Senior Security Analyst
Job description
About the role
This role guides security strategy for a rapidly expanding K-12 school network. The Senior Security Analyst leads complex initiatives to protect students, families, and staff. The position requires deep expertise in endpoint and cloud security to safeguard sensitive educational data. You will own the design and implementation of security controls across the technology infrastructure. Collaboration with cross-functional teams is essential to align security with business objectives. The role demands rigorous investigation of threats and vulnerabilities to ensure system integrity. You will shape the security roadmap to support the organization's growth and compliance needs. The work is evidence-based and requires clear communication of risk to diverse stakeholders.
Key facts
What you'll do
Collaboration with cloud engineering teams strengthens security for AWS and GCP environments by resolving identified vulnerabilities.
CrowdStrike Falcon and similar endpoint security platforms enable protection of endpoints through risk identification, investigation leadership, remediation driving, and continuous improvement of protections.
Emerging threats and security trends are tracked so that new tools can be recommended and vetted when appropriate.
Requirements for security controls are analyzed and translated into actionable technical specifications for engineering teams.
Design of security architectures ensures alignment with SOC 2, ISO 27001, and FERPA standards across cloud and on-premises systems.
Independent ownership of complex security initiatives is driven from concept through implementation and validation.
Advanced email security platforms such as Sublime, Mimecast, Proofpoint, and Abnormal are evaluated and integrated to enhance protection.
Identity access management platforms such as Okta are configured and managed to enforce least privilege and secure access.
Deep analysis of AWS security architecture, IAM, cloud networking, workload protection, and vulnerability management is conducted to reduce risk.
Clear communication of technical security concepts is delivered to both technical and non-technical audiences to promote organizational awareness.
Security monitoring processes are refined using data and threat intelligence to improve detection and response capabilities.
Gaps in security posture are identified through assessments and audits, with remediation plans developed and prioritized.
Policies and procedures are created to support compliance and best practices in a high-growth educational environment.
Incident response activities are led with precision to minimize impact and ensure thorough documentation and lessons learned.
Requirements
Professional experience in cybersecurity totals 5+ years, including experience independently leading security initiatives within cloud-first organizations.
Hands-on experience with Crowdstrike Falcon or similar endpoint security platforms is required.
Expertise in Google Workspace security administration covers Gmail rules, DLP, and monitoring.
Expertise in advanced email security platforms covers tools such as Sublime, Mimecast, Proofpoint, and Abnormal.
Identity access management platforms such as Okta are used with expertise.
Deep understanding of AWS security architecture, IAM, cloud networking, workload protection, and vulnerability management is required, with WIS experience preferred.
Security controls are designed rather than simply administering security tools.
Complex security initiatives are driven independently from concept through implementation.
Security controls are implemented aligned with SOC 2, ISO 27001, and FERPA.
Security risks are identified and resolved meticulously and tenaciously.
Security concepts are conveyed clearly in written and verbal communication to both technical and non-technical audiences.
Bachelor's degree is required for this role.
Practical notes
Success Academy Charter Schools is an equal opportunity employer.
Typical interview steps
Security interviews usually include a technical assessment, a threat modeling exercise, and behavioral rounds. Candidates may be asked to review a code sample for vulnerabilities or design a secure system. Practical knowledge and clear risk communication are the core skills. Interviewers often ask how you triage and communicate risk. Showing calm judgment under pressure matters as much as technical depth.
Good to know
Security analysts protect organizations by monitoring, detecting, and responding to threats.
Security tools often include endpoint platforms, email gateways, and cloud security suites.
Compliance frameworks such as SOC 2, ISO 27001, and FERPA guide security policies in education.
Cloud environments commonly rely on shared responsibility models for security.
Incident response processes coordinate technical and operational teams during breaches.
Technical guidance helps integrate security into technology decisions early.
Questions to ask
Worth asking in any interview: how the team measures success, who the role works with daily, what the onboarding looks like, and what the company is trying to achieve this year. Asking what past hires did well is a strong final question. Keep the list short and pick the questions that matter most to you.
Career growth
Security careers grow from analyst or engineer to senior, staff, and leadership roles. Specializations include cloud security, application security, and security operations. Certifications help early; demonstrated impact matters later. Security careers reward specialization and a track record of finding and fixing real issues. Written communication of risk is a core skill at senior levels.