Security Analyst
The Opportunity
As a Security Analyst, you will collaborate with a team of experienced security professionals to safeguard our corporate and production environments, leveraging advanced security tools and techniques to play a critical role in detecting, preventing, investigating, and responding to security threats and incidents.
As a first line of defense, you are expected to bring deep expertise across security operations, cloud security, DevSecOps, threat detection, and incident response, with strong hands-on experience in securing modern cloud-native environments. In addition, you will partner with cross-functional teams to provide security guidance, support, and training to strengthen our organization’s overall security posture.
This position requires participation in a shift rotation to support 24/7 security monitoring and incident response operations.
Responsibilities
Monitor, investigate, and triage security events to support and enhance threat modeling efforts
Proactively monitor cloud, network, endpoint to identify suspicious activity and emerging threats
Perform cloud security posture assessments, configuration reviews, policy enforcement, and continuous compliance monitoring across AWS, Azure, and GCP environments
Develop and maintain security alerts, log correlation rules, and dashboards using SIEM solution
Develop and implement security automation, detection engineering, and response workflows to improve operational efficiency and reduce manual effort
Configure, administer, and optimize security platforms including SIEM, CSPM, CNAPP, EDR/XDR, DLP, vulnerability management, and cloud security monitoring solutions
Conduct ongoing threat hunts and publish regular threat intelligence reports
Manage the InfoSec ticket queue, conduct investigations, and document resolutions
Review and evaluate vulnerability scan results and remediation efforts
Document, analyze, and escalate security incidents as needed
Collaborate with other business units to assess system configurations and ensure secure integration
Partner with internal stakeholders to define, develop, and implement security standards and best practices
Conduct quarterly security gap analyses and risk assessments
Conduct third-party security assessments for new and renewing vendors
Qualifications
5+ years of hands-on experience with major cloud service providers (e.g., AWS, Azure, GCP)
5+ years of hands-on experience with endpoint security and detection technologies such as Cortex XDR, CrowdStrike, Microsoft Defender, or equivalent platforms.
5+ years of experience working with SIEM solutions, including log correlation, alert development, and dashboard creation
5+ years of experience in security alert monitoring and incident investigation
3+ years of hands-on experience implementing DevSecOps practices, including security integration within CI/CD pipelines, Infrastructure-as-Code (IaC), container security, and automated security testing
Strong understanding of cloud-native security tools and configurations, including identity and access management, logging/monitoring, and workload protection
Experience developing automation using scripting languages such as Python, PowerShell, Bash, or similar to improve security operations and incident response workflows
Practical experience with threat hunting techniques and methodologies
Familiarity with the MITRE ATT&CK framework and its application to detection engineering and incident analysis
Strong ability to interpret and analyze security logs, network traffic, and system behaviors to detect attack patterns and anomalies
In-depth knowledge of network, endpoint, and cloud security technologies and principles
Demonstrated experience collaborating across global teams and working in cross-functional environments
Strong organizational and time management skills with the ability to work independently
Up-to-date knowledge of recent vulnerabilities, attack vectors, and remediation strategies
Excellent written and verbal communication skills to support collaboration with technical and non-technical stakeholders
Experience administering and fine-tuning security infrastructure is a strong plus
Security professional certifications such as CISSP, CCSP, Security+, GSEC, GCIH, GCIA, AWS Security Specialty, Azure Security Engineer Associate, or equivalent certifications are preferred
Skills Required
- 5+ years of hands-on experience with major cloud service providers, including AWS, Azure, or GCP
- 5+ years of hands-on experience with endpoint security and detection technologies such as Cortex XDR, CrowdStrike, or Microsoft Defender
- 5+ years of experience with SIEM solutions, including log correlation, alert development, and dashboard creation
- 5+ years of experience in security alert monitoring and incident investigation
- 3+ years of hands-on experience implementing DevSecOps practices, CI/CD security integration, Infrastructure as Code, container security, and automated security testing
- Strong understanding of cloud-native security tools and configurations, identity and access management, logging, monitoring, and workload protection
- Experience developing security automation using Python, PowerShell, Bash, or similar scripting languages
- Practical experience with threat hunting techniques and methodologies
- Familiarity with the MITRE ATT&CK framework and its application to detection engineering and incident analysis
- Ability to analyze security logs, network traffic, and system behaviors to detect attack patterns and anomalies
- In-depth knowledge of network, endpoint, and cloud security technologies and principles
- Experience collaborating across global teams and cross-functional environments
- Strong organizational, time management, independent working, written communication, and verbal communication skills
- Up-to-date knowledge of vulnerabilities, attack vectors, and remediation strategies
- Experience administering and fine-tuning security infrastructure
- Security certification such as CISSP, CCSP, Security+, GSEC, GCIH, GCIA, AWS Security Specialty, or Azure Security Engineer Associate
Thales Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Thales and has not been reviewed or approved by Thales.
-
Retirement Support — Retirement plans with employer contributions and matches, profit sharing, and share purchase opportunities are emphasized across multiple regions. These elements are positioned as competitive components of total rewards.
-
Leave & Time Off Breadth — Generous PTO that increases with tenure, paid holidays, and paid military, maternity, and paternity leave are described. This breadth supports work–life balance across locations.
-
Flexible Benefits — Hybrid work options, flexible schedules, and parental supports such as childcare benefits and leave for sick children are available in several markets. Flexibility is presented as a core part of the employee experience.
Thales Insights
What We Do
Thales is a global high technology leader investing in digital and “deep tech” innovations – connectivity, big data, artificial intelligence, cybersecurity and quantum technology – to build a future we can all trust, which is vital to the development of our societies. The company provides solutions, services and products that help its customers – businesses, organisations and states – in the defence, aeronautics, space, transportation and digital identity and security markets to fulfil their critical missions, by placing humans at the heart of the decision-making process.








