Onxmaps
Senior Security Analyst
Bozeman, Montana, United States · Austin, Texas, United States · Denver, Colorado, United States · Free Solo · Minneapolis, Minnesota, United States · Missoula, Montana, United States · Portland, Oregon, United States · Salt Lake City, Utah, United States · Seattle, Washington, United States
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Senior
- Country
- US
- Work mode
- On-site / unstated
- First seen by hirly
- 3 Oct 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
ABOUT onX
We’re a team of builders, adventurers, and risk takers using technology to help people confidently explore the outdoors. Driven by our mission to awaken the adventurer inside everyone, we build products that optimize every outdoor experience and inspire confidence to get out and go further.
We’re a high-growth tech company. The pace is fast, the work takes grit, and ambiguity is part of the job. As the world changes around us, we adapt - continuously evolving how we build, prioritize, and deliver.
Our business moves quickly, and there’s real opportunity to shape what we build next. Each of our verticals - Hunt, Offroad, Backcountry, and Fish - is at a different stage of maturity, which means the challenges you encounter and the impact you have will vary depending on where you sit and what the business needs most.
We operate with an experimentation mindset, continually iterating and improving how we solve problems. We expect our people to use the latest tooling, including AI, thoughtfully and responsibly, pairing human judgment with technology to increase quality, speed, and impact.
Our impact comes to life through the products we build, in the stories of our customers, and in our growing commitment to land stewardship and recreational access.
ABOUT THIS OPPORTUNITY
onX is seeking a Senior Security Analyst I with a passion for protecting the systems, data, and customers that make onX's products possible. As an onX Senior Security Analyst I, you will serve as the team's subject matter expert on day-to-day security operations, incident response, and application and vendor security. Your focus will be on security monitoring and detection, incident response execution, and application security testing, with a supporting role in compliance activities such as SOC 2 evidence collection. This role also partners closely with the onX Site Reliability Engineering (SRE) team, so a working understanding of Google Cloud Platform (GCP) is important to day-to-day work. onX views artificial intelligence (AI) as a powerful tool for strengthening security work, not something to fear, and this role should bring that same mindset.
This is a hands-on role: onX cannot do this work by hand at scale, so you will build the automations and tools needed to reduce manual effort across compliance evidence collection, application audits, and monitoring. You will also need to see your job as educating the company, not bubble-wrapping it, and finding secure solutions that let the business move and flex, rather than defaulting to blanket restrictions. You will work closely with the Director of IT and Security, providing expert recommendations and executing approved plans rather than operating independently. This is a great opportunity to be a part of a dynamic, growing company focused on making an impact on the business, and to help mature a growing security program. This role will serve as the senior technical expert within the Security function at onX. This position will report to the Director of IT and Security.
- WHAT YOU'LL DO
- Essential Job Duties & Functions
Security Monitoring and Detection
Serve as the team's subject matter expert on the SIEM/EDR platform (SentinelOne), recommending tuning changes and detection coverage improvements.
Analyze complex attack vectors, deconstructing adversary behavior and applying threat intelligence to improve detection.
Maintain threat models and vulnerability lifecycle metrics across the environment.
Partner with the onX Site Reliability Engineering (SRE) team on cloud security monitoring and detection within Google Cloud Platform (GCP), including visibility into infrastructure logging, IAM configuration, and workload security.
Incident Response
Execute the incident response playbook, making frontline judgment calls during incidents and escalating major incidents to the Director of IT and Security.
Facilitate incident response tabletop exercises and simulations with cross-functional stakeholders to test and improve readiness.
Partner with the SRE team during incidents that touch cloud infrastructure, ensuring security and reliability response efforts stay aligned.
Lead post-incident analysis and recommend improvements to the playbook based on lessons learned.
Application and Vendor Security
Run recurring security audits of business applications, with full coverage of Tier 0 systems.
Serve as the subject matter expert on the annual third-party penetration test, including mobile application testing, API endpoint testing, and phishing simulations, and coordinate remediation with product and engineering teams.
Conduct vendor security assessments and maintain a recurring re-assessment cadence for Tier 0 and Tier 1 vendors.
Collaborate with engineering teams to help design and build secure products throughout the development lifecycle.
Compliance Support
Support SOC 2 Type 2 compliance by gathering evidence and responding to auditor requests.
Maintain SOC 2 automation tooling (Sprinto) to keep ongoing compliance overhead low.
Help maintain security policies, procedures, and Information Security Management System (ISMS) documentation.
Leadership and Process Improvement
Partner with the IT and Security manager to prioritize risk reduction efforts across the security program, providing subject matter expertise to inform decisions.
Recommend frameworks for risk quantification and incident response automation for the team to review and approve.
Build automations and tools that reduce manual effort across the security program, including compliance evidence collection, application audits, and SIEM/EDR maintenance.
Identify and build automations that reduce manual security operations work, including identity and access management (IAM) lifecycle tasks.
Explore and pilot AI-assisted approaches to security operations tasks, such as alert triage, log analysis, and reporting, and share findings with the team.
Evaluate business requests and risk trade-offs to find secure, workable solutions that let teams move quickly, rather than defaulting to blanket restrictions.
Mentor other members of the security team.
Other ad hoc duties as assigned by the Supervisor
WHAT YOU’LL BRING
7 or more years of experience in security operations, incident response, or a related security role
Demonstrated experience tuning and operating SIEM and endpoint detection and response (EDR) platforms
Experience leading incident response, including major incident judgment calls and post-incident analysis
Working knowledge of vulnerability management and application security testing concepts
Clear written and verbal communication skills, including the ability to align leadership and stakeholders on risk
Ability to work independently, set standards, and prioritize across monitoring, incident response, and cross-functional projects
Working knowledge of Google Cloud Platform (GCP), including IAM, logging, and core infrastructure services
Ability to partner effectively with Infrastructure and engineering teams on cloud and application security matters
Uses artificial intelligence (AI) tools as a force multiplier for security work, and brings a curious, hands-on approach to using AI rather than treating it as a threat to be avoided
Demonstrated experience building scripts, automations, or tools that reduce manual work — for example, in compliance evidence collection, audit workflows, or alert triage
Sound judgment in weighing security risk against business need, with a track record of finding secure solutions that let the business move forward rather than defaulting to blanket restrictions
ADDED BONUSES
Though not required, we would be thrilled to consider candidates with any of the following:
Direct experience with SentinelOne or a comparable EDR platform
Experience with SOC 2 or a similar compliance framework
Experience with GRC automation tools, such as S
Similar jobs
- Senior Data Security AnalystSherwin Williams · Cleveland, OH, United StatesFirst seen today
- Sr Cyber Security Analyst- Vulnerability ManagementSrsdistribution · 2 LocationsFirst seen today
- Senior Security AnalystBlacksky · Seattle, WA, Herndon, VA, RemoteFirst seen todayremote
- Information Security Analyst-Senior (RMF)Caci · Fort Bragg, NC, USFirst seen today
- Sr Security AnalystLennar · Springfield IL - VirtualFirst seen yesterday
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job