Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Lead Security Analyst, Cloud & Endpoint Incident Response image - Rise Careers
Job details

Lead Security Analyst, Cloud & Endpoint Incident Response

1150868


About the role

The Lead Security Analyst is a senior, hands-on role within Security Operations focused on cloud-centric incident response with a primary emphasis on AWS, while also leading complex investigations across endpoint, identity, and SaaS environments. This role is for an experienced investigator who operates confidently in high-impact incidents, owns response end-to-end, and improves how security incidents are detected, investigated, and contained at scale. This is not simply an alert-triage role; it is a senior investigative and technical leadership position.

What you’ll do

Threat awareness & rapid assessment

  • Track emerging threats (active exploitation, 0-days, vendor advisories, high-risk CVEs) and quickly assess relevance to our AWS environment and endpoints.
  • Triage external and internal inputs (customer-reported issues, bug bounty reports, security research, escalations) and drive them through validation, investigation, and mitigation when risk is confirmed.
  • Translate threat intelligence into practical actions: containment guidance, detection updates, and prioritized remediation.

Incident response & investigation

  • Lead and execute high-severity security incidents across AWS, endpoints, identity, and SaaS environments.
  • Drive incidents from initial signal through scoping, containment, eradication, recovery, and post-incident review.
  • Reconstruct attacker activity by correlating AWS and endpoint evidence to determine initial access, persistence, privilege escalation, lateral movement, and impact.
  • Produce clear incident documentation (timelines, findings, evidence, and actionable recommendations) for both technical and non-technical stakeholders.

AWS incident response

  • Investigate AWS incidents including IAM abuse, credential compromise, control-plane attacks, persistence mechanisms, and lateral movement.
  • Use AWS telemetry to scope and confirm activity, including CloudTrail, CloudWatch Logs, VPC Flow Logs, IAM, and GuardDuty.
  • Lead investigations involving common AWS compromise patterns 
  • Execute containment actions across cloud surfaces, including credential/session revocation, policy/role changes, resource quarantine, and access tightening, balancing speed with service impact.
  • Identify visibility and telemetry gaps and work with engineering teams to close them (logging coverage, retention, alerting, access model for incident response).

Detection, automation & readiness

  • Improve detection coverage across AWS and endpoint environments by validating detections against real-world attack scenarios and incident learnings.
  • Partner with detection engineering to test and deploy new detections, tune noisy detections, and strengthen investigation context.
  • Build and maintain investigation and response automation using SOAR tools and scripting.
  • Develop and evolve AWS and endpoint incident response playbooks and ensure they’re usable under pressure.

Engineering partnership & remediation ownership

  • Partner with Engineering, SRE, and IT to implement mitigations, including infrastructure configuration changes and application-level fixes when needed.
  • Track corrective actions to completion and ensure incident learnings translate into durable prevention (not just documentation).

Required experience

  • Strong understanding of software engineering fundamentals, including code structure, build systems, dependencies, and package ecosystems—enabling effective partnership with Engineering teams.
  • Understanding of CI/CD pipelines and DevOps workflows, enabling collaboration with Infrastructure and DevOps teams.
  • Solid knowledge of cloud architecture, especially Amazon Web Services (AWS) services used in modern cloud-native deployments.
  • Hands-on experience responding to AWS security incidents, including investigation and containment actions.
  • Familiarity with SaaS architectures, identity systems, and integration patterns for effective collaboration with Cloud Security teams.
  • Proven experience leading complex security incidents across cloud and endpoint environments.
  • Strong understanding of identity and access concepts (IAM roles, federation, OAuth, privilege escalation patterns).
  • Experience using a SIEM for investigations and detection development (Splunk preferred).
  • Comfortable scripting or automating in Python to accelerate investigations and response workflows.
  • Strong Linux investigation skills; solid working knowledge of macOS and Windows.

Preferred experience

  • Experience operating in multi-account AWS environments and building practical IR workflows for scale (centralized logging, access patterns, guardrails).
  • Familiarity with AWS security services beyond core telemetry (e.g., Security Hub, Detective, Config, Macie).
  • Familiarity with Kubernetes, containers, serverless infrastructure, or modern distributed systems.
  • SOAR experience building reliable, auditable automations and response workflows.

What we value

  • Calm, structured decision-making under pressure
  • Speed with evidence-based rigor
  • Ownership and follow-through on remediation
  • Strong cross-functional collaboration with engineering teams
  • An automation and continuous-improvement mindset

Pay & Benefits

The cash compensation below includes base salary, on-target commission for employees in eligible roles, and annual bonus targets under HubSpot’s bonus plan for eligible roles. In addition to cash compensation, some roles are eligible to participate in HubSpot’s equity plan to receive restricted stock units (RSUs). Some roles may also be eligible for overtime pay. Individual compensation packages are tailored to your skills, experience, qualifications, and other job-related reasons.

This resource will help guide how we recommend thinking about the range you see. Learn more about HubSpot’s compensation philosophy.

Benefits are also an important piece of your total compensation package. Explore the benefits and perks HubSpot offers to help employees grow better.

At HubSpot, fair compensation practices aren’t just about checking off the box for legal compliance. It’s about living out our value of transparency with our employees, candidates, and community.

Annual Cash Compensation Range:
$130,800$209,300 USD

We know the confidence gap and impostor syndrome can get in the way of meeting spectacular candidates, so please don’t hesitate to apply — we’d love to hear from you.

If you need accommodations or assistance due to a disability, please reach out to us using this form.


At HubSpot, we value both flexibility and connection. Whether you’re a Remote employee or work from the Office, we want you to start your journey here by building strong connections with your team and peers. If you are joining our Engineering team, you will be required to attend a regional HubSpot office for in-person onboarding. If you join our broader Product team, you’ll also attend other in-person events, such as your Product Group Summit and other gatherings, to continue building on those connections.

If you require an accommodation due to travel limitations or other reasons, please inform your recruiter during the hiring process. We are committed to supporting candidates who may need alternative arrangements


Massachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Germany Applicants: (m/f/d) - link to HubSpot's Career Diversity page here.

India Applicants: link to HubSpot India's equal opportunity policy here.


About HubSpot

HubSpot (NYSE: HUBS) is an AI-powered customer platform with all the software, integrations, and resources customers need to connect marketing, sales, and service. HubSpot's connected platform enables businesses to grow faster by focusing on what matters most: customers. 

At HubSpot, bold is our baseline. Our employees around the globe move fast, stay customer-obsessed, and win together. Our culture is grounded in four commitments: Solve for the Customer, Be Bold, Learn Fast, Align, Adapt & Go!, and Deliver with HEART. These commitments shape how we work, lead, and grow.

We’re building a company where people can do their best work. We focus on brilliant work, not badge swipes. By combining clarity, ownership, and trust, we create space for big thinking and meaningful progress. And we know that when our employees grow, our customers do too.

Recognized globally for our award-winning culture by Comparably, Glassdoor, Fortune, and more, HubSpot is headquartered in Cambridge, MA, with employees and offices around the world.

Explore more:


HubSpot may use AI to help screen or assess candidates, but all hiring decisions are always human. More information can be found here. By submitting your application, you agree that HubSpot may collect your personal data for recruiting, global organization planning, and related purposes. Refer to HubSpot's Recruiting Privacy Notice for details on data processing and your rights.

HubSpot Glassdoor Company Review
4.0 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
HubSpot DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of HubSpot
HubSpot CEO photo
Yamini Rangan
Approve of CEO

Average salary estimate

$170050 / YEARLY (est.)
min
max
$130800K
$209300K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Photo of the Rise User
Boyd Gaming Hybrid 6465 S. Rainbow Blvd., Las Vegas
Posted 21 hours ago

Experienced network engineering professional needed to lead design, implementation, and troubleshooting of enterprise network infrastructure for a major casino entertainment company in Las Vegas.

Photo of the Rise User
Posted 13 hours ago

Lead CIM Group's IT Service Desk and Desktop Engineering teams to deliver reliable, ITIL-aligned support and mature ServiceNow-driven processes that improve user satisfaction and business continuity.

Jack Link's Protein Snacks Hybrid 600 Hennepin Ave, Minneapolis, MN 55403, USA
Posted 12 hours ago

Gain hands-on infrastructure experience at Jack Link's in Minneapolis as an IT Infrastructure Intern, working across virtualization, networking, security and project delivery while partnering with business stakeholders.

Photo of the Rise User
Posted 10 hours ago

Enoch Pratt Free Library seeks a Digital Navigator to lead digital equity efforts, deliver hands-on tech assistance to patrons, and coordinate digital literacy programs across multiple branches.

Photo of the Rise User
Red Bull Hybrid Santa Monica, CA, USA
Posted 8 hours ago

Experienced IT Business Analyst needed to lead requirements engineering and drive scalable, user-focused eCommerce solutions at Red Bull North America.

Photo of the Rise User

Lead Blackbaud's AI security engineering efforts as the Cyber Security Manager for AI Enablement and Delivery—driving secure AI adoption, cloud infrastructure security, and a global engineering team.

Photo of the Rise User
Fluent, LLC Hybrid No location specified
Posted 10 hours ago

Fluent is seeking an IT Support Specialist to provide hybrid on-site and remote technical support—covering macOS/Windows, mobile devices, endpoint management, and Okta administration—for the New York office and distributed users.

Photo of the Rise User
Posted 2 hours ago

Experienced ServiceNow TPRM/GRC developer needed to implement and maintain third‑party risk management workflows, integrations, and reporting for an onsite Malvern, PA engagement.

Photo of the Rise User

Coretelligent is hiring a Remote Support Engineer II to lead advanced troubleshooting and escalations for MSP clients during the Saturday–Tuesday 8 PM–7 AM ET shift.

HubSpot is an American AI-powered customer relationship management platform founded in Boston in 2016 that helps millions of businesses grow worldwide.

6 jobs
MATCH
Calculating your matching score...
BADGES
Badge ChangemakerBadge Diversity ChampionBadge Flexible CultureBadge InnovatorBadge Future Unicorn
CULTURE VALUES
Mission Driven
Customer-Centric
Transparent & Candid
Growth & Learning
Fast-Paced
Inclusive & Diverse
Work/Life Harmony
Rise from Within
BENEFITS & PERKS
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Education Stipend
Learning & Development
Bias Training
Performance Bonus
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
January 14, 2026
Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!