Information Security Analyst III
Job Fit Check
Base Career helps you apply smarter for this job.
Full Job Posting
Summary
An individual contributor that serves as a senior individual contributor on the cybersecurity operations team, responsible for the day-to-day operation, tuning, and continuous improvement of the enterprise cybersecurity toolset. This role owns advanced detection and response work across endpoint, identity, application and cloud surfaces; leads investigations of escalated alerts; builds automation that removes manual effort from repeatable security tasks; and translates threat intelligence and vulnerability data into prioritized, actionable remediation for platform and application owners.
Minimum Requirements
Combination of Education and Experience will be considered.
Must be authorized to work in the US as defined by the Immigration Act of 1986.
Must pass a Criminal Background Check.
Education Details
Bachelor's degree in Computer Science, Software Engineering or related field or equivalent combination of education and experience.
Certification Details
Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Offensive Security Certified Professional (OSCP), or any related industry certifications.
Years of Experience:
- Minimum six (6) years of experience in information security.
- Minimum two (2) years of project or team lead experience.
Credit Check: No
Valid/Unexpired Passport Book: Yes Valid/Unexpired Driver's License: Yes
- Master's degree in Computer Science or relevant field.
Preferred Requirements
- Eight (8) or more years of cybersecurity experience, including time in a security operations center or incident response function.
- Industry certification such as CISSP, GCIH, GCIA, GCFA, GSEC, CySA+, or vendor certification in EDR, SIEM, identity, or cloud security.
- Experience building security automation and orchestration playbooks that integrate multiple tools through APIs.
- Experience operating a threat intelligence program, including managing intelligence feeds, tracking threat actors relevant to the industry, and producing intelligence-driven detections.
- Experience with detection-as-code practices: version control, peer review, and CI/CD pipelines for detection and automation content.
- Experience integrating SAST, DAST, software composition analysis (SCA), and secrets scanning into CI/CD pipelines, including quality gates and build-breaking policy.
- Experience with interactive application security testing (IAST), runtime application self-protection (RASP), API security testing, or bot and fraud mitigation capabilities layered with a WAF.
- Secure code review ability in one or more languages used for web and API development, and familiarity with threat modeling for new features and services.
- Experience with PCI DSS requirements applicable to public-facing web applications, including WAF or equivalent control requirements and application penetration testing obligations.
- Cloud security experience in a major public cloud provider, including native logging and identity services.
- Familiarity with identity threat detection and response concepts, including privileged access management and detection of identity-based attack techniques.
- Experience in a regulated environment subject to requirements such as PCI DSS, SOX, or aviation-sector regulatory oversight.
- Experience supporting operational technology or specialized business systems in addition to corporate IT.
- Experience mentoring analysts, developing runbooks, and leading tabletop or purple team exercises.
Endpoint Detection And Response
- Operate and tune the enterprise EDR platform; investigate escalated detections, perform host triage and containment, and drive eradication and recovery actions.
- Develop and maintain custom detections, exclusions, and response policies; validate coverage against known attacker techniques.
- Monitor agent health and deployment coverage across the endpoint and server estate and work with platform teams to close gaps.
Automation and Orchestration
- Design, build, test, and maintain automation and orchestration playbooks that reduce manual analyst effort in triage, enrichment, containment, and reporting.
- Integrate security tools through APIs to move context automatically between detection, ticketing, identity, and asset systems.
- Maintain automation content in version control with peer review; measure and report time saved and error reduction.
Security Information And Event Management
- Develop, tune, and maintain correlation rules, use cases, dashboards, and alerts in the SIEM; reduce false positives while preserving detection coverage.
- Onboard new log sources, validate parsing and field normalization, and confirm data completeness and retention against monitoring and compliance requirements.
- Perform threat hunting and historical analysis across aggregated log data to identify activity that automated detections missed.
Threat Intelligence
- Consume, evaluate, and operationalize intelligence from commercial feeds, open sources, industry sharing groups, and government partners; convert relevant intelligence into detections, hunts, and blocking decisions.
- Track threat actors, campaigns, and techniques targeting the aviation, travel, hospitality, and payment sectors and brief stakeholders on relevance and recommended action.
- Produce concise written intelligence summaries for technical teams and leadership.
Vulnerability Management
- Operate scanning and assessment capabilities across endpoints, servers, cloud workloads, containers, and network devices; validate findings and eliminate false positives.
- Prioritize vulnerabilities using severity, exploitability, threat intelligence, asset criticality, and exposure; partner with system owners to define remediation plans and track them to closure.
- Report on remediation performance against defined service levels and escalate aging or high-risk exposures through the established risk process.
Application Security — Static Testing (SAST)
- Operate the static analysis platform: onboard repositories, configure language and framework coverage, tune rulesets, and maintain baselines for legacy code.
- Integrate static scanning into developer workflows and CI/CD pipelines; define and administer quality gates and policy thresholds in partnership with engineering.
- Triage static findings to remove false positives, confirm exploitable issues, and provide developers with specific, code-level remediation guidance and secure coding patterns.
- Support software composition analysis and secrets detection for third-party libraries, open-source dependencies, and credential leakage in source repositories.
Application Security — Dynamic Testing (DAST)
- Plan, schedule, and execute dynamic scans against web applications and APIs across pre-production and production environments, including authenticated scanning and API-definition-driven testing.
- Validate and reproduce dynamic findings, assess real-world exploitability and business impact, and route prioritized results into the remediation and risk-tracking process.
- Support and help scope third-party penetration tests and application assessments, and track resulting findings to closure.
Web Application Firewall
- Operate and tune the web application firewall protecting customer-facing and internal web applications and APIs: managed rule sets, custom rules, rate limiting, geo and reputation controls, and bot mitigation.
- Move new rules through detection only to blocking mode using traffic analysis, minimizing false positives, and avoiding disruption to legitimate customer traffic.
- Monitor and investigate WAF telemetry and blocked-event trends; correlate WAF logs into the SIEM and build detections for application-layer attack patterns, credential stuffing, scraping, and abuse.
- Support onboarding new applications and domains behind the WAF, including policy design, exclusion management, and validation testing with application teams.
- Maintain WAF configuration documentation and evidence supporting applicable regulatory and payment-industry control requirements.
Single Sign-On And Identity Protection
- Support and maintain SSO integrations for enterprise and third-party applications, including federation configuration, application onboarding, and access policy design.
- Configure and tune multifactor authentication, conditional access, and identity risk policies; investigate identity-based alerts such as impossible travel, MFA fatigue, token theft, and privilege escalation.
- Monitor privileged and service accounts, review access anomalies, and support access certification and least-privilege initiatives with the identity and access management team.
Incident Response And General Responsibilities
- Act as an escalation point for security incidents; lead or support investigation, evidence preservation, containment, and post-incident documentation and lessons learned.
- Maintain runbooks, detection documentation, and operational procedures; contribute to tabletop and purple team exercises.
- Mentor junior analysts on investigative techniques, tooling, and quality of documentation.
- Support audit, assessment, and regulatory evidence requests related to security monitoring, vulnerability management, and access controls.
- Handle sensitive data — including payment, personal, and crew or employee data — in accordance with company policy and applicable regulatory requirements.
- Clear written and verbal communication skills, including the ability to document investigative findings for both technical and non-technical audiences.
- Ability to participate in an on-call rotation and respond to security events outside normal business hours.
- Other duties as assigned.
Physical Requirements
The Physical Demands and Work Environment described here are a representative of those that must be met by a Team Member to successfully perform the essential functions of the role.
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the role.
Physical Demands And Work Environment
Office - While performing the duties of this job, the Team Member is regularly required to stand, sit, talk, hear, see, reach, stoop, kneel, and use hands and fingers to operate a computer, key board, printer, and phone.
May be required to lift, push, pull, or carry up to 20 lbs.
May be required to work various shifts/days in a 24-hour situation.
Regular attendance is a requirement of the role.
Exposure to moderate noise (i.e. business office with computers, phones, printers, and foot traffic), temperature and light fluctuations.
Ability to work in a confined area as well as the ability to sit at a computer terminal for an extended period of time.
Some travel may be a requirement of the role.
Essential Services Provider
Allegiant as a national air carrier is deemed an essential service provider during declared national and state emergencies.
Team Members will be required to report to their assigned trip or work location during national and state emergencies unless prohibited by local, state or federal order.
Eeo Statement
We welcome all individuals from varied backgrounds and experiences to apply.
Our company values the unique perspectives and talents that each person brings to our team.
Equal Opportunity Employer: Disability And Veteran
For more information, see https://allegiantair.jobs
Summary
An individual contributor that serves as a senior individual contributor on the cybersecurity operations team, responsible for the day-to-day operation, tuning, and continuous improvement of the enterprise cybersecurity toolset. This role owns advanced detection and response work across endpoint, identity, application and cloud surfaces; leads investigations of escalated alerts; builds automation that removes manual effort from repeatable security tasks; and translates threat intelligence and vulnerability data into prioritized, actionable remediation for platform and application owners.
Minimum Requirements
Combination of Education and Experience will be considered.
Must be authorized to work in the US as defined by the Immigration Act of 1986.
Must pass a Criminal Background Check.
Education Details
Bachelor's degree in Computer Science, Software Engineering or related field or equivalent combination of education and experience.
Certification Details
Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Offensive Security Certified Professional (OSCP), or any related industry certifications.
Years of Experience:
- Minimum six (6) years of experience in information security.
- Minimum two (2) years of project or team lead experience.
Credit Check: No
Valid/Unexpired Passport Book: Yes Valid/Unexpired Driver's License: Yes
- Master's degree in Computer Science or relevant field.
Preferred Requirements
- Eight (8) or more years of cybersecurity experience, including time in a security operations center or incident response function.
- Industry certification such as CISSP, GCIH, GCIA, GCFA, GSEC, CySA+, or vendor certification in EDR, SIEM, identity, or cloud security.
- Experience building security automation and orchestration playbooks that integrate multiple tools through APIs.
- Experience operating a threat intelligence program, including managing intelligence feeds, tracking threat actors relevant to the industry, and producing intelligence-driven detections.
- Experience with detection-as-code practices: version control, peer review, and CI/CD pipelines for detection and automation content.
- Experience integrating SAST, DAST, software composition analysis (SCA), and secrets scanning into CI/CD pipelines, including quality gates and build-breaking policy.
- Experience with interactive application security testing (IAST), runtime application self-protection (RASP), API security testing, or bot and fraud mitigation capabilities layered with a WAF.
- Secure code review ability in one or more languages used for web and API development, and familiarity with threat modeling for new features and services.
- Experience with PCI DSS requirements applicable to public-facing web applications, including WAF or equivalent control requirements and application penetration testing obligations.
- Cloud security experience in a major public cloud provider, including native logging and identity services.
- Familiarity with identity threat detection and response concepts, including privileged access management and detection of identity-based attack techniques.
- Experience in a regulated environment subject to requirements such as PCI DSS, SOX, or aviation-sector regulatory oversight.
- Experience supporting operational technology or specialized business systems in addition to corporate IT.
- Experience mentoring analysts, developing runbooks, and leading tabletop or purple team exercises.
Endpoint Detection And Response
- Operate and tune the enterprise EDR platform; investigate escalated detections, perform host triage and containment, and drive eradication and recovery actions.
- Develop and maintain custom detections, exclusions, and response policies; validate coverage against known attacker techniques.
- Monitor agent health and deployment coverage across the endpoint and server estate and work with platform teams to close gaps.
Automation and Orchestration
- Design, build, test, and maintain automation and orchestration playbooks that reduce manual analyst effort in triage, enrichment, containment, and reporting.
- Integrate security tools through APIs to move context automatically between detection, ticketing, identity, and asset systems.
- Maintain automation content in version control with peer review; measure and report time saved and error reduction.
Security Information And Event Management
- Develop, tune, and maintain correlation rules, use cases, dashboards, and alerts in the SIEM; reduce false positives while preserving detection coverage.
- Onboard new log sources, validate parsing and field normalization, and confirm data completeness and retention against monitoring and compliance requirements.
- Perform threat hunting and historical analysis across aggregated log data to identify activity that automated detections missed.
Threat Intelligence
- Consume, evaluate, and operationalize intelligence from commercial feeds, open sources, industry sharing groups, and government partners; convert relevant intelligence into detections, hunts, and blocking decisions.
- Track threat actors, campaigns, and techniques targeting the aviation, travel, hospitality, and payment sectors and brief stakeholders on relevance and recommended action.
- Produce concise written intelligence summaries for technical teams and leadership.
Vulnerability Management
- Operate scanning and assessment capabilities across endpoints, servers, cloud workloads, containers, and network devices; validate findings and eliminate false positives.
- Prioritize vulnerabilities using severity, exploitability, threat intelligence, asset criticality, and exposure; partner with system owners to define remediation plans and track them to closure.
- Report on remediation performance against defined service levels and escalate aging or high-risk exposures through the established risk process.
Application Security — Static Testing (SAST)
- Operate the static analysis platform: onboard repositories, configure language and framework coverage, tune rulesets, and maintain baselines for legacy code.
- Integrate static scanning into developer workflows and CI/CD pipelines; define and administer quality gates and policy thresholds in partnership with engineering.
- Triage static findings to remove false positives, confirm exploitable issues, and provide developers with specific, code-level remediation guidance and secure coding patterns.
- Support software composition analysis and secrets detection for third-party libraries, open-source dependencies, and credential leakage in source repositories.
Application Security — Dynamic Testing (DAST)
- Plan, schedule, and execute dynamic scans against web applications and APIs across pre-production and production environments, including authenticated scanning and API-definition-driven testing.
- Validate and reproduce dynamic findings, assess real-world exploitability and business impact, and route prioritized results into the remediation and risk-tracking process.
- Support and help scope third-party penetration tests and application assessments, and track resulting findings to closure.
Web Application Firewall
- Operate and tune the web application firewall protecting customer-facing and internal web applications and APIs: managed rule sets, custom rules, rate limiting, geo and reputation controls, and bot mitigation.
- Move new rules through detection only to blocking mode using traffic analysis, minimizing false positives, and avoiding disruption to legitimate customer traffic.
- Monitor and investigate WAF telemetry and blocked-event trends; correlate WAF logs into the SIEM and build detections for application-layer attack patterns, credential stuffing, scraping, and abuse.
- Support onboarding new applications and domains behind the WAF, including policy design, exclusion management, and validation testing with application teams.
- Maintain WAF configuration documentation and evidence supporting applicable regulatory and payment-industry control requirements.
Single Sign-On And Identity Protection
- Support and maintain SSO integrations for enterprise and third-party applications, including federation configuration, application onboarding, and access policy design.
- Configure and tune multifactor authentication, conditional access, and identity risk policies; investigate identity-based alerts such as impossible travel, MFA fatigue, token theft, and privilege escalation.
- Monitor privileged and service accounts, review access anomalies, and support access certification and least-privilege initiatives with the identity and access management team.
Incident Response And General Responsibilities
- Act as an escalation point for security incidents; lead or support investigation, evidence preservation, containment, and post-incident documentation and lessons learned.
- Maintain runbooks, detection documentation, and operational procedures; contribute to tabletop and purple team exercises.
- Mentor junior analysts on investigative techniques, tooling, and quality of documentation.
- Support audit, assessment, and regulatory evidence requests related to security monitoring, vulnerability management, and access controls.
- Handle sensitive data — including payment, personal, and crew or employee data — in accordance with company policy and applicable regulatory requirements.
- Clear written and verbal communication skills, including the ability to document investigative findings for both technical and non-technical audiences.
- Ability to participate in an on-call rotation and respond to security events outside normal business hours.
- Other duties as assigned.
Physical Requirements
The Physical Demands and Work Environment described here are a representative of those that must be met by a Team Member to successfully perform the essential functions of the role.
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the role.
Physical Demands And Work Environment
Office - While performing the duties of this job, the Team Member is regularly required to stand, sit, talk, hear, see, reach, stoop, kneel, and use hands and fingers to operate a computer, key board, printer, and phone.
May be required to lift, push, pull, or carry up to 20 lbs.
May be required to work various shifts/days in a 24-hour situation.
Regular attendance is a requirement of the role.
Exposure to moderate noise (i.e. business office with computers, phones, printers, and foot traffic), temperature and light fluctuations.
Ability to work in a confined area as well as the ability to sit at a computer terminal for an extended period of time.
Some travel may be a requirement of the role.
Essential Services Provider
Allegiant as a national air carrier is deemed an essential service provider during declared national and state emergencies.
Team Members will be required to report to their assigned trip or work location during national and state emergencies unless prohibited by local, state or federal order.
Eeo Statement
We welcome all individuals from varied backgrounds and experiences to apply.
Our company values the unique perspectives and talents that each person brings to our team.
Equal Opportunity Employer: Disability And Veteran
For more information, see https://allegiantair.jobs
About Allegiant Air
Ultra-low-cost passenger airline serving leisure travelers from small U.S. cities with nonstop flights to vacation destinations.
Visit company websiteJobs and hiring trendsApply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at Allegiant Air
Temporary Safety and Security Administrator
Las Vegas, USA
Summary The Safety and Security Administrator provides support to Safety and Security leadership. The position assists with the coordination of safety and security activities and projects across the Allegiant system. Thi
Program Manager, Enterprise Systems
Las Vegas, USA
Summary The Enterprise Systems Program Manager is responsible for the strategic planning, product management, program leadership, and project execution of Allegiant’s Enterprise Systems portfolio. This role combines the
Category Manager - Ground Operations
Las Vegas, USA
Summary The Category Manager – Ground Operations Services & Equipment is the strategic procurement leader for all ground operations-related categories. This role encompasses a broad portfolio of critical services and equ
HR Business Partner
Las Vegas, USA
Summary The strategic HR Business Partner serves as a trusted advisor to leaders, aligning people strategies with business objectives to drive organizational performance, engagement, and growth. This role builds strong p
Fleet Reliability Engineer
Las Vegas, USA
Summary The Fleet Reliability Engineer plays a critical role in ensuring the ongoing airworthiness, operational performance, and safety of Allegiant’s expanding fleet. This role bridges engineering acumen with analytical
AOG Buyer
Las Vegas, USA
Summary Assure the parts and materials required to perform aircraft maintenance are available to each assigned line station through stock transfers or procurements. Inventory levels should be monitored and parts should b
Instructional Designer - Inflight
Las Vegas, USA
Short Description From America's favorite small cities to world-class destinations, Allegiant makes leisure travel affordable and convenient. With low-low fares, nonstop, all-jet service and premier travel partners, Alle
Material Specialist - PIE
Clearwater, USA
Summary The Materials Specialist maintains the Stores stock and works with other departments at the station to ensure an adequate supply of materials for aircraft maintenance. Materials Specialist will receive, handle, s
Temporary Safety and Security Administrator
Las Vegas, USA
Program Manager, Enterprise Systems
Las Vegas, USA
Category Manager - Ground Operations
Las Vegas, USA
HR Business Partner
Las Vegas, USA
Fleet Reliability Engineer
Las Vegas, USA
AOG Buyer
Las Vegas, USA
Instructional Designer - Inflight
Las Vegas, USA
Material Specialist - PIE
Clearwater, USA