Senior Security Analyst, Security Operations (Threat Detection)

<strong>About GitHub</strong><br><br>GitHub is the world’s leading platform for agentic software development — powered by Copilot to build, scale, and deliver secure software. Over 180 million developers, including more than 90% of the Fortune 100 companies, use GitHub to collaborate, and more than 77,000 organisations have adopted GitHub Copilot.<br> <br><strong>Locations</strong><br><br>In this role you can work from Remote, United States<br> <br><strong>Overview</strong><br><br><div><p><span xml:lang="EN-GB" data-contrast="none">Are you interested in securing the home for all developers? GitHub is changing the way the world builds software, and we want you to help change the way we secure GitHub. We are looking for Security Engineers to evolve and advance the security posture of GitHub and its ecosystem.</span><span data-ccp-props="{" 134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":200,"335559739":200}"=""> </span></p></div><div><p><span xml:lang="EN-GB" data-contrast="none">Threat Detection and Response is a core function of Security Operations at GitHub. To effectively protect our people, our customers, and our business, we are looking for people who can effectively identify and respond to threats across our platform and supporting systems. </span><span data-ccp-props="{" 134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}"=""> </span></p></div><div><p><span data-ccp-props="{" 335551550":0,"335551620":0}"=""> </span></p></div><div><p><span xml:lang="EN-GB" data-contrast="none">The TDR team is made up of analysts and engineers with varied skill sets, able to perform security analysis, threat hunting, incident response, and tooling development at high levels.</span><span data-ccp-props="{" 134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}"=""> </span></p></div><div><p><span xml:lang="EN-GB" data-contrast="none">As a Senior Security Analyst, you will work alongside other members of Security, IT, and Engineering organizations to help drive technical direction for all things security. You will operate within a team who are driven to develop GitHub’s threat detection capabilities, and you will play a leading part in identifying and prioritizing detection efforts within our environment. Through industry research as well as collaborative Purple Team exercises, you will look to foster an innovative and collaborative environment for bettering GitHub’s security posture. A successful applicant will have a desire to work in tandem with other security professionals to secure GitHubbers and GitHub systems in diverse environments at scale.</span><span data-ccp-props="{" 134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":200,"335559739":200}"=""> </span></p></div> <br><strong>Responsibilities</strong><br><br><div><p><strong><span xml:lang="EN-GB" data-contrast="none">Responsibilities:</span><span data-ccp-props="{" 134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":200,"335559739":200}"=""> </span></strong></p></div><div><ul style="list-style-type: disc;" role="list"><li role="listitem" aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{" 335552541":1,"335559683":0,"335559684":-2,"335559685":720,"335559991":360,"469769226":"symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridmultilevel"}"="" data-aria-posinset="1" data-aria-level="1"><p><span xml:lang="EN-GB" data-contrast="none">Partnering with other security teams to identify, investigate, and mitigate threats</span> </p></li><li role="listitem" aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{" 335552541":1,"335559683":0,"335559684":-2,"335559685":720,"335559991":360,"469769226":"symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridmultilevel"}"="" data-aria-posinset="1" data-aria-level="1"><p><span xml:lang="EN-GB" data-contrast="none">Communicating persuasively with peers to inspire cooperation</span> </p></li><li role="listitem" aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{" 335552541":1,"335559683":0,"335559684":-2,"335559685":720,"335559991":360,"469769226":"symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridmultilevel"}"="" data-aria-posinset="1" data-aria-level="1"><p><span xml:lang="EN-GB" data-contrast="none">Working solo or collaboratively while delivering simultaneous projects on a deadline</span> </p></li><li role="listitem" aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{" 335552541":1,"335559683":0,"335559684":-2,"335559685":720,"335559991":360,"469769226":"symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridmultilevel"}"="" data-aria-posinset="1" data-aria-level="1"><p><span xml:lang="EN-GB" data-contrast="none">Developing, maturing and documenting security policy and processes</span> </p></li><li role="listitem" aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{" 335552541":1,"335559683":0,"335559684":-2,"335559685":720,"335559991":360,"469769226":"symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridmultilevel"}"="" data-aria-posinset="1" data-aria-level="1"><p><span xml:lang="EN-GB" data-contrast="none">Participating in an on-call rotation</span> </p></li><li role="listitem" aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{" 335552541":1,"335559683":0,"335559684":-2,"335559685":720,"335559991":360,"469769226":"symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridmultilevel"}"="" data-aria-posinset="1" data-aria-level="1"><p><span xml:lang="EN-GB" data-contrast="none">Collaborating on and leading purple team exercises</span> </p></li><li role="listitem" aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{" 335552541":1,"335559683":0,"335559684":-2,"335559685":720,"335559991":360,"469769226":"symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridmultilevel"}"="" data-aria-posinset="1" data-aria-level="1"><p><span xml:lang="EN-GB" data-contrast="none">Making well-reasoned decisions that inspire and energize others</span> </p></li><li role="listitem" aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{" 335552541":1,"335559683":0,"335559684":-2,"335559685":720,"335559991":360,"469769226":"symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridmultilevel"}"="" data-aria-posinset="1" data-aria-level="1"><p><span xml:lang="EN-GB" data-contrast="none">Continuously evaluating GitHub’s detection suite and identifying visibility gaps</span> </p></li><li role="listitem" aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{" 335552541":1,"335559683":0,"335559684":-2,"335559685":720,"335559991":360,"469769226":"symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridmultilevel"}"="" data-aria-posinset="1" data-aria-level="1"><p><span xml:lang="EN-GB" data-contrast="none">This role will require working non-standard working hours, including weekends and holidays approximately 1-2 times per month.</span><span data-ccp-props="{" 134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":200,"335559739":200}"=""> </span></p></li></ul></div> <br><strong>Qualifications</strong><br><br><div><p><strong>Qualifications Required/Minimum Qualifications:</strong></p><ul><li> 7+ years experience in security analysis, security research, cyber security, security engineering, or relevant area<ul><li>​​OR Associate’s Degree AND 6+ years of experience in security analysis, security research, cybeer secuirty, security engineering or relevant area </li><li>OR Bachelor's Degree AND 5+ years of experience in security analysis, security research, cyber security, securityy engineering,, or relevant area</li><li>OR Master's Degree AND 3+ years experience in security analysis, security research, cyber secuirty, security engineering, or relevant area</li><li>OR Doctorate AND 1+ year(s) experience in ecurity analysis, security research, cyber secuirty, security engineering, or relevant area</li><li>OR equivalent experience</li></ul></li><li>5+ years of experience in threat hunting and/or detection engineering</li><li>3+ years of experience with SIEM solutions</li><li>5+ years of experience with software development in python</li></ul><p> </p><p><strong>Preferred Qualifications:</strong></p><ul><li>Experience and/or expertise with Microsoft Azure, Amazon Web Services or a similar cloud provider </li><li>Passionate about mentoring and helping their peers grow </li><li>Familiarity with data correlation and modern threat detection techniques </li><li>Knowledge and understanding of security controls across all security domains </li><li>The ability to take a pragmatic, risk-based approach to decision making while applying practical security principles and practices</li></ul><p> </p><p> </p></div><div><p> </p></div> <br><strong>Compensation Range</strong><br><br>The base salary range for this job is USD $124,000.00 - USD $329,200.00 /Yr.<br><br>These pay ranges are intended to cover roles based across the United States. An individual's base pay depends on various factors including geographical location and review of experience, knowledge, skills, abilities of the applicant. At GitHub certain roles are eligible for benefits and additional rewards, including annual bonus and stock. These rewards are allocated based on individual impact in role. In addition, certain roles also have the opportunity to earn sales incentives based on revenue or utilization, depending on the terms of the plan and the employee's role. <p><strong>GitHub values</strong></p> <ul><li>Customer-obsessed</li> <li>Ship to learn</li> <li>Growth mindset</li> <li>Own the outcome</li> <li>Better together</li> <li>Diverse and inclusive</li></ul> <p><strong>Manager fundamentals</strong></p> <ul><li>Model</li> <li>Coach</li> <li>Care</li></ul> <p><strong>Leadership principles</strong></p> <ul><li>Create clarity</li> <li>Generate energy</li> <li>Deliver success</li></ul> <br><strong>Who We Are</strong><br><br>GitHub is the world’s leading AI-powered developer platform with 150 million developers and counting. We’re also home to the biggest open-source community on earth (and 99% of the world’s software has open-source code in its DNA). Many of the apps and programs you use every day are built on GitHub.<br> Our teams are dreamers, doers, and pioneers, leading the way in AI, driving humanitarian efforts around the globe, and even sending open source to Mars (and beyond!). At GitHub, our goal is to create the space you need to do your best work. We’re remote-first and offer competitive pay, generous learning and growth opportunities, and excellent benefits to support you, wherever you are—because we know that people flourish when they can work on their own terms.<br> Join us, and let’s change the world, together.<br> <br><strong>EEO Statement</strong><br><br>GitHub is made up of people from a wide variety of backgrounds and lifestyles. We embrace diversity and invite applications from people of all walks of life. We don't discriminate against employees or applicants based on gender identity or expression, sexual orientation, race, religion, age, national origin, citizenship, disability, pregnancy status, veteran status, or any other differences. Also, if you have a disability, please let us know if there's any way we can make the interview process better for you; we're happy to accommodate!

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...