We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Senior Security Analyst

Performance Contracting Group
$95,000-$110,000 annual salary plus non-guaranteed annualized bonus program.
life insurance, vision insurance, flexible benefit account, paid time off, paid holidays, 401(k)
United States, Kansas, Lenexa
11145 Thompson Avenue (Show on map)
Oct 05, 2026
Company Overview

Performance Contracting Group is a national employee-owned specialty contractor that offers quality services and products to the commercial, industrial, and non-residential construction markets. We are committed to recruiting, developing, and advancing employees from a diversity of backgrounds and experiences, as well as supporting a culture of safety and inclusiveness that allows you to contribute to your fullest potential. We place high value on training and professional development, encouraging you to broaden and strengthen your unique skill sets so you can fully realize your potential.

The Senior Security Analyst is a senior individual contributor responsible for security monitoring, threat analysis, incident response, vulnerability and exposure management, security assessments, and continuous improvement of operational security practices. The role provides advanced analytical support for complex security events, evaluates technical risk, recommends practical controls, and helps improve the organization's overall security posture.


In addition to broad Senior Security Analyst responsibilities, this position serves as a security subject matter resource for artificial intelligence, automation, citizen-developed applications, and other emerging technologies. AI security is an area of emphasis within the role, not its exclusive function. The position partners closely with Security Operations, Security Engineering, GRC, Data Governance, Privacy, Legal, IT Operations, application owners, platform teams, and business stakeholders.


Essential Functions


Security Monitoring and Threat Analysis



  • Perform advanced security monitoring and analysis across SIEM, endpoint, email, identity, network, cloud, application, and other security data sources.
  • Triage and investigate alerts, correlate activity across multiple platforms, determine business impact, and recommend appropriate response actions.
  • Conduct proactive threat hunting, review relevant threat intelligence, and identify emerging threats that may affect the organization.
  • Improve detection use cases, alert logic, triage guidance, escalation criteria, and analyst investigation procedures.
  • Provide senior-level analytical support for complex security events and mentor analysts through technical review and knowledge sharing.


Incident Response and Investigations



  • Identify, investigate, contain, and support recovery from cybersecurity incidents in coordination with Security Operations and business partners.
  • Analyze suspected unauthorized access, malware, phishing, account compromise, data exposure, policy violations, and other security events.
  • Collect and preserve relevant evidence, document investigative findings, assess impact, and communicate recommended actions clearly.
  • Maintain and improve incident response procedures, investigation playbooks, escalation paths, and lessons-learned activities.
  • Participate in tabletop exercises and readiness activities that strengthen organizational response capabilities.


Vulnerability, Exposure, and Security Control Analysis



  • Analyze vulnerabilities and security exposures, validate findings, assess applicability and risk, and coordinate remediation with system owners.
  • Review technical designs, configurations, authentication and authorization models, network paths, APIs, secrets management, logging, and security controls.
  • Perform or coordinate security assessments, threat modeling, control validation, abuse-case analysis, and technical risk reviews.
  • Track findings through remediation, verification, exception, or formal risk acceptance using established processes.
  • Evaluate new security products and technologies and recommend improvements to security controls, tooling, and operational practices.


AI and Emerging Technology Security



  • Assess AI platforms, generative AI tools, agents, copilots, machine learning solutions, automation, low-code applications, and citizen-developed technology as part of the broader security review function.
  • Evaluate risks involving prompts, model outputs, knowledge sources, connectors, retrieval methods, data flows, third-party processing, retention, identity, and access.
  • Analyze AI-specific threats such as prompt injection, data leakage, insecure output handling, excessive agency, unsafe tool use, unauthorized retrieval, and supply-chain compromise.
  • Provide practical security guidance and reusable control patterns for proof-of-concept, pilot, and production use of AI-enabled solutions.
  • Monitor relevant AI security research, standards, threat activity, and vendor capabilities and translate developments into appropriate security recommendations.
  • Security Advisory, Process Improvement, and Collaboration
  • Provide practical security guidance to IT teams, application owners, platform engineers, citizen developers, vendors, and business stakeholders.
  • Develop and maintain security procedures, review checklists, control requirements, knowledge articles, and repeatable assessment practices.
  • Identify automation and process improvement opportunities that increase consistency, reduce manual effort, and improve response quality.
  • Prepare clear reports, metrics, dashboards, and executive-ready summaries describing security risks, findings, trends, and remediation progress.
  • Partner with Security Engineering, GRC, Data Governance, Privacy, Legal, Procurement, and Vendor Risk Management to support coordinated security outcomes.



Salary range: $95,000-$110,000 annual salary plus non-guaranteed annualized bonus program.



Minimum Requirements



  • Bachelor's degree and/or certifications in information security, cybersecurity, computer science, information technology, or a related field, or equivalent practical experience.
  • Five or more years of progressive experience in cybersecurity, including security monitoring, incident response, investigations, vulnerability analysis, application security, cloud security, or technical risk assessment.
  • Experience performing security investigations, security assessments, threat modeling, vulnerability analysis, or security architecture reviews.
  • Working knowledge of SIEM, EDR/XDR, email security, identity security, vulnerability management, network security, cloud security, application security, and case-management technologies.
  • Foundational knowledge of generative AI, AI-enabled applications, APIs, automation, cloud services, identity and access management, and data security principles.
  • Ability to analyze complex technical activity and designs, identify realistic attack or abuse scenarios, and translate findings into clear business impact and actionable requirements.
  • Strong analytical, problem-solving, organizational, written communication, and interpersonal skills.
  • Ability to work independently and collaboratively across technical teams, business functions, leadership levels, and third-party providers.
  • High level of integrity, sound judgment, attention to detail, and professionalism.


Preferred Requirements



  • Hands-on experience with security monitoring, incident response, threat hunting, vulnerability management, application security testing, API security, or cloud security.
  • Experience assessing or securing generative AI platforms, AI agents, copilots, retrieval-augmented generation solutions, low- code applications, or citizen-developed technology.
  • Experience with Microsoft-focused enterprise environments, including Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Cloud, Microsoft Entra ID, Azure AI services, Microsoft Copilot, or Microsoft Power Platform.
  • Knowledge of common cybersecurity frameworks and guidance, including NIST Cybersecurity Framework, MITRE ATTCCK, CIS Controls, the NIST AI Risk Management Framework, OWASP guidance for large language model applications, or MITRE ATLAS.
  • Experience supporting vendor risk reviews, privacy assessments, data governance, security exceptions, or technology approval processes.
  • Relevant professional certification such as CISSP, CSSLP, CCSP, CISM, CySA+, Security+, GIAC certification, or a comparable cloud or security credential.
  • Experience supporting a geographically distributed organization with a mix of corporate, field, cloud, SaaS, and on-premises technology environments.

Benefits



At Performance Contracting, our employees are our greatest asset. We put our people first and are proud to provide a comprehensive benefits package designed to meet the needs of our employees at every stage of life.


In our commitment to fostering an environment where everyone can thrive personally and professionally, we offer:



  • Competitive pay
  • Incentive bonus plan
  • Employee stock ownership plan (ESOP)
  • 401(k) retirement savings plan with match
  • Medical, prescription drug, dental, and vision insurance plans with flexible spending account option
  • Life insurance, AD&D, and disability benefits
  • Employee assistance program (EAP)
  • Flexible paid time off policy and paid holidays


PCG provides equal employment and affirmative action opportunities to applicants and employees without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability.


PCG is a background screening, drug-free workplace. In accordance with the provisions of Tennessee Code Annotated (T.C.A.), Title 50, Chapter 9, PCG's Drug-Free Workplace Program includes drug and alcohol testing as part of the hiring process and throughout employment, as applicable.


Please note this job description is not designed to contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.


NOTICE TO STAFFING FIRMS, AGENCIES AND EMPLOYMENT VENDORS:


Performance Contracting Group and its affiliates will not accept unsolicited resumes from third party recruiters without a signed Fee Agreement in place AND a candidate has been submitted into our applicant tracking system (Dayforce). Vendor solicitation should be directed to the Corporate Recruitment Department directly; as such, firms that circumvent the required compliant process will be barred from submitting candidates. In the absence of a signed fee agreement AND proper resume submission, PCG does not recognize any claim on a candidate by a third party, will consider unsolicited resumes the property of the company and reserves the right to engage and hire those candidates without any financial responsibility to the third-party vendor.


#PCG

Applied = 0

(web-9db6c7984-8pbzw)