- Company Name
- Ramp
- Job Title
- Senior Security Analyst | Corporate Security
- Job Description
-
**Job title:** Senior Security Analyst – Corporate Security
**Role Summary:**
Senior individual contributor responsible for designing, implementing, and scaling enterprise security programs across identity, endpoints, SaaS, and data. Drives Insider Risk, DLP, SaaS posture, and endpoint security for corporate and FedRAMP‑aligned environments while enabling rapid AI‑driven business operations.
**Expactations:**
- 3+ years of hands‑on experience in enterprise security engineering or operations.
- Primary ownership of security programs (not a SOC Tier 1 or manager role).
- U.S. citizenship (required for sovereign/FedRAMP environments).
- Ability to work hybrid in New York City (≥2 days onsite).
**Key Responsibilities:**
- Own and continuously improve Insider Risk and DLP programs (policy, detection, playbooks, training).
- Manage SaaS security posture: remediate misconfigurations, remove stale accounts, enforce key rotation, control OAuth scopes, and gate risky integrations.
- Operate sovereign Google Workspace and Okta tenants; align controls with NIST 800‑53/800‑171 and FedRAMP requirements.
- Modernize identity & access: enforce phishing‑resistant MFA, device/context‑aware access, least‑privilege/JIT, SCIM lifecycle management, and break‑glass processes.
- Harden macOS and Windows endpoints using EDR, MDM, disk encryption; enforce ZTNA/SSE policies (e.g., Cloudflare WARP).
- Define, track, and report security metrics (coverage, MTTD/MTTR, policy efficacy, configuration drift); conduct control health reviews.
- Automate security operations via scripting, APIs, and workflow tools (account hygiene, access reviews, configuration checks, alert triage).
- Produce clear documentation, runbooks, and decision records; collaborate with IT, Engineering, Legal, People, and GRC teams.
**Required Skills:**
- Practical experience with Insider Risk, DLP, SaaS security posture management, and endpoint security in cloud‑first environments.
- Hands‑on administration of Okta (or comparable IdP) and Google Workspace (or similar collaboration suite).
- Strong knowledge of MFA, Zero‑Trust Network Access (ZTNA), Secure Service Edge (SSE), and endpoint detection & response (EDR).
- Proficiency in scripting/automation (e.g., Python, PowerShell, REST APIs).
- Ability to develop security metrics, conduct risk assessments, and lead remediation efforts.
- Excellent written and verbal communication; ability to partner across cross‑functional teams.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or related field (or equivalent work experience).
- Preferred certifications: CISSP, CISM, CCSP, or equivalent security credentials.