Sr. Security Analyst
We tailor your resume to this role and apply for you in seconds.
Apply to Sr. Security Analyst at BDAJob details
- Location
- Woodinville, Washington
- Work type
- Hybrid
- Compensation
- $120,000 - $130,000/yr
- Posted
- today
- Apply on
- job-boards.greenhouse.io
About this role
Most companies claim to have the best people. We say to them, "Keep dreaming." Our people are second to none. They set us apart with their entrepreneurial spirit and ambition. They come to us from the likes of Amazon, Microsoft, Nordstrom, Starbucks and the sports world, bringing energy, bold ideas and a willingness to dive into the unfamiliar. It's our people that make BDA the top global Merchandise Agency to work for.
Location:
- This role is based in Woodinville, WA and requires you to work onsite 4 days per week, with 1 day remote.
- To be considered, you must live within commuting distance, as regular in-person collaboration is a key part of the role.
Job Summary
BDA is looking for a Senior Security Analyst who can help us strengthen our security program and move from a primarily reactive approach to a more proactive, planned security strategy.
This role will have a strong focus on application, cloud, and infrastructure security. You will identify vulnerabilities, test applications and environments, evaluate potential exploits, and work closely with IT and business partners to reduce risk across the organization.
You will also have the opportunity to help define what the red-team security function looks like at BDA. We are open to an experienced mid-level professional who has strong application security skills and is ready to continue growing, as well as a more seasoned security professional seeking broad ownership and meaningful challenges.
What You’ll Do
- Conduct vulnerability scans, penetration testing, and security assessments across applications, systems, cloud environments, and infrastructure.
- Use tools including Tenable Nessus, Burp Suite, and CrowdStrike to identify vulnerabilities, investigate threats, and recommend remediation.
- Test web applications to identify potential exploits, attack paths, and security weaknesses.
- Evaluate the security of Linux-based and cloud environments, including AWS, OCI, and Azure.
- Partner with infrastructure and engineering teams to improve system configurations, hardening standards, access controls, and overall security posture.
- Monitor security events, investigate potential incidents, and support incident response and forensic activities.
- Conduct account reviews, access reviews, risk assessments, and other security-related analysis.
- Develop clear reports and recommendations for technical teams, business leaders, and executive stakeholders.
- Help establish repeatable security processes, priorities, and testing practices that allow the organization to address risks proactively.
- Collaborate with security team members, consultants, IT infrastructure, engineering, legal, compliance, and business teams across BDA.
- Support the development and ongoing improvement of security policies, procedures, standards, and employee awareness initiatives.
- Stay current on emerging threats, vulnerabilities, attack methods, and security best practices.
Required Qualifications
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Professional experience in information security, application security, infrastructure security, or a closely related area.
- Hands-on experience with all of the following: Microsoft Defender, Microsoft Purview, CrowdStrike, Tenable Nessus, and Burp Suite
- Proven experience with application and environment security, vulnerability testing, exploit testing, penetration testing, or vulnerability scanning.
- Strong understanding of cloud security and experience securing environments such as AWS, OCI, or Azure.
- Experience working with Linux environments and securing cloud-based or distributed infrastructure.
- Knowledge of security frameworks and standards such as NIST, CIS, or ISO 27001.
- Understanding of risk management practices and the ability to identify, prioritize, and communicate security risks.
- Working knowledge of security technologies such as firewalls, IDS/IPS, endpoint security, SIEM, and enterprise intrusion-prevention systems.
- Experience with system-hardening standards for servers, desktops, laptops, or network devices.
- Understanding of malware, attack vectors, network threats, incident response, authentication, and access-control technologies.
- Knowledge of internet protocols and security technologies, including HTTP, TLS, SSL, HTML, and XML.
- Understanding of cloud, container-based, and virtualized architectures.
- Knowledge of encryption techniques, standards, and appropriate encryption levels.
- Strong analytical, problem-solving, and attention-to-detail skills.
- Clear communication skills and the ability to work effectively across technical and nontechnical teams.
- A collaborative and humble working style, with the ability to accept direction, execute priorities, and remain open to the perspectives of others.
Preferred Qualifications
- Previous experience in an IT infrastructure, systems administration, networking, DevOps, or engineering role before moving into security.
- Experience that combines technical security with governance, risk, compliance, or privacy responsibilities.
- Familiarity with privacy regulations such as GDPR, CPRA, or CCPA.
- Experience with firewalls, load balancers, web application firewalls, or VPN concentrators.
- Experience with databases and related technologies such as Elasticsearch, SQL, or Oracle.
- Experience handling and protecting information across different sensitivity levels.
- Familiarity with standards or regulations such as FISMA, GLBA, FERPA, PCI DSS, ISO, or NIST.
- Higher education or government information-security experience.
- Security certifications such as CISSP, CISA, CISM, CEH, GWAPT, GPEN, CSFA, or similar credentials.
- Experience with SUMO Cloud or comparable security monitoring and log-analysis tools.
Why This Role?
- This is an opportunity to do more than maintain an existing security program. You will help shape how BDA approaches red-team testing, vulnerability management, application security, and proactive risk reduction.
- You will join a close-knit security team of four that brings strong energy, collaboration, and long-standing knowledge of the organization. The team works across the entire business, giving you visibility into systems, applications, and risks that few other roles get to see.
- The work is broad, challenging, and rarely repetitive. You will have room to grow, opportunities to influence how the security function evolves, and the flexibility of a team that genuinely believes family comes first.
Why BDA?
BDA is a place where creativity, partnership, and customer care come together. For more than 40 years, we have helped some of the world’s most recognized brands create memorable experiences through branded merchandise, gifting, and custom programs. We are proud of the work we do, the relationships we build, and the people behind it all. At BDA, you will find a team that values collaboration, innovation, and a “get it done” mindset — while still making space for creativity, growth, and meaningful impact.
Our Core Values:
- BDA is a Team and a Family
- Always Strive to Be The Best
- Entrepreneurial Spirit
- Tigger Attitude
- Work Hard, Play Hard
- Make It Happen the Best Way
- Total Client Affinity & Advocacy
Want to learn more? So much to explore
- BDA Instagram: https://www.instagram.com/bda_inc/
- Harper + Scott (a BDA company): https://www.harperandscott.com/ & https://www.instagram.com/harperandscott/
- swagup (a BDA company) end-to-end Merch Ecommerce site: https://www.swagup.com/
- Idea Planet (a BDA company): https://www.ideaplanetlp.com/about
- BDA Careers Page: https://www.bdainc.com/careers/
- LinkedIn – BDA page: https://www.linkedin.com/company/bdainc/
#LI-AH1
#LI-Hybrid
We are pleased to share the base salary range for this position is $120,000 to $130,000. If you are hired at BDA, your compensation will be determined based on factors that may include geographic location, skills, education, and experience. In addition to these factors, we believe in the importance of pay equity and consider internal equity of our current team members as a part of any offer. In the spirit of pay transparency, the range listed is the full base salary range for the role and hiring at the top of the range would not be typical, in order to allow for future salary growth. The range listed is just one component of BDA’s total compensation and rewards programs, which includes: robust PTO; vacation, a paid volunteer day, holidays and summer Fridays, Benefits; medical, dental, vision, life, and AD&D insurance, 401k; tuition reimbursement, mental health and financial wellness programs and professional development opportunities including tuition reimbursement. Certain revenue-generating positions may be eligible for incentive compensation.
Connect With Us! Not ready to apply? Connect with us for general consideration.