← Back to results

Senior Security Analyst

Join onX as a Senior Security Analyst to protect systems and data while collaborating closely with the IT and Security team.

Location
Bozeman, Montana, United States
Compensation
$136k–$170k/yr
Level
senior
Type
full time · On-site

Posted by employer 1 week ago

First seen on Joblaze 1 day ago

Last verified on the company career page 1 day ago

Apply at onXmaps → Save job Scanned from onxmaps.com

Skills & Technologies

What you'll build

  • Serve as the team's subject matter expert on the SIEM/EDR platform
  • Execute the incident response playbook
  • Run recurring security audits of business applications
  • Support SOC 2 Type 2 compliance
  • Build automations and tools that reduce manual effort

Must have

  • 7 or more years of experience in security operations
  • Demonstrated experience tuning and operating SIEM and EDR platforms
  • Experience leading incident response
  • Working knowledge of vulnerability management and application security testing
  • Clear written and verbal communication skills
  • Working knowledge of Google Cloud Platform

Nice to have

  • Direct experience with SentinelOne
  • Experience with SOC 2 or a similar compliance framework
  • Familiarity with mobile application and API security testing
  • Proficiency with a scripting language
  • Relevant industry certification, such as GSEC, GCIH, or CISSP

AI in the day-to-day

onX views artificial intelligence (AI) as a powerful tool for strengthening security work.

Requirements

Experience
7+ years

Not disclosed in this posting: visa sponsorship.

Benefits

401k Match Equity/Stock Options Health Insurance Relocation Assistance Parental Leave

Joblaze summary

The Senior Security Analyst at onX is responsible for overseeing daily security operations, incident response, and application security, while also collaborating with the Site Reliability Engineering team on cloud security within Google Cloud Platform. Key skills include expertise in SIEM and EDR platforms, incident management, and application security testing, alongside a proactive approach to using AI in security processes. This role is suited for experienced professionals with a strong background in security operations and a focus on balancing security needs with business agility. onX fosters a collaborative environment, emphasizing the importance of mentorship and continuous improvement

Joblaze insights

  • Listed yesterday — first seen on Joblaze October 8, 2026. Last confirmed on onXmaps's careers page October 8, 2026.
  • Salary band is below the typical range for Security roles (median ~$170,000).
  • Starts above 12% of 102 comparable senior security roles in United States that list Python we track (median $174,250 across 43 companies). See Python salary trends
  • Python appears in 40.5% of 328 comparable senior security roles in United States; SentinelOne appears in 0.3% of 328 comparable senior security roles in United States.

Quick facts

Is the Senior Security Analyst role remote?
No — this is an on-site role in Bozeman, Montana, United States.
What's the salary range?
onXmaps lists $136,000–$170,000 for this role.
How much experience is required?
At least 7 years of relevant experience for this Senior Security Analyst role.
Where is the role based?
onXmaps is hiring for this position in Bozeman, Montana, United States.
What's the tech stack?
Joblaze extracted these technologies from the posting: Google Cloud Platform, Python, SOC 2, SentinelOne.
What seniority level is this role?
onXmaps targets senior candidates for this position.
Is this full-time or contract?
Full-time for this Senior Security Analyst role at onXmaps.

From the original posting

ABOUT onX

ABOUT THIS OPPORTUNITY

onX is seeking a Senior Security Analyst I with a passion for protecting the systems, data, and customers that make onX's products possible. As an onX Senior Security Analyst I, you will serve as the team's subject matter expert on day-to-day security operations, incident response, and application and vendor security. Your focus will be on security monitoring and detection, incident response execution, and application security testing, with a supporting role in compliance activities such as SOC 2 evidence collection. This role also partners closely with the onX Site Reliability Engineering (SRE) team, so a working understanding of Google Cloud Platform (GCP) is important to day-to-day work. onX views artificial intelligence (AI) as a powerful tool for strengthening security work, not something to fear, and this role should bring that same mindset.

This is a hands-on role: onX cannot do this work by hand at scale, so you will build the automations and tools needed to reduce manual effort across compliance evidence collection, application audits, and monitoring. You will also need to see your job as educating the company, not bubble-wrapping it, and finding secure solutions that let the business move and flex, rather than defaulting to blanket restrictions. You will work closely with the Director of IT and Security, providing expert recommendations and executing approved plans rather than operating independently. This is a great opportunity to be a part of a dynamic, growing company focused on making an impact on the business, and to help mature a growing security program. This role will serve as the senior technical expert within the Security function at onX. This position will report to the Director of IT and Security.

Security Monitoring and Detection

  • Serve as the team's subject matter expert on the SIEM/EDR platform (SentinelOne), recommending tuning changes and detection coverage improvements.
  • Analyze complex attack vectors, deconstructing adversary behavior and applying threat intelligence to improve detection.
  • Maintain threat models and vulnerability lifecycle metrics across the environment.
  • Partner with the onX Site Reliability Engineering (SRE) team on cloud security monitoring and detection within Google Cloud Platform (GCP), including visibility into infrastructure logging, IAM configuration, and workload security.

Incident Response

  • Execute the incident response playbook, making frontline judgment calls during incidents and escalating major incidents to the Director of IT and Security.
  • Facilitate incident response tabletop exercises and simulations with cross-functional stakeholders to test and improve readiness.
  • Partner with the SRE team during incidents that touch cloud infrastructure, ensuring security and reliability response efforts stay aligned.
  • Lead post-incident analysis and recommend improvements to the playbook based on lessons learned.

Application and Vendor Security

  • Run recurring security audits of business applications, with full coverage of Tier 0 systems.
  • Serve as the subject matter expert on the annual third-party penetration test, including mobile application testing, API endpoint testing, and phishing simulations, and coordinate remediation with product and engineering teams.
  • Conduct vendor security assessments and maintain a recurring re-assessment cadence for Tier 0 and Tier 1 vendors.
  • Collaborate with engineering teams to help design and build secure products throughout the development lifecycle.

Compliance Support

  • Support SOC 2 Type 2 compliance by gathering evidence and responding to auditor requests.
  • Maintain SOC 2 automation tooling (Sprinto) to keep ongoing compliance overhead low.
  • Help maintain security policies, procedures, and Information Security Management System (ISMS) documentation.

Leadership and Process Improvement

  • Partner with the IT and Security manager to prioritize risk reduction efforts across the security program, providing subject matter expertise to inform decisions.
  • Recommend frameworks for risk quantification and incident response automation for the team to review and approve.
  • Build automations and tools that reduce manual effort across the security program, including compliance evidence collection, application audits, and SIEM/EDR maintenance.
  • Identify and build automations that reduce manual security operations work, including identity and access management (IAM) lifecycle tasks.
  • Explore and pilot AI-assisted approaches to security operations tasks, such as alert triage, log analysis, and reporting, and share findings with the team.
  • Evaluate business requests and risk trade-offs to find secure, workable solutions that let teams move quickly, rather than defaulting to blanket restrictions.
  • Mentor other members of the security team.
  • Other ad hoc duties as assigned by the Supervisor

WHAT YOU'LL BRING

  • 7 or more years of experience in security operations, incident response, or a related security role
  • Demonstrated experience tuning and operating SIEM and endpoint detection and response (EDR) platforms
  • Experience leading incident response, including major incident judgment calls and post-incident analysis
  • Working knowledge of vulnerability management and application security testing concepts
  • Clear written and verbal communication skills, including the ability to align leadership and stakeholders on risk
  • Ability to work independently, set standards, and prioritize across monitoring, incident response, and cross-functional projects
  • Working knowledge of Google Cloud Platform (GCP), including IAM, logging, and core infrastructure services
  • Ability to partner effectively with Infrastructure and engineering teams on cloud and application security matters
  • Uses artificial intelligence (AI) tools as a force multiplier for security work, and brings a curious, hands-on approach to using AI rather than treating it as a threat to be avoided
  • Demonstrated experience building scripts, automations, or tools that reduce manual work — for example, in compliance evidence collection, audit workflows, or alert triage
  • Sound judgment in weighing security risk against business need, with a track record of finding secure solutions that let the business move forward rather than defaulting to blanket restrictions
  • Direct experience with SentinelOne or a comparable EDR platform
  • Experience with SOC 2 or a similar compliance framework
  • Experience with GRC automation tools, such as Sprinto
  • Familiarity with mobile application and API security testing
  • Experience with workflow automation tools, such as Workato
  • Proficiency with a scripting language (such as Python) for building automations and tools
  • Relevant industry certification, such as GSEC, GCIH, or CISSP
  • Google Cloud Platform (GCP) and AWS certification, such as Associate Cloud Engineer or Professional Cloud Security Engineer
  • Experience mentoring or informally leading other security team members

WHERE YOU CAN WORK

This role is based onsite in our Bozeman, MT office, alongside the majority of our IT team. This proximity enables the hands-on collaboration and partnership that are important to the role. Relocation assistance may be available for the right candidate.

HOW YOU’LL BE COMPENSATED

onX is committed to compensating all employees fairly and equitably for their contributions. For this position, applicants can expect to make between $136,000 and $170,000 upon hire. The pay range will vary based upon experience, skills, certifications, education, among other factors as required in the job description. In addition, full-time onX employees are eligible for a grant of common share options with a vesting schedule and an annual bonus of 10% based on company performance.

Position open until filled.

At onX, we believe that unique perspectives make us stronger. By bringing together people with different experiences, ideas, and viewpoints, we fuel innovation and move closer to our mission of awakening the adventurer in everyone. We are proud to be an equal opportunity employer and are committed to fairness not only in hiring, but also in development, compensation, and promotion. Our goal is to build an inclusive community where every team member can show up authentically and thrive. Together, we win as one team. Come join us!

Standard company text repeated across onXmaps's postings is omitted here.

Similar positions

Attentive Mobile
Senior Corporate Security Operations Engineer
Attentive Mobile · United States
Orkes
Senior Security Engineer
Orkes · In Office - Santa Clara, CA
Obsidian Security
Lead IT Systems Engineer
Obsidian Security · Palo Alto, CA
Okta
OpenGov
Manager, Application Security
OpenGov · India | Pune