Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Analyst III

Allegiant

Job Description

Job Description

Summary

An individual contributor that serves as a senior individual contributor on the cybersecurity operations team, responsible for the day-to-day operation, tuning, and continuous improvement of the enterprise cybersecurity toolset. This role owns advanced detection and response work across endpoint, identity, application and cloud surfaces; leads investigations of escalated alerts; builds automation that removes manual effort from repeatable security tasks; and translates threat intelligence and vulnerability data into prioritized, actionable remediation for platform and application owners.

Visa Sponsorship Available

No

Minimum Requirements

Combination of Education and Experience will be considered. Must be authorized to work in the US as defined by the Immigration Act of 1986. Must pass a Criminal Background Check.

Education: Bachelor’s Degree

Education Details:

Bachelor's degree in Computer Science, Software Engineering or related field or equivalent combination of education and experience.

Certification: Yes

Certification Details:

Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Offensive Security Certified Professional (OSCP), or any related industry certifications.

Years of Experience:

  • Minimum six (6) years of experience in information security.

  • Minimum two (2) years of project or team lead experience.

Credit Check: No

Valid/Unexpired Passport Book: Yes
Valid/Unexpired Driver's License: Yes

  • Master's degree in Computer Science or relevant field.

Preferred Requirements
  • Eight (8) or more years of cybersecurity experience, including time in a security operations center or incident response function.

  • Industry certification such as CISSP, GCIH, GCIA, GCFA, GSEC, CySA+, or vendor certification in EDR, SIEM, identity, or cloud security.

  • Experience building security automation and orchestration playbooks that integrate multiple tools through APIs.

  • Experience operating a threat intelligence program, including managing intelligence feeds, tracking threat actors relevant to the industry, and producing intelligence-driven detections.

  • Experience with detection-as-code practices: version control, peer review, and CI/CD pipelines for detection and automation content.

  • Experience integrating SAST, DAST, software composition analysis (SCA), and secrets scanning into CI/CD pipelines, including quality gates and build-breaking policy.

  • Experience with interactive application security testing (IAST), runtime application self-protection (RASP), API security testing, or bot and fraud mitigation capabilities layered with a WAF.

  • Secure code review ability in one or more languages used for web and API development, and familiarity with threat modeling for new features and services.

  • Experience with PCI DSS requirements applicable to public-facing web applications, including WAF or equivalent control requirements and application penetration testing obligations.

  • Cloud security experience in a major public cloud provider, including native logging and identity services.

  • Familiarity with identity threat detection and response concepts, including privileged access management and detection of identity-based attack techniques.

  • Experience in a regulated environment subject to requirements such as PCI DSS, SOX, or aviation-sector regulatory oversight.

  • Experience supporting operational technology or specialized business systems in addition to corporate IT.

  • Experience mentoring analysts, developing runbooks, and leading tabletop or purple team exercises.

Job DutiesEndpoint Detection and Response
  • Operate and tune the enterprise EDR platform; investigate escalated detections, perform host triage and containment, and drive eradication and recovery actions.

  • Develop and maintain custom detections, exclusions, and response policies; validate coverage against known attacker techniques.

  • Monitor agent health and deployment coverage across the endpoint and server estate and work with platform teams to close gaps.

Automation and Orchestration
  • Design, build, test, and maintain automation and orchestration playbooks that reduce manual analyst effort in triage, enrichment, containment, and reporting.

  • Integrate security tools through APIs to move context automatically between detection, ticketing, identity, and asset systems.

  • Maintain automation content in version control with peer review; measure and report time saved and error reduction.

Security Information and Event Management
  • Develop, tune, and maintain correlation rules, use cases, dashboards, and alerts in the SIEM; reduce false positives while preserving detection coverage.

  • Onboard new log sources, validate parsing and field normalization, and confirm data completeness and retention against monitoring and compliance requirements.

  • Perform threat hunting and historical analysis across aggregated log data to identify activity that automated detections missed.

Threat Intelligence
  • Consume, evaluate, and operationalize intelligence from commercial feeds, open sources, industry sharing groups, and government partners; convert relevant intelligence into detections, hunts, and blocking decisions.

  • Track threat actors, campaigns, and techniques targeting the aviation, travel, hospitality, and payment sectors and brief stakeholders on relevance and recommended action.

  • Produce concise written intelligence summaries for technical teams and leadership.

Vulnerability Management
  • Operate scanning and assessment capabilities across endpoints, servers, cloud workloads, containers, and network devices; validate findings and eliminate false positives.

  • Prioritize vulnerabilities using severity, exploitability, threat intelligence, asset criticality, and exposure; partner with system owners to define remediation plans and track them to closure.

  • Report on remediation performance against defined service levels and escalate aging or high-risk exposures through the established risk process.

Application Security — Static Testing (SAST)
  • Operate the static analysis platform: onboard repositories, configure language and framework coverage, tune rulesets, and maintain baselines for legacy code.

  • Integrate static scanning into developer workflows and CI/CD pipelines; define and administer quality gates and policy thresholds in partnership with engineering.

  • Triage static findings to remove false positives, confirm exploitable issues, and provide developers with specific, code-level remediation guidance and secure coding patterns.

  • Support software composition analysis and secrets detection for third-party libraries, open-source dependencies, and credential leakage in source repositories.

Application Security — Dynamic Testing (DAST)
  • Plan, schedule, and execute dynamic scans against web applications and APIs across pre-production and production environments, including authenticated scanning and API-definition-driven testing.

  • Validate and reproduce dynamic findings, assess real-world exploitability and business impact, and route prioritized results into the remediation and risk-tracking process.

  • Support and help scope third-party penetration tests and application assessments, and track resulting findings to closure.

Web Application Firewall
  • Operate and tune the web application firewall protecting customer-facing and internal web applications and APIs: managed rule sets, custom rules, rate limiting, geo and reputation controls, and bot mitigation.

  • Move new rules through detection only to blocking mode using traffic analysis, minimizing false positives, and avoiding disruption to legitimate customer traffic.

  • Monitor and investigate WAF telemetry and blocked-event trends; correlate WAF logs into the SIEM and build detections for application-layer attack patterns, credential stuffing, scraping, and abuse.

  • Support onboarding new applications and domains behind the WAF, including policy design, exclusion management, and validation testing with application teams.

  • Maintain WAF configuration documentation and evidence supporting applicable regulatory and payment-industry control requirements.

Single Sign-On and Identity Protection
  • Support and maintain SSO integrations for enterprise and third-party applications, including federation configuration, application onboarding, and access policy design.

  • Configure and tune multifactor authentication, conditional access, and identity risk policies; investigate identity-based alerts such as impossible travel, MFA fatigue, token theft, and privilege escalation.

  • Monitor privileged and service accounts, review access anomalies, and support access certification and least-privilege initiatives with the identity and access management team.

Incident Response and General Responsibilities
  • Act as an escalation point for security incidents; lead or support investigation, evidence preservation, containment, and post-incident documentation and lessons learned.

  • Maintain runbooks, detection documentation, and operational procedures; contribute to tabletop and purple team exercises.

  • Mentor junior analysts on investigative techniques, tooling, and quality of documentation.

  • Support audit, assessment, and regulatory evidence requests related to security monitoring, vulnerability management, and access controls.

  • Handle sensitive data — including payment, personal, and crew or employee data — in accordance with company policy and applicable regulatory requirements.

  • Clear written and verbal communication skills, including the ability to document investigative findings for both technical and non-technical audiences.

  • Ability to participate in an on-call rotation and respond to security events outside normal business hours.

  • Other duties as assigned.

Physical Requirements

The Physical Demands and Work Environment described here are a representative of those that must be met by a Team Member to successfully perform the essential functions of the role. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the role.

Physical Demands / Work Environment

Office - While performing the duties of this job, the Team Member is regularly required to stand, sit, talk, hear, see, reach, stoop, kneel, and use hands and fingers to operate a computer, key board, printer, and phone. May be required to lift, push, pull, or carry up to 20 lbs. May be required to work various shifts/days in a 24-hour situation. Regular attendance is a requirement of the role. Exposure to moderate noise (i.e. business office with computers, phones, printers, and foot traffic), temperature and light fluctuations. Ability to work in a confined area as well as the ability to sit at a computer terminal for an extended period of time. Some travel may be a requirement of the role.

Essential Services Provider

Allegiant as a national air carrier is deemed an essential service provider during declared national and state emergencies. Team Members will be required to report to their assigned trip or work location during national and state emergencies unless prohibited by local, state or federal order.

EEO Statement

We welcome all individuals from varied backgrounds and experiences to apply. Our company values the unique perspectives and talents that each person brings to our team.

Equal Opportunity Employer: Disability/Veteran

For more information, see

Full Time Benefits:

Profit Sharing

Medical/Dental/Vision/Life/ Disability Insurance

Medical Travel Reimbursement

Legal, Identity and Pet Insurance

401K with an employer match

Employee Stock Purchase Plan

Employee Assistance Program

Tuition Reimbursement

Flight Benefits

Paid vacation, holidays, and sick time

Part Time Benefits:

Profit Sharing

Medical Travel Reimbursement

Legal, Identity and Pet Insurance

401K with an employer match

Employee Stock Purchase Plan

Employee Assistance Program

Tuition Reimbursement

Flight Benefits

Sick time

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Information Security Analyst III in Minneapolis, MN vacancy
  • $94.4k - $129.8k

     ...About The Role Participates in projects and assessments as a security consultant or advisor on risk. Researches general and industry...  ...security trends. Analyzes, defines security policies and information security standards. Provides detail to project teams regarding... 
    Suggested
    Ongoing contract
    Temporary work

    COUNTRY Financial

    Minneapolis, MN
    3 days ago
  • $60k - $80k

     ...IT Security Analyst The IT Security Analyst role will assess information risk, track vulnerabilities, and facilitate remediation of vulnerabilities across Corporate IT. Responsibilities Essential Functions Facilitates and manages risk remediation tasks, track... 
    Suggested
    Daily paid
    Temporary work
    Summer work
    Work at office

    C1

    Minneapolis, MN
    4 days ago
  •  ...Paid holidays. ~ Health and wellness programs and MORE! Position Summary: The IT SECURITY ANALYST III is responsible for implementing and supporting information security engineering for all Johns Hopkins Health Plans (JHHP) information systems. Reviews regulatory... 
    Suggested
    Full time

    Johns Hopkins Medicine

    Hopkins, MN
    2 days ago
  • $80k - $100k

    Description:: Under the direction of the Director, Information Security, the Information Security Compliance Analyst supports the execution, administration, and continuous improvement of ImageTrend's cybersecurity compliance, governance, and risk management programs... 
    Suggested
    Full time
    Remote work

    ImageTrend

    Eagan, MN
    2 days ago
  • $94k - $151k

     ...The Security Analyst will work across Security, Engineering, Product, Cloud Operations, IT, Compliance, and other business teams to assess...  ...Set You Apart: ~3–5 years of experience in cybersecurity, information security, technology risk, cloud security, security... 
    Suggested
    Permanent employment
    Relocation

    Epicor Inc

    Minneapolis, MN
    1 day ago
  • $90k - $115k

     ...due to Department of Defense restrictions. Our Senior Security Policy Analyst is responsible for developing, implementing, and maintaining...  .... Can support AI governance awareness programs to inform employees about responsible AI use, ethical considerations,... 
    Contract work
    For contractors
    Work at office
    Local area
    Immediate start
    Remote work
    3 days per week

    WPS Health Solutions

    Minneapolis, MN
    4 days ago
  • $76.4k - $138.6k

     ...Today’s world is fueled by vast amounts of information. Data is more valuable than ever before....  ..., and everyone in EY Information Security has a critical role to play. Join a global...  .... Opportunity As an Offensive Security Analyst on the Vulnerability Management team, you... 
    Summer holiday
    Flexible hours

    EY

    Minneapolis, MN
    1 day ago
  • $108.2k - $140k

     ...collaborate closely across exposure management, security engineering, and cloud security.This...  ...stakeholders, and keeping leadership informed with clear, timely updates. Document...  ...provide coaching and feedback that helps analysts grow.Participate in the team's on-call rotation... 
    Full time
    Work at office
    Local area
    Remote work

    SPS Commerce

    Minneapolis, MN
    7 days ago
  • $81.9k - $139.7k

     ...supports the design, configuration, and maintenance of Workday security, ensuring secure, compliant, and scalable access across HCM...  ...to a position in California, please click here for additional information.At RSM, an employee’s pay at any point in their career is intended... 
    Full time
    Work experience placement
    Internship
    Local area

    RSM International

    Minneapolis, MN
    4 days ago
  • $90k - $132k

     ...organizations like Digiday, Google, Inc. 5000, USA Today, and Search Engine Land.About the RoleOvative Group is seeking a Security Analyst to join our growing Information Security team. Reporting to the Head of Information Security and Privacy, this roleowns the operational core... 
    Full time
    Work at office

    Ovative Group

    Minneapolis, MN
    6 days ago
  • $95k - $125k

     ...Security Analyst Legence (Nasdaq: LGN) is a leading provider of engineering, consulting, installation, and maintenance services for mission...  ...to enhance and mature the security of the organization's information systems. Key Responsibilities: Cloud Security:... 
    Work at office
    Local area
    Immediate start
    Flexible hours

    Black Bear Energy Inc.

    Minneapolis, MN
    5 days ago
  • $105.63k - $130.49k

     ...things.YOUR OPPORTUNITYAs the Financial Analyst III/Sr. Financial Analyst you will support...  ...Visit our Perks & Benefits page for more information on these offerings:Health & Family...  ...or sensitive information such as Social Security numbers. If you’re unsure about the legitimacy... 
    Full time
    Work at office
    Worldwide

    Greenheck Group

    Minneapolis, MN
    3 days ago
  • $140k - $175k

     ...accommodation or an alternative application process. Principal Security Analyst, Governance Risk, and Compliance Full Time Professional...  ...compliance function and is a member of a larger, multi-site Information Systems and Security team that supports HistoSonics as a whole... 
    Full time
    Contract work
    Temporary work
    Work at office
    Visa sponsorship

    HISTOSONICS INC

    Minneapolis, MN
    1 day ago
  • $85.1k - $154.42k

     ...Job Duties What you'll do at Jamf: The Security Risk & Compliance Analyst (Analyst) is responsible for ensuring that Jamf ‘s security controls, policies, and procedures are implemented in accordance with applicable laws, regulations, and industry standards. Reporting... 
    Full time
    Work at office
    Remote work
    Worldwide
    Shift work

    JAMF Software LLC

    Minneapolis, MN
    4 days ago
  • $102.55k - $126.68k

    Financial Analyst III page is loaded## Financial Analyst IIIremote type: Hybridlocations:...  ...Enterprise Resource Planning system into usable information.* Utilize several different software...  ...:* Health & Family Support* Financial Security* Learning & Development* Rewards &... 
    Work experience placement
    Work at office

    Greenheck Group

    Minneapolis, MN
    1 day ago
  • $75k - $95k

     ...Overview What You'll Be Doing This Junior Security Analyst role will have client facing responsibilities that encompass security analyst...  ...are strengthening society and the natural world. For more information, visit cadmusgroup.com . Responsibilities ~1-2 years of... 
    Permanent employment
    Work experience placement
    Local area
    Worldwide

    Cadmus, LLC

    Saint Paul, MN
    2 days ago
  • $65k - $70k

     ...Type Full Time Education Level 4 Year Degree Category Information Technology Description Work Where You Matter! At St...  ...team of caregivers, then come work where you matter. Security Operations Analyst Position Overview The IT Security Analyst is... 
    Full time
    Work experience placement

    St Croix Hospice

    Saint Paul, MN
    3 days ago
  • $105.4k - $207.8k

     ...Microsoft Purview capabilities that advance data governance, information protection, and regulatory compliance. This role offers the opportunity...  ...activities for Microsoft Purview and adjacent Microsoft security and compliance technologies.Advising clients on data... 
    Local area
    Visa sponsorship

    Deloitte

    Minneapolis, MN
    7 days ago
  • $52k - $101k

     ...Business Analyst 3 The Business Analyst 3 provides advanced support for assigned business process and/or system within a business unit. Duties & Responsibilities: Maintains, monitors, updates assigned business process and/or system. Researches complex problems... 
    Full time
    H1b
    Work at office
    Remote work
    Work from home
    Flexible hours

    Huntington

    Minneapolis, MN
    3 days ago
  • $105.4k - $207.8k

    Position Summary Cisco Network Security Engineer/ Senior Consultant, Strategy, Growth, and TransformationDeloitte’s Cyber business...  ...architectures, integrating Cisco platforms with security information and event management (SIEM) tools and automation solutions, and... 
    Work experience placement
    Local area
    Visa sponsorship

    Deloitte

    Minneapolis, MN
    5 days ago
  • $133.8k - $170k

     ...adherence to engineering best practices, coding standards, and security protocols. Incident & problem management: Manage and resolve...  ...Qualifications: Education: Bachelor’s degree in Computer Science, Information Technology, Data Engineering, or a related field. Proven... 
    Full time
    Work at office
    Local area

    SPS Commerce

    Minneapolis, MN
    4 days ago
  • $90k - $160k

     ...care for high-risk data to comply with the firm’s Enterprise Information Management (IM) Risk Policy and extend the standards of care to...  ...Privacy, Decision Making, Information Management, Information Security Management, Interpersonal Relationship Management, Risk Management... 
    Full time
    Work at office
    Flexible hours

    Royal Bank of Canada

    Minneapolis, MN
    3 days ago
  • $56.6k - $97k

     ...norm and every member feels valued. The Provider Network Data Analyst III ensures the accuracy, integrity, and timely distribution of...  ...benefits to support our employees. The compensation and benefits information is provided as of the date of this posting. Medica's... 
    Work experience placement
    Work at office
    3 days per week

    Medica

    Minnetonka, MN
    5 days ago
  • $86k - $100k

     ...We currently have an opportunity for a Quantitative Investment Analyst to join our Intact Investment Management team based in our Plymouth...  ...and validate large datasets including market data, fundamental security level data, macroeconomic data, and alternative data sources.... 
    Full time
    Work at office
    Flexible hours

    Intact Services USA LLC

    Minneapolis, MN
    17 days ago
  • $110k - $160k

     ...best practices for data ownership, quality, metadata, lineage, security, data products, and lifecycle management.Partner with business...  ...business leaders, Quality, Privacy, Legal, Regulatory, and Information Security teams to ensure data governance practices support regulatory... 
    For contractors
    Work experience placement
    Local area
    Flexible hours

    Inspire Medical Systems

    Minneapolis, MN
    3 days ago
  • $22.84 per hour

     ...Allied Universal®, North America’s leading security and facility services company, offers...  ...SOC (Security Operations Center) Security Analyst will be assigned to furthering the...  ...and safety of client staff, assets and information Monitor operational network video cameras... 
    Part time
    Work at office
    Local area
    Remote work
    Shift work

    Allied Universal

    Saint Paul, MN
    2 days ago
  • Medica, a nonprofit health plan serving Minnesota and surrounding states, is seeking a Provider Network Data Analyst III to ensure accuracy and timely distribution of provider data across PNOM systems. The role leads complex data analysis, troubleshoots issues with IT teams... 
    Work at office

    Medica

    Minnetonka, MN
    5 days ago
  • $109.3k - $164k

    SUMMARY Mortenson is currently seeking a MEP Estimator III - Process Piping that will be responsible for leading estimating efforts...  ...complete and reliable estimates incorporating all relevant information, adjusting assignments as neededDetermine trade partner strategy... 
    For contractors
    H1b
    Work at office
    Local area

    Mortenson

    Minneapolis, MN
    3 days ago
  • $88k - $132k

     ...Cardiovascular portfolio, helping to inform business decisions and support...  ....As a Senior Financial Analyst supporting the GOSC Strategic...  ...requirements of 8 C.F.R. § 214.2(h)(4)(iii)(A) is required.Physical Job...  ...as bank account or Social Security details) during early stages... 
    Full time
    H1b
    Work at office
    Local area
    Immediate start
    Flexible hours

    Medtronic

    Minneapolis, MN
    4 days ago
  • $152.7k - $294k

     ...Global Information Security Strategist At EY, we're all in to shape your future with confidence. We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world... 
    Summer holiday
    Flexible hours
    Shift work

    Minnesota Jobs

    Minneapolis, MN
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Analyst III. Be the first to apply!