IT Security Analyst

Who You'll Work With

In this role, you will collaborate closely with internal teams such as IT, Legal, Compliance, and HR to assess and manage risks affecting business operations. You will work directly with security teams, including network security, cloud security, and security operations, to align risk management efforts and identify vulnerabilities. You will also partner with the Compliance team to ensure adherence to regulatory requirements and industry best practices, and regularly communicate with senior management to report on risk assessments, mitigation strategies, and opportunities for improvement across the organization.

What You’ll Do

  • Conduct in-depth penetration testing of cloud environments (AWS, Azure, GCP), focusing on identifying complex vulnerabilities and security misconfigurations.
  • Perform penetration testing of containerized applications (Docker, Kubernetes) and serverless architectures.
  • Develop and execute custom penetration testing methodologies and tools to simulate real-world attacks.
  • Expertise in manual penetration testing techniques and the use of advanced offensive security tools (Burp Suite, Cobalt Strike, Metasploit, etc.).
  • Utilize commercial security tools such as Checkmarx, Invicti, and Synopsys for static and dynamic analysis.
  • Familiarity with security frameworks and approaches such as SAST, DAST, fuzzing, property-based testing, symbolic execution, and network simulation.
  • Perform comprehensive security assessments of RESTful and other API architectures.
  • Demonstrated ability to identify and exploit vulnerabilities in API authentication and authorization mechanisms.
  • Perform security testing for distributed systems and microservices.
  • Expert knowledge of hacking authentication methods such as OAuth, SAML, and JWT.
  • Knowledge of macOS and Windows Active Directory systems and their security implications.
  • Deep understanding of Linux operating systems and their security implications.
  • Ability to analyze and understand complex software architectures and codebases.
  • Work closely with software engineers to provide security guidance and recommendations.
  • Basic knowledge of Python or Go programming languages for scripting and tool development.
  • Collaborate effectively with cross-functional teams, including software engineers, cloud architects, and security professionals.
  • Communicate security findings and recommendations clearly and concisely to both technical and non-technical audiences.
  • Stay up-to-date on the latest cloud security threats, vulnerabilities, and attack techniques.
  • Conduct security research and develop new penetration testing methodologies.
  • Have experience in threat modelling, red/blue teaming, working with best-in-class independent engineering teams.

Nice-to-Have:

  • Administer and optimize Cloud Security Posture Management (CSPM) and SaaS Security Posture Management (SSPM) tools.
  • Configure and maintain cloud security tools and platforms to ensure continuous monitoring and threat detection.
  • Work with Infrastructure as Code tools such as Terraform and CloudFormation to ensure secure cloud deployments.
  • Configure, deploy, and maintain Web Application Firewalls (WAF) in production and development environments.
  • BA or BSc. in Computer Science, Information Security, or a related field.
  • 6+ years of experience in penetration testing, with a strong focus on cloud security.
  • Expert-level knowledge of cloud platforms (AWS, Azure, GCP) and their security services.
  • Proven experience in API security testing and authentication hacking.
  • Strong understanding of Linux, macOS and Windows Active directory operating systems and software development practices.
  • Proficiency in using penetration testing tools and frameworks, including commercial tools like Checkmarx, Invicti, and Synopsys etc.
  • Excellent communication and collaboration skills.
  • Deep understanding of the MITRE ATT&CK framework.
  • Experience working in a software development environment.

Nice-to-Have:

  • Relevant security certifications (e.g., OSCP, OSCE, GPEN, GWAPT).
  • Experience with CSPM and SSPM tools.

Compensation Information

The new hire base pay for this role has a salary range of $103,000 to $154,000. The actual salary offered will be based on a wide range of factors, including skills, qualifications, relevant experience, and US location. The salary range provided reflects the base salary and in addition may also be eligible for discretionary Arista bonuses, commissions, equity, and benefits including medical, dental, vision, wellbeing, tax savings and income protection. The recruiting team can share more details during the hiring process specific to the role and location.

#LI-SZ1

Arista Networks is an equal opportunity employer.  Arista makes all hiring and employment-related decisions in a non-discriminatory manner without regard to race, color, religion, sex, sexual orientation, gender identity, national origin or any other factor determined to be unlawful under applicable federal, state, or law law.  All your information will be kept confidential according to EEO guidelines.

Arista Networks is the leader in software driven networking solutions for today’s largest Data Center (DC), Cloud, Internet/WAN, Service Provider (SP) and Campus environments. Arista has over 7500 customers ranging from the largest cloud providers, to healthcare, government, carrier, finance, education, and production web/SaaS companies. Arista's products are the foundation underpinning much of modern society's operations.Arista has ambitious plans and an unprecedented opportunity for growth and we are looking for many more engineers and designers to join us in building and innovating the world's networks. Arista is a profitable, publicly quoted company with revenues of over $2B with a culture of invention, quality, respect, and fun.

View all jobs
Salary
$103,000 – $154,000 per year
Ace your job interview

Understand the required skills and qualifications, anticipate the questions you may be asked, and study well-prepared answers using our sample responses.

IT Security Analyst Q&A's
Report this job

This job is no longer available