Senior Security Analyst
Abby Care · San Francisco
About this role
**Senior Security Analyst** **About Abby Care** Abby Care is building the leading AI-native platform for family-led care—helping families deliver better care at home with clinical oversight and an AI-powered platform. We partner with health plans, providers, and community organizations to expand access to care, reduce reliance on higher-cost settings, and improve transparency across the healthcare system. **The Opportunity** We’re seeking a **Senior Security Analyst** to strengthen our **security operations, threat detection, and risk management** program. Reporting into the **Director of IT, Information & Security**, you’ll lead **incident response, vulnerability management, and security monitoring** across our **cloud, endpoint, and identity** infrastructure—while mentoring junior analysts and continuously improving our security posture. This is a **Full-Time Hybrid** role based in **San Francisco, CA**. --- ## What You’ll Work On ### Security Operations & Incident Response - Lead **end-to-end incident response**, **threat hunting**, and **root cause analysis** across **SIEM**, **EDR (SentinelOne)**, and **cloud security** tooling. - Develop and maintain **incident response playbooks**, **runbooks**, and run **tabletop exercises**. ### Vulnerability & Risk Management - Own the **vulnerability management lifecycle**, partnering with **IT** and **Engineering** to remediate **scan**, **pen test**, and **audit** findings. - Maintain the **risk register**, conduct **third-party/vendor risk assessments**, and communicate technical risks to business stakeholders. ### Identity, Endpoint & Compliance Oversight - Partner with IT to audit and enforce security controls across **Okta (RBAC/MFA)**, **Google Workspace (DLP/logs)**, **JAMF**, and **SentinelOne**. - Drive **evidence collection** and remediation for compliance audits (**SOC 2, ISO 27001, HIPAA, PCI DSS**) while aligning policies with **NIST CSF** and **CIS** frameworks. ### Security Engineering & Automation - Automate detection, response, and reporting workflows via **SOAR**, **scripting**, and **APIs** to improve alert quality and efficiency. - Mentor team members and contribute to cross-functional security knowledge sharing. ### AI Security & Governance - Establish guardrails and acceptable-use policies for enterprise AI tools (e.g., **GenAI, Claude**) to mitigate **shadow AI**, **data leakage**, and third-party vendor risks. - Partner with Product and Engineering to assess and remediate **AI/LLM-specific vulnerabilities** (e.g., **prompt injection**, **model abuse**, **data exposure**). - Pilot and evaluate AI-powered security capabilities (e.g., **AI-assisted SIEM/EDR triage** and **anomaly detection**) to improve response speed and operational efficiency. --- ## What You’ll Have - **8+ years** of experience in security operations, leading incident response end-to-end from detection through remediation. - Associate’s or Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field (or equivalent practical experience). - Hands-on experience with **SIEMs**, **EDR/XDR** (e.g., **SentinelOne**), vulnerability scanners, cloud security, and core **IAM** concepts (**SSO, MFA, RBAC**). - Working knowledge of security frameworks (**SOC 2, ISO 27001, NIST, CIS**) and strong ability to translate technical risk to business stakeholders. - Familiarity with emerging **AI/LLM risks** and interest in evaluating AI capabilities for security use cases. - Exc
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.