CareerMoonshot

Security analyst

Gravity Payments · Remote

📍 Remote💰 $90,000 - $168,000via greenhousePosted 2026-09-15
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Gravity Payments.
A career with Gravity Payments is an opportunity to be on a collaborative team where creative leadership, passion for progress, and responsibility are paramount. Our team members focus and commit to providing for our clients and our community because we care deeply for others. We are seeking a Security Analyst to operate and build security across our cloud, endpoint, identity, SaaS, and corporate environments. You will triage and investigate alerts, respond to incidents on a 24x7 rotation with the team, and hunt for threats that automated detections miss. You will be in a position to directly impact the quality of our existing security systems and be trusted to make decisions that will direct the path of our security program. This is a practical role for a careful investigator who can move from writing API integrations, to log analysis and containment, to remediation reporting. This is a hands-on, high-trust role for someone committed to protecting team members and customers through both operational excellence and building the next better system. Success in this role looks like: Within 3 months: You are co-owning first-line alert triage across our SIEM and connected tools, and you are confidently serving as a first responder on the 24x7 on-call rotation, investigating and dispositioning alerts with prompt, clear escalation of real incidents.  Within 6 months: You are trusted to lead complex, sensitive investigations in our payments environment, such as analyzing fraud signals or account-takeover attempts, and you handle them with discretion, care, and sound evidence practice. You have materially reduced the likelihood or impact of a tracked threat on our Risk Register, created or advanced a SOAR playbook of your own design, and added a new, fully correlated signal source to our SIEM. Within 1 year: You are a strong dual operator and builder who owns your corner of the security program. You have led significant threat investigations end to end, your automations have measurably reduced response times and false-positive pages, and you decide where we invest in future automation efforts. You have supported PCI DSS and SOC 2 audits and have tangibly matured our detection, defense, and reporting so that real risks are identified and mitigated faster. Core Responsibilities Monitor, triage, investigate, and disposition security alerts across SIEM, endpoint, cloud, identity, email, SaaS, network, data loss prevention, and file integrity sources. Take part in the shared 24/7 on-call rotation, perform initial containment, and escalate confirmed or complex incidents promptly. Engineer automation and integrations across the security stack, developing the code that connects and orchestrates our security tools, and advances our SOAR playbooks to reduce intervention and speed response. Apply agentic AI as a force multiplier, with tested results, human control, and full audit for any action it takes.  Investigate security incidents, malicious email, suspected fraud, insider threats, and data loss events. Conduct proactive threat hunts, preserve relevant evidence, and contribute clear incident reports and follow-up actions. Build and maintain SaaS, endpoint, and application security posture; operate file integrity monitoring; run phishing simulations; support penetration tests; and track identified gaps through remediation, mitigation, or technical acceptance of risk. Support PCI DSS and SOC 2 compliance program through evidence collection automation and audit engagement interviews.  Maintain and iterate weekly and quarterly reporting for organization leadership. Maintain investigation and response documentation, and daily guidance to team members through the company security help channels. Continuously bring your unique experience and expertise to lead us through changes in detection and response paradigms.  Preferred Skills Experience working within or closely with Technology, Engineering, and DevOps teams at a small or midsize company, where cross-functional collaboration and shared ownership are expected. Experience in the credit card payment services industry or another regulated financial services environment. Strong judgment and attention to detail, with a calm, methodical approach under pressure and a sound sense of when to contain, when to escalate, and how to act on incomplete, uncertain, or noisy data. Clear written and verbal communication that explains findings, risk, and required actions to technical and nontechnical audiences, and the ability to influence teams without direct authority. Strong organization and follow-through, able to manage investigations, recurring operational work, and remediation tracking at the same time, with a continuous learning mindset toward current attacker methods and defenses. A self-driven adopter of AI who treats it as a force multiplier, reaches for it by instinct to compare evidence, find gaps, speed up assessments, and verifies every output before use. Technical Requirements At least 3 years of hands-on experience in security operations, incident response, vulnerability management, systems administration, or a closely related role. Experience must include independent alert investigation and escalation or containment responsibility. A bachelor's degree in cybersecurity, computer science, information technology, or a related field, or an equivalent combination of practical experience, training, and certification. Hands-on experience with SIEM and EDR/XDR platforms and with security telemetry from cloud, endpoint, identity, email, and SaaS systems. Our environment includes CrowdStrike NG-SIEM, AWS CloudTrail and CloudWatch, AWS Security Hub, Okta, Microsoft Entra, Google Workspace, Keeper, Duo, UniFi, Microsoft Defender, Jira, and MintMCP. Ability to query, interpret, and correlate logs by using a SIEM query language such as LogScale/CQL, SPL, or a comparable language. Ability to use Python, PowerShell, and

More Remote jobs

Remote jobs · Browse all locations