Senior Security Analyst
CoLab Software · United States, Remote
Remote · USNew
senior
security analyst
Apply on CoLab Software →
About CoLab
At CoLab, we help mechanical engineering teams bring life-changing products to market years sooner.
CoLab is the AI platform for driving stronger engineering decisions. Every design review in CoLab builds a knowledge repository of design feedback, decisions, and lessons learned - which AI agents draw from to flag issues on future designs before they compound. The more your team works in CoLab, the smarter it gets and the faster you arrive at the ideal design. Companies like Ford, Komatsu, and Johnson Controls use CoLab to catch issues earlier, eliminate rework cycles, and bring products to market faster.
Founded in St. John’s, Newfoundland, CoLab has grown quickly from our first customer in 2019 to a rapidly scaling company. We’ve recently been recognized on Deloitte’s Fast 50™ and Fast 500™, and named a Canadian company to watch by The Globe and Mail and Financial Post.
About the Role
Security at CoLab isn't a compliance exercise. It's a core part of earning and maintaining the trust of some of the world's largest engineering organizations.
As a Senior Security Analyst, you'll help shape the future of our enterprise security program. You'll be a key member of our Blue Team, responsible for protecting CoLab's cloud infrastructure, corporate systems, and customer data while continuously improving how we detect, investigate, and respond to threats.
This is a hands-on technical role reporting to our CISO. You'll spend time investigating alerts, leading incident response efforts, refining detection capabilities, improving security controls, and helping teams make sound security decisions before problems emerge.
You won't be handed a mature playbook and asked to follow it. You'll help build it. If you enjoy solving complex security problems, taking ownership, and balancing strong technical judgment with practical business decisions, you'll likely find this role rewarding.
Our Ideal Candidate
You're the type of person who sees an alert and wants to understand the full story—not just close the ticket.
You can move comfortably between technical investigation, risk discussions, and stakeholder communication. During an incident, you're calm, methodical, and focused on facts. Afterward, you're just as interested in improving systems and processes to prevent it from happening again.
You'll thrive here if you enjoy:
Solving difficult security problems with incomplete information
Taking ownership of outcomes, not just tasks
Learning continuously as technologies and threats evolve
Working closely with Security, Technology, and Product teams
Balancing strong security practices with business realities
Job Responsibilities
Lead investigation and response activities for security incidents, suspicious activity, and emerging threats
Design, implement, and improve security monitoring, detection, and response capabilities across our AWS environment
Develop and maintain effective detection rules, alerting strategies, and investigation procedures
Conduct post-incident reviews to identify root causes, lessons learned, and preventative measures
Identify security exposures, vulnerabilities, misconfigurations, and non-compliance risks and communicate recommendations clearly
Perform security assessments of third-party vendors, services, and technologies
Partner with Technology and Product teams to design secure solutions and strengthen existing controls
Support vulnerability management, threat modeling, and endpoint security initiatives
Create and maintain security documentation, standards, and operational procedures
Contribute to security awareness efforts and provide guidance on secure business practices
Stay current on evolving threats, attacker techniques, and defensive technologies
Authorizes/approves user access to CoLab
Coordinates with relevant CoLab AI teams for program functions wholly or partially implemented at the corporate level (i.e., general security training)
Develops and maintains an accurate and up-to-date System Security Plan (SSP)Package for the FedRAMP-designated system
Distributes copies of SSP Package elements to relevant team members, on a need-to-know basis
Designates key personnel as responsible for core program functions (i.e., incident handling, disaster recovery, etc.)
Receives operational alerts, updates, and status reports from team members and critical system components
Oversees the Continuous Monitoring Program for CoLab
Reports the security and privacy state of CoLab to external entities (i.e., CustomerAgencies, FedRAMP Program Management Office (PMO), Third Party AssessmentOrganizations (3PAOs)
Qualifications
Required:
US Citizenship, living in the USA
5+ years of experience in security operations, security engineering, or a similar cybersecurity role
Strong experience with security monitoring, incident response, threat detection, and forensic investigations
Deep understanding of network security, application security, infrastructure hardening, and vulnerability management
Experience deploying, managing, and automating security solutions in cloud environments
Strong knowledge of AWS architecture, security services, and cloud security best practices
Experience working with macOS, Linux, and Windows environments
Strong understanding of log collection, analysis, and security event investigation
Experience developing and maintaining security procedures and operational processes
Ability to communicate technical risks and recommendations clearly to both technical and non-technical audiences
Experience supporting compliance initiatives such as SOC 2, ISO 27001, GDPR, FedRAMP or PIPEDA
Nice to Have
Experience with threat modelling programs
Experience building security automation workflows
Experience assessing third-party vendors and SaaS platforms
Security certifications such as CISSP, GCIH, GSEC, Security+, AWS Certified Security – Specialty, or AWS Certified Solutions Architect
The Extra Details
This is a full-time, permanent position with a competitive compensation package that includes stock options
Comprehensive health and benefits coverage
Unlimited paid vacation
401K matching
This role can be performed remotely from anywhere in the United States of America
Equity Note
Frequently cited statistics show that people who identify with historically marginalized groups are likely to apply to jobs only if they meet 100% of the qualifications. We encourage you to help us break that statistic and apply even if you don’t meet every single qualification—your potential is what matters most to us.
Posted 2026-07-30