SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 136,000 - 170,000 / annual
onX is a high-growth outdoor technology company seeking a Senior Security Analyst I to serve as the team's subject matter expert on security operations, incident response, and application/vendor security. This is a hands-on role focused on building automations and tools to scale security work across the organization.
Key Responsibilities:
Security Monitoring and Detection: Serve as SME on SIEM/EDR platforms (SentinelOne), analyze complex attack vectors, maintain threat models and vulnerability metrics, and partner with the SRE team on Google Cloud Platform (GCP) security monitoring including IAM, logging, and workload security.
Incident Response: Execute incident response playbooks, make frontline judgment calls during incidents, facilitate tabletop exercises and simulations, partner with SRE during cloud-related incidents, and lead post-incident analysis with recommendations for playbook improvements.
Application and Vendor Security: Run recurring security audits of business applications with full Tier 0 coverage, serve as SME on annual third-party penetration tests (mobile, API, phishing), conduct vendor security assessments with recurring cadence for Tier 0/1 vendors, and collaborate with engineering on secure product design throughout the development lifecycle.
Compliance Support: Support SOC 2 Type 2 compliance through evidence gathering and auditor responses, maintain SOC 2 automation tooling (Sprinto), and help maintain security policies, procedures, and ISMS documentation.
Leadership and Process Improvement: Partner with Director of IT and Security to prioritize risk reduction, recommend frameworks for risk quantification and incident response automation, build automations and tools to reduce manual effort across compliance, audits, and monitoring, identify IAM lifecycle automations, explore and pilot AI-assisted approaches to security operations, evaluate business requests to find secure solutions that enable speed, and mentor other security team members.
This role reports to the Director of IT and Security and is part of a distributed company with 400+ employees. onX operates with clear goals, structure, and frameworks while emphasizing individual ownership and autonomy within strategic boundaries.
Requirements:
- 7+ years of experience in security operations, incident response, or related security role
- Demonstrated experience tuning and operating SIEM and EDR platforms
- Experience leading incident response, including major incident judgment calls and post-incident analysis
- Working knowledge of vulnerability management and application security testing concepts
- Clear written and verbal communication skills, including ability to align leadership and stakeholders on risk
- Ability to work independently, set standards, and prioritize across monitoring, incident response, and cross-functional projects
- Working knowledge of Google Cloud Platform (GCP), including IAM, logging, and core infrastructure services
- Ability to partner effectively with Infrastructure and engineering teams on cloud and application security matters
- Demonstrated use of AI tools as a force multiplier for security work with a curious, hands-on approach
- Demonstrated experience building scripts, automations, or tools that reduce manual work (compliance evidence collection, audit workflows, alert triage)
- Sound judgment in weighing security risk against business need with a track record of finding secure solutions that enable business progress
Bonuses (not required):
- Direct experience with SentinelOne or comparable EDR platform
- Experience with SOC 2 or similar compliance framework
- Experience with GRC automation tools such as Sprinto
- Familiarity with mobile application and API security testing
- Experience with workflow automation tools such as Workato
- Proficiency with scripting languages (Python) for building automations and tools
- Relevant industry certifications (GSEC, GCIH, CISSP)
- Google Cloud Platform (GCP) and AWS certifications (Associate Cloud Engineer, Professional Cloud Security Engineer)
- Experience mentoring or informally leading other security team members