Senior Security Analyst (Rapid 7)

About the position Virtual Technologies Group is seeking a Senior Security Analyst to act as a primary responder and technical specialist within a staff augmentation model. In this role, you will focus on the day-to-day monitoring, investigation, and refinement of a security stack centered on AWS/Azure, Rapid7, and Proofpoint. Your goal is to move beyond basic alert monitoring to provide deep-dive forensic analysis and proactive threat hunting, ensuring that our cloud infrastructure remains resilient against emerging threats. This role requires a sharp analytical mind to evaluate complex security events and the ability to mentor junior analysts in improving incident response workflows. Responsibilities • Act as a primary responder and technical specialist. • Focus on day-to-day monitoring, investigation, and refinement of a security stack centered on AWS/Azure, Rapid7, and Proofpoint. • Provide deep-dive forensic analysis and proactive threat hunting. • Ensure cloud infrastructure remains resilient against emerging threats. • Evaluate complex security events. • Mentor junior analysts in improving incident response workflows. Requirements • 5+ years of experience in Security Operations or Analysis. • At least 3 years focused on investigating Cloud Security alerts (AWS or Azure). • Proficiency in auditing cloud environments (VPC/VNet, S3/Blob access logs) and reviewing Identity & Access Management (IAM) permissions for anomalies. • 2+ years of hands-on experience utilizing a SIEM or XDR platform (e.g., Rapid7, Splunk, or Sentinel) for event correlation and alert investigation. • Experience interpreting vulnerability scan results, assessing their real-world exploitability, and tracking remediation progress with technical teams. • Proven experience leading the "detect and analyze" phases of the IR lifecycle, including containment and detailed post-mortem documentation. • Experience performing internal audits or control testing related to frameworks such as SOX or PCI-DSS. • Ability to distill complex forensic findings into clear, concise reports for stakeholders and provide guidance to junior-level analysts. Nice-to-haves • Direct experience analyzing phishing and malware trends using Proofpoint (specifically TAP, TRAP, and IMD). • Experience helping engineers refine detection logic and reducing false positives within Rapid7 InsightIDR. • Ability to use Python or PowerShell to query logs, parse data sets, or automate common investigative steps. • Familiarity with Microsoft Defender for Cloud and using Microsoft Purview for investigating data leakage or sensitive data exposure. • Industry-recognized certifications such as GCIH, GCIA, CySA+, or Microsoft SC-200. • Experience developing hypotheses for proactive threat hunts based on current IOCs and MITRE ATT&CK techniques. • Previous experience working in a dedicated analyst capacity within a managed services or staff augmentation environment. Benefits • Medical insurance plans • Dental insurance • Vision insurance • Health savings accounts (HSA) • Flexible spending accounts (FSA) • Life insurance • Short and long-term disability insurance • Paid time off and holidays • 401(k) with employer match Apply tot his job Apply To this Job

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...