambiguity is part of the job. As the world changes around us we adapt - continuously evolving how we build prioritize and deliver.
Our business moves quickly and theres real opportunity to shape what we build next. Each of our verticals - Hunt Offroad Backcountry and Fish - is at a different stage of maturity which means the challenges you encounter and the impact you have will vary depending on where you sit and what the business needs most.
We operate with an experimentation mindset continually iterating and improving how we solve problems. We expect our people to use the latest tooling including AI thoughtfully and responsibly pairing human judgment with technology to increase quality speed and impact.
Our impact comes to life through the products we build in the stories of our customers and in our growing commitment to land stewardship and recreational access.
onX is seeking a Senior Security Analyst I with a passion for protecting the systems data and customers that make onXs products possible. As an onX Senior Security Analyst I you will serve as the teams subject matter expert on day-to-day security operations incident response and application and vendor security. Your focus will be on security monitoring and detection incident response execution and application security testing with a supporting role in compliance activities such as SOC 2 evidence collection. This role also partners closely with the onX Site Reliability Engineering (SRE) team so a working understanding of Google Cloud Platform (GCP) is important to day-to-day work. onX views artificial intelligence (AI) as a powerful tool for strengthening security work not something to fear and this role should bring that same mindset.
This is a hands-on role: onX cannot do this work by hand at scale so you will build the automations and tools needed to reduce manual effort across compliance evidence collection application audits and monitoring. You will also need to see your job as educating the company not bubble-wrapping it and finding secure solutions that let the business move and flex rather than defaulting to blanket restrictions. You will work closely with the Director of IT and Security providing expert recommendations and executing approved plans rather than operating independently. This is a great opportunity to be a part of a dynamic growing company focused on making an impact on the business and to help mature a growing security program. This role will serve as the senior technical expert within the Security function at onX. This position will report to the Director of IT and Security.
Essential Job Duties & Functions
- Serve as the teams subject matter expert on the SIEM/EDR platform (SentinelOne) recommending tuning changes and detection coverage improvements.
- Analyze complex attack vectors deconstructing adversary behavior and applying threat intelligence to improve detection.
- Maintain threat models and vulnerability lifecycle metrics across the environment.
- Partner with the onX Site Reliability Engineering (SRE) team on cloud security monitoring and detection within Google Cloud Platform (GCP) including visibility into infrastructure logging IAM configuration and workload security.
- Execute the incident response playbook making frontline judgment calls during incidents and escalating major incidents to the Director of IT and Security.
- Facilitate incident response tabletop exercises and simulations with cross-functional stakeholders to test and improve readiness.
- Partner with the SRE team during incidents that touch cloud infrastructure ensuring security and reliability response efforts stay aligned.
- Lead post-incident analysis and recommend improvements to the playbook based on lessons learned.
- Run recurring security audits of business applications with full coverage of Tier 0 systems.
- Serve as the subject matter expert on the annual third-party penetration test including mobile application testing API endpoint testing and phishing simulations and coordinate remediation with product and engineering teams.
- Conduct vendor security assessments and maintain a recurring re-assessment cadence for Tier 0 and Tier 1 vendors.
- Collaborate with engineering teams to help design and build secure products throughout the development lifecycle.
- Support SOC 2 Type 2 compliance by gathering evidence and responding to auditor requests.
- Maintain SOC 2 automation tooling (Sprinto) to keep ongoing compliance overhead low.
- Help maintain security policies procedures and Information Security Management System (ISMS) documentation.
- Partner with the IT and Security manager to prioritize risk reduction efforts across the security program providing subject matter expertise to inform decisions.
- Recommend frameworks for risk quantification and incident response automation for the team to review and approve.
- Build automations and tools that reduce manual effort across the security program including compliance evidence collection application audits and SIEM/EDR maintenance.
- Identify and build automations that reduce manual security operations work including identity and access management (IAM) lifecycle tasks.
- Explore and pilot AI-assisted approaches to security operations tasks such as alert triage log analysis and reporting and share findings with the team.
- Evaluate business requests and risk trade-offs to find secure workable solutions that let teams move quickly rather than defaulting to blanket restrictions.
- Mentor other members of the security team.
- Other ad hoc duties as assigned by the Supervisor
- 7 or more years of experience in security operations incident response or a related security role
- Demonstrated experience tuning and operating SIEM and endpoint detection and response (EDR) platforms
- Experience leading incident response including major incident judgment calls and post-incident analysis
- Working knowledge of vulnerability management and application security testing concepts
- Clear written and verbal communication skills including the ability to align leadership and stakeholders on risk
- Ability to work independently set standards and prioritize across monitoring incident response and cross-functional projects
- Working knowledge of Google Cloud Platform (GCP) including IAM logging and core infrastructure services
- Ability to partner effectively with Infrastructure and engineering teams on cloud and application security matters
- Uses artificial intelligence (AI) tools as a force multiplier for security work and brings a curious hands-on approach to using AI rather than treating it as a threat to be avoided
- Demonstrated experience building scripts automations or tools that reduce manual work for example in compliance evidence collection audit workflows or alert triage
- Sound judgment in weighing security risk against business need with a track record of finding secure solutions that let the business move forward rather than defaulting to blanket restrictions
Though not required we would be thrilled to consider candidates with any of the following:
- Direct experience with SentinelOne or a comparable EDR platform
- Experience with SOC 2 or a similar compliance framework
- Experience with GRC automation tools such as Sprinto
- Familiarity with mobile application and API security testing
- Experience with workflow automation tools such as Workato
- Proficiency with a scripting language (such as Python) for building automations and tools
- Relevant industry certification such as GSEC GCIH or CISSP
- Google Cloud Platform (GCP) and AWS certification such as Associate Cloud Engineer or Professional Cloud Security Engineer
- Experience mentoring or informally leading other security team members
onX is a distributed company with more than 400 employees across the country. We come together regularly to work in person and stay connected through regional basecamps and a culture that balances individual ownership with deep collaboration.
While we move quickly were not a scrappy start-up. We operate with clear goals structure and frameworks that guide how we prioritize and execute. Priorities matter. While they may shift data shapes how we evolve as our business products and the world around us change.
Clear priorities and structure dont limit ownership - they make it possible. Youll have the autonomy to define your work and make meaningful decisions within clear strategic boundaries. Youll partner closely with others to solve complex problems and build solutions that scale across teams and platforms. Along the way youll be supported with feedback tools and opportunities to grow your craft as you take on new challenges.
This job must be performed onsite in our Bozeman MT office.
onX is committed to compensating all employees fairly and equitably for their contributions. For this position applicants can expect to make between 136000 and 170000 upon hire. The pay range will vary based upon experience skills certifications education among other factors as required in the job addition full-time onX employees are eligible for a grant of common share options with a vesting schedule and an annual bonus of 10% based on company performance.
- Competitive salaries annual bonuses equity and opportunities for growth
- Comprehensive health benefits including a no-monthly-cost medical plan
- Paid parental leave of 13 weeks for birthing parents and 5 weeks for non-birthing parents
- 401k matching at 100% for the first 3% you save and 50% from 3-5%
- Company-wide outdoor adventures and amazing outdoor industry perks
- Annual Get Out Get Active funds to fuel your active lifestyle
- Flexible time away package that includes PTO STO VTO and paid holidays
In this role success is driven by cognitive abilities such as concentration and problem-solving essential for our computer-centric tasks. onX will explore reasonable accommodations to ensure that individuals with diverse abilities can fully engage in and contribute to the essential physical and mental functions of the job. If you need assistance or accommodation please contact us at .
Position open until filled.
At onX we believe that unique perspectives make us stronger. By bringing together people with different experiences ideas and viewpoints we fuel innovation and move closer to our mission of awakening the adventurer in everyone. We are proud to be an equal opportunity employer and are committed to fairness not only in hiring but also in development compensation and promotion. Our goal is to build an inclusive community where every team member can show up authentically and thrive. Together we win as one team. Come join us!
onX Maps will never ask for credit card or SSN details during the initial application process. For your digital safety apply only through our legitimate website at directly via our LinkedIn page.
onX does not sell any Personal Information but we may transfer employment related records to our service providers or third parties that provide business services to onX or as required by law. For more information see our .
As part of our interview process your conversation may be recorded for documentation purposes to allow interviewers to focus fully on the discussion. Recordings are confidential and accessible only to authorized personnel. Please note onX respects all applicable laws regarding recording consent and you will have an opportunity to opt-out if preferred.
Required Experience:
Senior IC
About Company
Know where you stand with onX, the most accurate GPS mapping tech for outdoor enthusiasts featuring land ownership maps that work offline.