Coalition logo
Coalition·

Senior Security Support Analyst - Coalition

About Us

Coalition is the world's first Active Insurance provider designed to help prevent digital risk before it strikes. Founded in 2017, Coalition combines comprehensive insurance coverage and innovative cybersecurity tools to help businesses manage and mitigate potential cyberattacks.

About the Role

The Senior Security Analyst helps protect Coalition policyholders from cyber loss by assessing security risk, investigating incidents and claims, and translating technical findings into practical recommendations. The role sits within Coalition’s Security team, working across threat intelligence, cyber risk management, and defensive security controls.

This role connects security analysis to business and product execution. In addition to advising customers and security leaders, the analyst partners with Product and internal stakeholders to codify security best practices into underwriting algorithms, rating models, risk-management applications, and internal processes.

Responsibilities

  • Assess the security posture of insureds and prospective insureds across programs, technologies, controls, and business environments.
  • Investigate incidents and cyber insurance claims to identify root cause, attack vectors, control gaps, and opportunities for prevention.
  • Advise customers and security leaders on practical, prioritized improvements across architecture, cloud security, data protection, and compliance.
  • Translate threat intelligence and observed attacker behavior into detection tradecraft and actionable security recommendations.
  • Partner with Product and cross-functional teams to improve risk models, underwriting approaches, and security-focused applications.
  • Track emerging practices, regulatory developments, and industry trends to inform Coalition’s customers, processes, and products.

Ideal Candidate Profile

Background & Domain

  • 2–4 years of experience in security analysis, defensive or blue-team operations, penetration testing, red-team work, incident response, or cyber risk consulting.
  • Experience assessing security programs, investigating incidents, or analyzing control effectiveness in complex business environments.
  • Exposure to cloud security, security architecture, data protection, threat intelligence, or cyber insurance is particularly relevant.

Technical & Regulatory

  • Strong understanding of network threats, attack vectors, exploitation methods, and intrusion-set tactics, techniques, and procedures.
  • Practical knowledge of TCP/IP, network analysis, security technologies, logs, and network traffic captures.
  • Familiarity with NIST, ISO, HIPAA, and PCI frameworks, and the ability to connect requirements to real-world controls.

Collaboration & Influence

  • Able to turn ambiguous technical evidence into clear conclusions and prioritized business recommendations.
  • Comfortable communicating with security practitioners, business stakeholders, customers, and executive audiences, including CISOs.
  • Collaborative and self-directed, with the judgment and initiative expected at the P4 level.
  • Effective in a fast-paced, evolving environment where they can help improve processes and products.

Skills and Qualifications

  • 2–4 years of experience in security analysis, blue-team or defensive security, penetration testing, red-team operations, incident response, or a related discipline.
  • Expert understanding of network threat lifecycles, attack vectors, exploitation methods, and attacker TTPs.
  • Knowledge of TCP/IP protocols, network analysis, and network and security applications, including log analysis and network traffic capture analysis.
  • Ability to investigate incidents and claims, determine root cause, and recommend effective preventive or detective controls.
  • Familiarity with NIST, ISO, HIPAA, and PCI frameworks and their practical application.
  • Strong written and verbal communication skills, with the ability to provide clear recommendations to technical and executive audiences.

Bonus Points

  • Experience analyzing cyber insurance claims or translating security findings into underwriting, rating, or risk-scoring inputs.
  • Hands-on experience with cloud security, security architecture, data protection, or security control assessments.
  • Background in threat intelligence and developing detection tradecraft from observed attacker behavior.
  • Experience advising CISOs or customers on prioritizing security improvements based on risk, feasibility, and business context.
  • Demonstrated ability to create or improve internal security processes, products, or analytical methodologies.

Timezone overlap

UTC-8–-4

Open to

US

Sign in to track applications and earn points.

More roles at Coalition

Similar remote roles