Information Security Analyst III
Allegiant · Nevada
📍 Las Vegas, NV💰 $107,700-$131,300via leverPosted 2026-09-02
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Allegiant.
Summary
An individual contributor that serves as a senior individual contributor on the cybersecurity operations team, responsible for the day-to-day operation, tuning, and continuous improvement of the enterprise cybersecurity toolset. This role owns advanced detection and response work across endpoint, identity, application and cloud surfaces; leads investigations of escalated alerts; builds automation that removes manual effort from repeatable security tasks; and translates threat intelligence and vulnerability data into prioritized, actionable remediation for platform and application owners.
Visa Sponsorship Available
No
Minimum Requirements
Combination of Education and Experience will be considered. Must be authorized to work in the US as defined by the Immigration Act of 1986. Must pass a Criminal Background Check.
Education: Bachelor’s Degree
Education Details:
Bachelor's degree in Computer Science, Software Engineering or related field or equivalent combination of education and experience.
Certification: Yes
Certification Details:
Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Offensive Security Certified Professional (OSCP), or any related industry certifications.
Years of Experience:
Minimum six (6) years of experience in information security.
Minimum two (2) years of project or team lead experience.
Credit Check: No
Valid/Unexpired Passport Book: no
Valid/Unexpired Driver's License: no
Master's degree in Computer Science or relevant field.
Preferred Requirements
Eight (8) or more years of cybersecurity experience, including time in a security operations center or incident response function.
Industry certification such as CISSP, GCIH, GCIA, GCFA, GSEC, CySA+, or vendor certification in EDR, SIEM, identity, or cloud security.
Experience building security automation and orchestration playbooks that integrate multiple tools through APIs.
Experience operating a threat intelligence program, including managing intelligence feeds, tracking threat actors relevant to the industry, and producing intelligence-driven detections.
Experience with detection-as-code practices: version control, peer review, and CI/CD pipelines for detection and automation content.
Experience integrating SAST, DAST, software composition analysis (SCA), and secrets scanning into CI/CD pipelines, including quality gates and build-breaking policy.
Experience with interactive application security testing (IAST), runtime application self-protection (RASP), API security testing, or bot and fraud mitigation capabilities layered with a WAF.
Secure code review ability in one or more languages used for web and API development, and familiarity with threat modeling for new features and services.
Experience with PCI DSS requirements applicable to public-facing web applications, including WAF or equivalent control requirements and application penetration testing obligations.
Cloud security experience in a major public cloud provider, including native logging and identity services.
Familiarity with identity threat detection and response concepts, including privileged access management and detection of identity-based attack techniques.
Experience in a regulated environment subject to requirements such as PCI DSS, SOX, or aviation-sector regulatory oversight.
Experience supporting operational technology or specialized business systems in addition to corporate IT.
Experience mentoring analysts, developing runbooks, and leading tabletop or purple team exercises.
Job Duties
Endpoint Detection and Response
Operate and tune the enterprise EDR platform; investigate escalated detections, perform host triage and containment, and drive eradication and recovery actions.
Develop and maintain custom detections, exclusions, and response policies; validate coverage against known attacker techniques.
Monitor agent health and deployment coverage across the endpoint and server estate and work with platform teams to close gaps.
Automation and Orchestration
Design, build, test, and maintain automation and orchestration playbooks that reduce manual analyst effort in triage, enrichment, containment, and reporting.
Integrate security tools through APIs to move context automatically between detection, ticketing, identity, and asset systems.
Maintain automation content in version control with peer review; measure and report time saved and error reduction.
Security Information and Event Management
Develop, tune, and maintain correlation rules, use cases, dashboards, and alerts in the SIEM; reduce false positives while preserving detection coverage.
Onboard new log sources, validate parsing and field normalization, and confirm data completeness and retention against monitoring and compliance requirements.
Perform threat hunting and historical analysis across aggregated log data to identify activity that automated detections missed.
Threat Intelligence
Consume, evaluate, and operationalize intelligence from commercial feeds, open sources, industry sharing groups, and government partners; convert relevant intelligence into detections, hunts, and blocking decisions.
Track threat actors, campaigns, and techniques targeting the aviation, travel, hospitality, and payment sectors and brief stakeholders on relevance and recommended action.
Produce concise written intelligence summaries for technical teams and leadership.
Vulnerability Management
Operate scanning and assessment capabilities across endpoints, servers, cloud workloads, containers, and network devices; validate findings and eliminate false positives.
Prioritize vulnerabilities using severity, exploitability, threat intelligence, asset criticality, and exposure; partner with system owners to define remediation plans and track them to closure.
Report on remediation performance against defined service levels and escalate aging or high-risk exposures through the established risk process.
Application Security — Static Testing (SAST)
Operate the
More Nevada jobs
Nevada jobs · Browse all locations