ForgeApply · Job listing
Sr. Security Analyst
Bdainc
Apply in about a minute — without sacrificing quality.
ForgeApply autofills this application and tailors your resume to this exact posting. You review everything before it's sent. Free trial, no card required.
About this role
Most companies claim to have the best people. We say to them, "Keep dreaming." Our people are second to none. They set us apart with their entrepreneurial spirit and ambition. They come to us from the likes of Amazon, Microsoft, Nordstrom, Starbucks and the sports world, bringing energy, bold ideas and a willingness to dive into the unfamiliar. It's our people that make BDA the top global Merchandise Agency to work for.
Location:
• This role is based in Woodinville, WA and requires you to work onsite 4 days per week , with 1 day remote .
• To be considered, you must live within commuting distance , as regular in-person collaboration is a key part of the role.
Job Summary
BDA is looking for a Senior Security Analyst who can help us strengthen our security program and move from a primarily reactive approach to a more proactive, planned security strategy.
This role will have a strong focus on application, cloud, and infrastructure security. You will identify vulnerabilities, test applications and environments, evaluate potential exploits, and work closely with IT and business partners to reduce risk across the organization.
You will also have the opportunity to help define what the red-team security function looks like at BDA. We are open to an experienced mid-level professional who has strong application security skills and is ready to continue growing, as well as a more seasoned security professional seeking broad ownership and meaningful challenges.
What You’ll Do
• Conduct vulnerability scans, penetration testing, and security assessments across applications, systems, cloud environments, and infrastructure.
• Use tools including Tenable Nessus, Burp Suite, and CrowdStrike to identify vulnerabilities, investigate threats, and recommend remediation.
• Test web applications to identify potential exploits, attack paths, and security weaknesses.
• Evaluate the security of Linux-based and cloud environments, including AWS, OCI, and Azure.
• Partner with infrastructure and engineering teams to improve system configurations, hardening standards, access controls, and overall security posture.
• Monitor security events, investigate potential incidents, and support incident response and forensic activities.
• Conduct account reviews, access reviews, risk assessments, and other security-related analysis.
• Develop clear reports and recommendations for technical teams, business leaders, and executive stakeholders.
• Help establish repeatable security processes, priorities, and testing practices that allow the organization to address risks proactively.
• Collaborate with security team members, consultants, IT infrastructure, engineering, legal, compliance, and business teams across BDA.
• Support the development and ongoing improvement of security policies, procedures, standards, and employee awareness initiatives.
• Stay current on emerging threats, vulnerabilities, attack methods, and security best practices.
Required Qualifications
• Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
• Professional experience in information security, application security, infrastructure security, or a closely related area.
• Hands-on experience with all of the following: Microsoft Defender, Microsoft Purview, CrowdStrike, Tenable Nessus, and Burp Suite
• Proven experience with application and environment security, vulnerability testing, exploit testing, penetration testing, or vulnerability scanning.
• Strong understanding of cloud security and experience securing environments such as AWS, OCI, or Azure.
• Experience working with Linux environments and securing cloud-based or distributed infrastructure.
• Knowledge of security frameworks and standards such as NIST, CIS, or ISO 27001.
• Understanding of risk management practices and the ability to identify, prioritize, and communicate security risks.
• Working knowledge of security technologies such as firewalls, IDS/IPS, endpoint security, SIEM, and enterprise intrusion-prevention systems.
• Experience with system-hardening standards for servers, desktops, laptops, or network devices.
• Understanding of malware, attack vectors, network threats, incident response, authentication, and access-control technologies.
• Knowledge of internet protocols and security technologies, including HTTP, TLS, SSL, HTML, and XML.
• Understanding of cloud, container-based, and virtualized architectures.
• Knowledge of encryption techniques, standards, and appropriate encryption levels.
• Strong analytical, problem-solving, and attention-to-detail skills.
• Clear communication skills and the ability to work effectively across technical and nontechnical teams.
• A collaborative and humble working style, with the ability to accept direction, execute priorities, and remain open to the perspectives of others.
Preferred Qualifications
• Previous experience in an IT infrastructure, systems administration, networking, DevOps, or engineering role before moving into security.
• Experience that combines technical security with governance, risk, compliance, or privacy responsibilities.
• Familiarity with privacy regulations such as GDPR, CPRA, or CCPA.
• Experience with firewalls, load balancers, web application firewalls, or VPN concentrators.
• Experience with databases and related technologies such as Elasticsearch, SQL, or Oracle.
• Experience handling and protecting information across different sensitivity levels.
• Familiarity with standards or regulations such as FISMA, GLBA, FERPA, PCI DSS, ISO, or NIST.
• Higher education or government information-security experience.
• Security certifications such as CISSP, CISA, CISM, CEH, GWAPT, GPEN, CSFA, or similar credentials .
• Experience with SUMO Cloud or comparable security monitoring and log-analysis tools.
Why This Role?
• This is an opportunity to do more than maintain an existing security program. You will help shape how BDA approaches red-t
Salary insight
The midpoint of this range ($125k) is about 23% below the median disclosed salary for Washington DC roles listed on ForgeApply ($161k across 490 jobs).
See full Security Engineer salary data for Washington DC →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Ready to apply to Bdainc?
Apply in about a minuteSimilar jobs
- Senior Security Analyst — Colabsoftware · Remote
- Sr. Security Engineer — Brave · Remote
- Senior Security Analyst I — Digitalocean98 · Remote
- Senior Security Analyst I — Digitalocean98 · Seattle
- Senior Security & Compliance Analyst — Hs · Santa Monica, California, United States
- Senior Security and Compliance Analyst — Insurify · Cambridge, MA - Hybrid
- Sr. Security Engineer II — Iherb · Remote
- Sr. Application Security Engineer — Esri · Redlands, CA
More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in Washington DC · More jobs at Bdainc · Browse all jobs