Jobs
>
Palo Alto

    Senior Security Analyst - Palo Alto, United States - hims & hers

    Default job background
    Description
    Hims & Hers


    Hims is a one-stop telehealth service for men's wellness and care, providing treatment options for hair loss, ED & more.

    View company page

    Hims & Hers Health, Inc.

    (better known as Hims & Hers) is the leading health and wellness platform, on a mission to help the world feel great through the power of better health.

    We are revolutionizing telehealth for providers and their patients alike.

    Making personalized solutions accessible is of paramount importance to Hims & Hers and we are focused on continued innovation in this space.

    Hims & Hers offers nonprescription products and access to highly personalized prescription solutions for a variety of conditions related to mental health, sexual health, hair care, skincare, heart health, and more.

    Hims & Hers is a public company, traded on the NYSE under the ticker symbol "HIMS". To learn more about the brand and offerings, you can visit

    and , or visit our investor site .

    For information on the company's outstanding benefits, culture, and its talent-first flexible/remote work approach, see below and visit .


    About the Role:
    We are seeking a Senior Security Analyst to help build our Security Operations discipline. Our team moves at a fast pace and always looking to help drive best security practices at our core.

    This dynamic team enables multiple areas of the business to be able to stay agile, but with always being vigilant to keep our infrastructure secure and drive innovation.

    This is an opportunity to directly drive change and security in our business.

    You Will:

    Advanced Security Monitoring and Analysis:
    Oversee the continuous monitoring and in-depth analysis of network traffic, system logs, and security alerts, employing cutting-edge SIEM

    solutions and leveraging advanced threat intelligence feeds to detect and respond to sophisticated cyber threats
    Incident Response

    Mastery:

    Develop, refine, and lead the execution of advanced incident response plans and procedures, orchestrating multifaceted incident handling activities with a focus on rapid containment, eradication, and recovery.

    Serve as the ultimate technical authority during high-stress security incidents

    Vulnerability Assessment and Management Expertise:
    Lead the identification and prioritization of vulnerabilities across our intricate technology stack, conducting comprehensive vulnerability assessments and overseeing advanced remediation efforts, including penetration testing and code review
    AWS, Azure, and GCP

    Security Expertise:
    Utilize your extensive knowledge of AWS, Azure, and GCP security best practices to assess and enhance the security of cloud

    environments. Implement and maintain security configurations, identity and access controls, and encryption mechanisms specific to each cloud platform. Conduct security assessments and audits to identify vulnerabilities and provide recommendations for remediation

    Pioneering Threat Intelligence Integration:
    Maintain an expert understanding of emerging cybersecurity threats and trends, actively integrating advanced threat intelligence into security operations to drive proactive threat detection and support the development of custom threat-hunting methodologies
    Master of Security Automation and Tooling: Spearheaded the development and deployment of highly sophisticated scripts, automation tools, and custom security solutions to optimize and streamline complex security tasks, enhance operational efficiency, and enable rapid response to evolving threats
    Prior experience with Threat Hunting and making recommendations on findings
    Experience in Red team, Blue team, Purple team, and table top exercise
    Recommend and implement security enhancements to proactively address emerging threats
    Assist in the development and enforcement of security policies, standards, and procedures
    Prior experience with industry regulations and standards, such as NIST, CIS, and GDPR

    You Have:
    Bachelor's degree in a relevant field or equivalent work experience
    Minimum of 5 years of experience in a security analyst role
    Strong expertise in cloud computing, with a preference for AWS
    Proficiency in Sumo Logic for creating Insights and Signals
    Experience researching through logs for security investigations
    Familiarity with security platforms such as Netskope, CrowdStrike, Tenable, Cisco Meraki, and Proofpoint, or similar products
    Certifications such as OCSP, CompTIA Security+, Pentest+, or AWS Certified Security – a plus
    Excellent problem-solving and analytical skills
    Strong communication, documentation, and teamwork abilities
    Ability to work independently and under pressure in a fast-paced environment
    Exposure to penetration testing platforms such as Burp Suite, Kali Linux, Metasploit, Nexpose
    Skilled with network security tools such as Palo Alto Firewalls, Cisco VPNs, Palo Alto IDS
    Understanding of regulatory compliance (NIST CSF, SOX, ISO)

    Our Benefits (there are more but here are some highlights):

    Competitive salary

    & equity compensation for full-time roles
    Unlimited PTO, company holidays, and quarterly mental health days
    Comprehensive health benefits including medical, dental & vision, and parental leave
    Employee Stock Purchase Program (ESPP)
    Employee discounts on hims & hers & Apostrophe online products
    401k benefits with employer matching contribution
    Hims & Hers Health, Inc.

    (better known as Hims & Hers) is the leading health and wellness platform, on a mission to help the world feel great through the power of better health.

    We are revolutionizing telehealth for providers and their patients alike.

    Making personalized solutions accessible is of paramount importance to Hims & Hers and we are focused on continued innovation in this space.

    Hims & Hers offers nonprescription products and access to highly personalized prescription solutions for a variety of conditions related to mental health, sexual health, hair care, skincare, heart health, and more.

    Hims & Hers is a public company, traded on the NYSE under the ticker symbol "HIMS". To learn more about the brand and offerings, you can visit

    and , or visit our investor site .

    For information on the company's outstanding benefits, culture, and its talent-first flexible/remote work approach, see below and visit .


    About the Role:
    We are seeking a Senior Security Analyst to help build our Security Operations discipline. Our team moves at a fast pace and always looking to help drive best security practices at our core.

    This dynamic team enables multiple areas of the business to be able to stay agile, but with always being vigilant to keep our infrastructure secure and drive innovation.

    This is an opportunity to directly drive change and security in our business.

    You Will:

    Advanced Security Monitoring and Analysis:
    Oversee the continuous monitoring and in-depth analysis of network traffic, system logs, and security alerts, employing cutting-edge SIEM

    solutions and leveraging advanced threat intelligence feeds to detect and respond to sophisticated cyber threats
    Incident Response

    Mastery:

    Develop, refine, and lead the execution of advanced incident response plans and procedures, orchestrating multifaceted incident handling activities with a focus on rapid containment, eradication, and recovery.

    Serve as the ultimate technical authority during high-stress security incidents

    Vulnerability Assessment and Management Expertise:
    Lead the identification and prioritization of vulnerabilities across our intricate technology stack, conducting comprehensive vulnerability assessments and overseeing advanced remediation efforts, including penetration testing and code review
    AWS, Azure, and GCP

    Security Expertise:
    Utilize your extensive knowledge of AWS, Azure, and GCP security best practices to assess and enhance the security of cloud

    environments. Implement and maintain security configurations, identity and access controls, and encryption mechanisms specific to each cloud platform. Conduct security assessments and audits to identify vulnerabilities and provide recommendations for remediation

    Pioneering Threat Intelligence Integration:
    Maintain an expert understanding of emerging cybersecurity threats and trends, actively integrating advanced threat intelligence into security operations to drive proactive threat detection and support the development of custom threat-hunting methodologies
    Master of Security Automation and Tooling: Spearheaded the development and deployment of highly sophisticated scripts, automation tools, and custom security solutions to optimize and streamline complex security tasks, enhance operational efficiency, and enable rapid response to evolving threats
    Prior experience with Threat Hunting and making recommendations on findings
    Experience in Red team, Blue team, Purple team, and table top exercise
    Recommend and implement security enhancements to proactively address emerging threats
    Assist in the development and enforcement of security policies, standards, and procedures
    Prior experience with industry regulations and standards, such as NIST, CIS, and GDPR

    You Have:
    Bachelor's degree in a relevant field or equivalent work experience
    Minimum of 5 years of experience in a security analyst role
    Strong expertise in cloud computing, with a preference for AWS
    Proficiency in Sumo Logic for creating Insights and Signals
    Experience researching through logs for security investigations
    Familiarity with security platforms such as Netskope, CrowdStrike, Tenable, Cisco Meraki, and Proofpoint, or similar products
    Certifications such as OCSP, CompTIA Security+, Pentest+, or AWS Certified Security – a plus
    Excellent problem-solving and analytical skills
    Strong communication, documentation, and teamwork abilities
    Ability to work independently and under pressure in a fast-paced environment
    Exposure to penetration testing platforms such as Burp Suite, Kali Linux, Metasploit, Nexpose
    Skilled with network security tools such as Palo Alto Firewalls, Cisco VPNs, Palo Alto IDS
    Understanding of regulatory compliance (NIST CSF, SOX, ISO)

    Our Benefits (there are more but here are some highlights):

    Competitive salary

    & equity compensation for full-time roles
    Unlimited PTO, company holidays, and quarterly mental health days
    Comprehensive health benefits including medical, dental & vision, and parental leave
    Employee Stock Purchase Program (ESPP)
    Employee discounts on hims & hers & Apostrophe online products
    401k benefits with employer matching contribution
    Offsite team retreats
    #LI-Remote
    Outlined below is a reasonable estimate of H&H's compensation range for this role.


    H&H also offers a comprehensive Total Rewards package that includes equity grants of restricted stock (RSU's) so that H&H employees own a piece of our company.


    The actual amount will take into account a range of factors that are considered in making compensation decisions including but not limited to, skill sets, experience and training, licensure and certifications, and location.

    Consult with your Recruiter during any potential screening to determine a more targeted range based on the job-related factors.

    We don't ever want the pay range to act as a deterrent from you applyingAn estimate of the current salary range for US-based employees is$100,000—$115,000 USD We are focused on building a diverse and inclusive workforce.

    If you're excited about this role, but do not meet 100% of the qualifications listed above, we encourage you to apply.

    Hims is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics or any other basis forbidden under federal, state, or local law.

    Hims considers all qualified applicants in accordance with the San Francisco Fair Chance Ordinance.

    Hims & hers is committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures.

    If you need assistance or an accommodation due to a disability, you may contact us . Please do not send resumes to this email address.

    For our California-based applicants – Please see ourCalifornia Employment Candidate Privacy Policy to learn more about how we collect, use, retain, and disclose Personal Information.

    Explore more InfoSec / Cybersecurity career opportunities


    Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.

    #J-18808-Ljbffr


  • Allied Universal® San Francisco, United States

    SOC Security Analyst · **Overview**: · Allied Universal, North America's leading security and facility services company, provides rewarding careers that give you a sense of purpose. While working in a dynamic, diverse and inclusive workplace, you will be part of a team that fuels ...


  • Ramsoftsystems inc Santa Clara, United States

    **Job Title: Information Security Manager** · **Location (Onsite, Remote, or Hybrid?): Santa Clara, CA (3 days Onsite in Mandatory (Hybrid))** · **Contract Duration: contract until 12/1/2024** · **Working Hours: 8-5 M-F PST** · **Position Overview**: · - Work with one of Company' ...

  • Informatica

    Security Analyst

    4 days ago


    Informatica Redwood City, United States

    · Job Number: · 37136 · Position Title: · Intern · Build Your Career at Informatica · We're looking for a diverse group of collaborators who believe data has the power to improve society. Adventurous, work-from-anywhere minds who value solving some of the world's most challe ...


  • Sibylline Ltd Mountain View, United States

    Company Description · About Sibylline · Sibylline is a leading intelligence and strategic risk consultancy in the security sector. Since 2010 we have supported businesses, governments and NGOs through the provision of high-quality risk analysis, due diligence and consultancy ser ...


  • Sibylline Americas Mountain View, United States

    Job Description · Embedded Security Analyst · Sibylline is looking for a motivated early-career intelligence analyst to join us in an embedded role within a globally dispersed intelligence team. The role will based onsite in Mountain View, CA. Using the latest industry technologi ...


  • Sibylline Americas Mountain View, United States

    Job Description · Job DescriptionCompany Description · About Sibylline · Sibylline is a leading intelligence and strategic risk consultancy in the security sector. Since 2010 we have supported businesses, governments and NGOs through the provision of high-quality risk analysis, d ...


  • Knightscope, Inc Mountain View, United States

    Job Description · Job DescriptionRemote Security Analyst · The Security Surveillance Analyst will be responsible for assisting the CX Manager of National Accounts in monitoring and maintaining the security of Knightscope's autonomous robots, while providing premium customer servi ...

  • Zobility

    IT Security Analyst

    1 week ago


    Zobility Newark, United States

    We are currently seeking an IT Security Analyst who will be monitoring computer networks for security issues. This person will also investigate cyber security incidents as well as security breaches. Our ideal candidate exhibits a can-do attitude and approaches his or her work wit ...


  • Oracle Redwood City, United States Regular Employee

    At Oracle Cloud Infrastructure (OCI), we build the future of the cloud for Enterprises. We act with the speed and attitude of a start-up along with the scale and customer focus of the leading enterprise software company in the world. · About the team: · EES Security and Complian ...


  • eGain Sunnyvale, United States

    Hundreds of global brands trust eGain to automate customer engagement and empower employees in a digital-first world. Powered by knowledge and AI, our solution is top-rated by Gartner and Forrester. · We dream big and sweat details. We are diverse, optimistic, and tenacious. We ...


  • eGain Corporation Sunnyvale, United States

    Hundreds of global brands trust eGain to automate customer engagement and empower employees in a digital-first world. Powered by knowledge and AI, our solution is top-rated by Gartner and Forrester. · We dream big and sweat details. We are diverse, optimistic, and tenacious. We t ...


  • eGain Sunnyvale, United States

    Hundreds of global brands trust eGain to automate customer engagement and empower employees in a digital-first world. Powered by knowledge and AI, our solution is top-rated by Gartner and Forrester. · We dream big and sweat details. We are diverse, optimistic, and tenacious. We t ...


  • Fortinet Sunnyvale, United States

    IT Security and Compliance Analyst · "Job Details" · Sunnyvale, CA, United States · Job Identification · 15101 · Job Category · IT Compliance · Locations · Sunnyvale, CA, United States · Posting Date · 01/29/2024, 07:10 PM · Degree Level · Bachelor's Degree · Job Schedule · Fu ...


  • Fortinet Sunnyvale, United States

    Security and Compliance Analyst · Job Summary: We are seeking a highly skilled and motivated Security and Compliance Analyst to join our dynamic team. The ideal candidate will play a crucial role in ensuring the security and compliance of our organization by supporting the implem ...


  • Craig Technologies Mountain View, United States

    Title: C3RS Expert Analyst · Location: Sunnyvale, CA · Clearance: N/A · Citizenship requirement: Yes · Req #: 3614 · Salary: $50.00 Hourly · This position can be Part time or Full time Job Description: · Serve as an expert in railroad safety on the C3RS project under the ASRS and ...

  • Lucile Packard Children's Hospital

    Data Analyst

    2 days ago


    Lucile Packard Children's Hospital Palo Alto, United States

    **Information Technology** · **1.0 FTE, 8 Hour Day Shift** · At Stanford Children's Health, we know world-renowned care begins with world-class caring. That's why we combine advanced technologies and breakthrough discoveries with family-centered care. It's why we provide our care ...

  • Insight Global

    Security Analyst

    1 week ago


    Insight Global Berkeley, United States

    Job Description · Insight Global is looking for a security analyst to join one of our largest education client's IT Division · We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are a ...

  • University of California

    Security Analyst

    6 days ago


    University of California San Francisco, United States

    · Security Analyst · PPH-Domestic-Core-IZ · Full Time · 77068BR · Job Summary · This position supports the California Immunization System and involves work implementing and maintaining measures to safeguard the system from unauthorized access, data breaches, and cyber threat ...

  • University of California , San Francisco

    Security Analyst

    1 week ago


    University of California , San Francisco San Francisco, United States

    · Security Analyst · PPH-Domestic-Core-IZ · Full Time · 77068BR · Job Summary · This position supports the California Immunization System and involves work implementing and maintaining measures to safeguard the system from unauthorized access, data breaches, and cyber threat ...

  • Wearelegence

    Security Analyst

    1 week ago


    Wearelegence San Jose, United States

    Gilbert, 5251 West 74th St., Edina, Minnesota, United States of America ● Legence, 1601 Las Plumas Ave., San Jose, California, United States of America · Req #1367 · Legence , a Blackstone portfolio company, is an Energy Transition Accelerator that provides advisory services and ...