Security Analyst

Sorry, this job was removed at 2:29 p.m. (MST) on Thursday, October 18, 2018
Find out who's hiring in Colorado Springs.
See all Cybersecurity + IT jobs in Colorado Springs
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Who we are...

BombBomb makes it easy to use simple videos to build relationships through email, text and social media. Our team is scrappy and intelligent. Competitive and collaborative. Fun-loving and tenacious. We're close-knit and love adding new talent to the mix. Rehumanizing the planet can't be done without EXCELLENT people and we want to add you to our already amazing team!

Who we're looking for...

The Security Analyst will be a part of our IT Information Security team, and help us achieve a SOC2 attestation by the end of 2018 to facilitate BombBomb’s relationship with emerging enterprise markets. You will swiftly identify and remediate vulnerabilities to the company’s cyber infrastructure. Additionally, you will help protect BombBomb employees, resources and confidential company/customer data by implementing appropriate security policies and practices.

What you will do...

  • Continually complete client security questionnaires within 3 business days.
  • Lead the various compliance projects, guide the development and IT staff to achieve SOC2 attestation by the end of Q4 2018.
  • Continually run vulnerability assessments every 30 days, work with internal teams to remediate critical vulnerabilities
  • Run PCI compliance scans for our payment processor every 90 days and resolve any issues
  • Establish good relationships with senior management and staff. Communicate and coordinate security efforts to ensure that BombBomb includes security awareness in its culture.
  • Coordinate and advocate for security development work among product owners and developers to ensure progress is made in larger security initiatives
  • Continually improve technical skills to include a good working knowledge of the following:
    • Linux systems and bash scripting to improve automation capabilities and troubleshoot back-end systems related to security
    • Enough programming to know the basics and spot obvious vulnerabilities such as SQL injection and Cross-Site scripting
    • Splunk administration and creation of high-level security dashboards
  • Run phishing campaigns and follow up with live education classes twice a year. Maintain a recidivism rate of lower than 35% (new employees exempt) company-wide
  • Maintain security policies and understand them in depth.
  • Review and audit the efficacy of BombBomb’s Security policies at least annually to ensure compliance.
  • Review and audit the efficacy of BombBomb’s Security controls at least quarterly to ensure compliance.
  • Train and remediate security incidents with BombBomb staff, ensuring that BombBomb staff recidivism is less than 35%
  • Maintain and administer the physical security systems and periodically review video footage and access logs for unauthorized access.
  • Manage security-related vendor relationships such as physical security, software products and services, ensuring that they are secure and well-researched. Be accurate in licensing counts and stay within budgetary estimates.
  • Deliver accurate budgetary requirements yearly in October

How you'll do it...

Embody BombBomb’s core values: Relationships, Fun, Humility, Flexibility and Service

Integrity & Trust: Acts ethically and honestly and builds professional relationships by promoting mutual trust

Communication: Be a good communicator and build relationships with the people you will be working with in the office. The position will depend on communication between multiple people across multiple departments, coordinating to achieve ISO compliance. Communicating deadlines and the relevance of the requirements will be crucial to the project’s success.

Flexibility: Willing to learn new technologies, security protocols and methods of circumventing our security systems. Ability to adapt to new challenges as they arise, and put out fires without being overwhelmed during busy times.

Detail-Oriented: The position requires attention to detail, as a violation in company policy may result in failure to achieve compliance and ultimately losses in company revenue.

Analytical Thinking / Problem Solving: The ability to understand an idea, situation, or problem by breaking it into smaller pieces

Diplomacy: Effectively handling difficult or sensitive issues by using tact, diplomacy and an understanding of organizational culture and climate

Our ideal candidate will be or have...

  • 5+ years of progressive information technology experience
  • 3+ years of IT security experience
  • Bachelor's degree in technology or related field
  • Experience with enterprise logging (Splunk, SumoLogic, etc.)
  • Experience with enterprise endpoint protection systems (ESET, Cylance, or similar)
  • Experience with vulnerability assessment tools (Rapid7, Burp Suite or similar)
  • Strong understanding of networking concepts (VPN, subnetting, ACLs, VLANs, etc.)
  • Familiarity with network IDS/IPS systems (CheckPoint, SNORT, SourceFire, etc.)
  • Experience working with Security Compliance Frameworks (ISO 27001, SOC2 and PCI-DSS)
  • Knowledge of popular SaaS applications
  • Knowledge of Linux, macOS, iOS, and Android
  • Knowledge of AWS security principles
  • Familiarity with Kanban/Agile project management
  • Ability to meet deadlines and adjust to changing priorities
  • Willingness to work in a fast paced and hands-on environment
  • Preferred Qualifications:
    • CompTIA Security+ certification
    • CompTIA CySA+ or CSA+ certification
    • CISM or CISSP certification

BombBomb Benefits Package Includes...

  • Excellent Medical, Dental and Vision Benefits for you and your family (2 PPO + HSA option)
  • 10 days paid vacation and 5 days of sick leave
  • 8 paid holidays
  • 401k Plan with employer match
  • Weekly company-catered lunch
  • Fun workplace: happy hour every Friday and company game room
  • Annual Education/Development for your career growth
Read Full Job Description
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

Technology we use

  • Engineering
  • Product
  • Sales & Marketing
  • People Operations
    • JavascriptLanguages
    • PHPLanguages
    • ReactLibraries
    • Node.jsFrameworks
    • RedisDatabases
    • AWS (Amazon Web Services)Services
    • Google AnalyticsAnalytics
    • TableauAnalytics
    • IllustratorDesign
    • PhotoshopDesign
    • SketchDesign
    • AsanaManagement
    • ConfluenceManagement
    • Google DriveManagement
    • Chorus.AICRM
    • DocuSignCRM
    • LinkedIn SalesNavigatorCRM
    • OutreachCRM
    • SalesforceCRM
    • MarketoLead Gen
    • SlackCollaboration
    • ZoomCollaboration

Location

BombBomb is in the heart of downtown Colorado Springs. We are in walking distance of great food, drinks, and entertainment - with amazing views!

An Insider's view of BombBomb

What’s the vibe like in the office?

The vibe at BombBomb is high energy and fun! Since our company is growing rapidly, employees are highly motivated and driven. One of our core values is fun, and that's just what we do all day long! Whether it's through our work or a game of ping pong, the office is always full of life.

Abby

Customer Success Manager

How has your career grown since starting at the company?

My career has grown in so many ways at BombBomb. I started off on a more traditional design path but through goal setting, leadership support, and team growth I was able to pursue a career path in product design. I was recently promoted to Lead Senior Product Designer, which I would not have been able to do without the support of BombBomb.

Lisa

Lead Senior Product Designer

What are BombBomb Perks + Benefits

BombBomb Benefits Overview

BombBomb offers health / dental / vision insurance, flexible PTO and paid holidays, a 401k plan with company match, Short / Long term disability, and company paid life insurance. There are countless perks, including company sponsored lunch on BombBomb Friday, great beers on tap, professional development opportunities, and paid volunteer time.

As we've become more of a 'remote-first' team, we're pleased to announce these additional perks:
- monthly internet stipend for all employees
- one-time home office stipend
- First Fridays of every month off - to focus on our employees mental health

Culture
Volunteer in local community
BombBomb sets aside philanthropic paid time off for every employee to volunteer to support causes they are passionate about.
Partners with nonprofits
BombBomb has established partnerships with Non-profits in our local community, such as Mary's Home and Springs Rescue Mission.
Open door policy
OKR operational model
Team based strategic planning
Pair programming
Open office floor plan
Remote work program
Diversity
Mandated unconscious bias training
Diversity manifesto
Hiring practices that promote diversity
Health Insurance & Wellness Benefits
Flexible Spending Account (FSA)
Disability insurance
Dental insurance
Vision insurance
Health insurance
Life insurance
Pet insurance
Wellness programs
Mental health benefits
Financial & Retirement
401(K)
401(K) matching
Company equity
Child Care & Parental Leave Benefits
Generous parental leave
Family medical leave
Vacation & Time Off Benefits
Unlimited vacation policy
Generous PTO
Paid volunteer time
Paid holidays
Paid sick days
Office Perks
Company-sponsored outings
Some meals provided
Company-sponsored happy hours
Onsite office parking
Relocation assistance
Fitness stipend
Home-office stipend for remote employees
Professional Development Benefits
Job training & conferences
Lunch and learns
Promote from within
Mentorship program
Continuing education stipend

Additional Perks + Benefits

Fridays are the bomb at BombBomb! We enjoy lunch as a team every Friday and celebrate newcomers and people living out the core values. The winner gets two weeks in the corner (truly) Awesome Office. There is a walking/biking trail just steps away from our office and you can be IN the mountains within 15 minutes. The million dollar views of Pikes Peak keep us inspired and energized. We're always learning and growing so lunch-n-learns are common - we discuss everything from how to be an authentic leader to the magic of a true Customer Success experience and selling like a boss. Also, #HACKWEEK is legit and our developers wow us every time with their innovative creations.

More Jobs at BombBomb

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about BombBombFind similar jobs like this