Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Security Analyst image - Rise Careers
Job details

Security Analyst

At SiteMinder we believe the individual contributions of our employees are what drive our success. That’s why we hire and encourage diverse teams that include and respect a variety of voices, identities, backgrounds, experiences and perspectives. Our diverse and inclusive culture enables our employees to bring their unique selves to work and be proud of doing so. It’s in our differences that we will keep revolutionising the way for our customers. We are better together!

What We Do…

We’re people who love technology but know that hoteliers just want things to be simple. So since 2006 we’ve been constantly innovating our world-leading hotel commerce platform to help accommodation owners find and book more guests online - quickly and simply.

 

We’ve helped everyone from boutique hotels to big chains, enabling travellers to book igloos, cabins, castles, holiday parks, campsites, pubs, resorts, Airbnbs, and everything in between.

 

And today, we’re the world’s leading open hotel commerce platform, supporting 44,500 hotels in 150 countries - with over 100 million reservations processed by SiteMinder’s technology every year.

About the Security Analyst role...

We are seeking a skilled Security Analyst to join our team, focusing on offensive security techniques, technical integrations, security operations, and fraud analysis. The role combines hands-on technical security testing with development work to enhance our security infrastructure and fraud detection capabilities.

What you’ll do…

Security Operations

  • Daily review security alerts in SiteMinder’s security platform. 

  • Experience using SIEM including running queries.

  • Ability to analyze logs for incident investigation.

  • Experience using Google Chronicle, CrowdStrike, Google Workspace, Stripe and Cloudflare. 

  • Knowledge of YARA-L 2.0, Splunk query language, JSON data modelling and syslog data format.

  • Identify threats and cyber security issues from security alerts.

  • Write security incident reports that correctly capture the details of security events and actions taken to resolve or mitigate the security issue.

  • Enforce security policies across multiple systems and ensure that security controls are relevant for the level of protection required.

  • Review and update detection rules to reduce false positives and unnecessary notifications.

  • Playbook / incident response processes development.

  • Reviewing and audit monitoring solutions for different parts of the business.

  • Integration of additional application logging into the security platform, Google Chronicle. 

  • Ensure security operations are utilising technical in the most effective way with the features available.

  • Communication with vendors on additional features required by the security platform.

Compliance and Information Security Standards

  • Ensure security controls meet compliance requirements, specifically, PCI DSS, GDPR and ISO 27001

  • Research general security issues that come up from time to time.

  • Auditing effectiveness of technical controls and gathering evidence of external audits.

Data Security

  • Reviewing third-party vendor security assessments and communicating gaps to employees and vendors. 

  • Management of information security policies by aligning information security policies to relevant international security standards.

  • Evaluate SiteMinder’s security practices against the NIST cybersecurity framework (CSF). 

  • Communication of information security policies across SiteMinder departments.

What you have…

  • Strong programming skills in languages such as Go, Python, Kotlin, Java, Logstash, YARA-L, or similar.

  • Experience with penetration testing tools and methodologies.

  • Knowledge of API integration and development.

  • Understanding of security protocols and common attack vectors.

  • Experience with fraud detection and analysis.

  • Strong analytical and problem-solving skills.

  • Familiarity with security automation and tooling.

  • Experience with red teaming operations and offensive security.

  • Knowledge of common security vulnerabilities and mitigation strategies.

  • Strong documentation and communication skills.

  • Ability to work independently and as part of a team.

  • Experience with security monitoring and incident response.

  • Relevant security certifications (e.g., OSCP, CEH, SANS) are a plus.

  • Background in software development or systems engineering.

  • Understanding of network protocols and security architectures.

  • Experience with cloud security and infrastructure.

Our Perks & Benefits…

- Equity packages for you to be a part of the SiteMinder journey 

- Hybrid working model (in-office & from home)

- Mental health and well-being initiatives

- Generous parental (including secondary) leave policy

- Paid birthday, study and volunteering leave every year

- Sponsored social clubs, team events, and celebrations

- Employee Resource Groups (ERG) to help you connect and get involved 

- Investment in your personal growth offering training for your advancement

Does this job sound like you? If yes, we'd love for you to be part of our team! Please send a copy of your resume and our Talent Acquisition team will be in touch.

When you apply, please tell us the pronouns you use and any adjustments you may need during the interview process. We encourage people from underrepresented groups to apply.

SiteMinder Glassdoor Company Review
4.0 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
SiteMinder DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of SiteMinder
SiteMinder CEO photo
Sankar Narayan
Approve of CEO

Average salary estimate

$70000 / YEARLY (est.)
min
max
$60000K
$80000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security Analyst, SiteMinder

At SiteMinder, we're on the lookout for a passionate Security Analyst to join our vibrant team in Manila! If you love tackling security challenges and diving into the techy side of things, this is the perfect opportunity for you. Our commitment to diversity and inclusion means we welcome unique perspectives and backgrounds, enabling us to continuously innovate and revolutionize the hospitality industry. As a Security Analyst, you’ll play a crucial role in enhancing our security infrastructure while combining hands-on technical testing with development efforts. You’ll be analyzing security alerts daily, investigating incidents, and ensuring that we maintain compliance with international standards like PCI DSS and GDPR. You’ll work with advanced systems like Google Chronicle and CrowdStrike, and your skills in programming languages such as Python and Go will shine in our fast-paced environment. Your responsibility will include reviewing and updating detection rules to minimize false positives and ensuring our policies align with the required security standards. Plus, you’ll have the chance to communicate with various teams and vendors, contributing to the overall security strategy of a company that supports over 44,500 hotels in 150 countries. Not only do we believe in your professional growth, but we also prioritize your well-being with a hybrid working model and fantastic perks like mental health initiatives and paid leave for volunteering. So, if you’re ready to join a company that values your contributions and offers a supportive community, we’d love to hear from you at SiteMinder!

Frequently Asked Questions (FAQs) for Security Analyst Role at SiteMinder
What are the key responsibilities of a Security Analyst at SiteMinder?

As a Security Analyst at SiteMinder, your primary responsibilities will include reviewing security alerts, conducting incident investigations, and ensuring compliance with standards like PCI DSS and GDPR. You'll work with various security tools such as Google Chronicle and CrowdStrike, develop playbooks for incident response, and write reports on security incidents. Additionally, you'll be involved in refining our security policies and ensuring the effectiveness of our security measures against potential threats.

Join Rise to see the full answer
What qualifications are required for the Security Analyst position at SiteMinder?

To succeed as a Security Analyst at SiteMinder, candidates should possess strong programming skills in languages such as Go, Python, and Java, along with hands-on experience in penetration testing and familiarity with security protocols. A background in software development or systems engineering is also beneficial, as well as experience in fraud detection and analysis. Relevant security certifications like OSCP or CEH are a plus, showcasing your commitment to professional growth in the cybersecurity domain.

Join Rise to see the full answer
What tools and technologies does a Security Analyst at SiteMinder work with?

In the role of a Security Analyst at SiteMinder, you'll utilize various cutting-edge tools and technologies including Google Chronicle, CrowdStrike, Stripe, and Cloudflare. Familiarity with SIEM tools, Splunk query language, and capably managing JSON data formats will enhance your ability to analyze incidents effectively. Your role also involves utilizing programming languages like Logstash and YARA-L to integrate and improve our security measures.

Join Rise to see the full answer
How does SiteMinder support continuous learning for Security Analysts?

SiteMinder is committed to the professional development of its employees, offering extensive support for continuous learning. As a Security Analyst, you’ll have access to training programs and resources that aid in your professional growth and advancement in the field of cybersecurity. Additionally, the company sponsors employee involvement in social clubs and initiatives that can enhance your skill set and network within the industry.

Join Rise to see the full answer
What is the work culture like for a Security Analyst at SiteMinder?

At SiteMinder, the work culture is built on collaboration, diversity, and inclusion. As a Security Analyst, you’ll be part of a team that values varied perspectives and backgrounds, fostering an environment that encourages innovative ideas and effective problem-solving. With a hybrid working model, you can enjoy flexibility while engaging with your team through exciting initiatives designed to promote mental well-being and personal growth.

Join Rise to see the full answer
Common Interview Questions for Security Analyst
Can you explain your experience with security operations and SIEM tools?

In responding to this question, you should highlight any direct experience with security operations, particularly your familiarity with SIEM tools. Discuss specific tools you have used, such as Splunk or Google Chronicle, and give examples of how you analyzed security alerts or incidents. Mention any relevant metrics or achievements, and show how your experience can benefit SiteMinder's security operations.

Join Rise to see the full answer
What programming languages are you proficient in, and how have you applied them in security roles?

When answering this question, specify the programming languages you are proficient in, such as Go or Python. Provide examples of projects or tasks where you've used these languages to enhance security measures or automate processes. This showcases not only your technical skills but also your practical application in a real-world security environment.

Join Rise to see the full answer
How do you stay updated on the latest cybersecurity threats and trends?

To effectively answer this question, discuss your strategies for staying informed about current cybersecurity trends, such as following leading blogs, participating in online forums, or attending industry conferences. You could mention specific resources you trust, like cybersecurity news websites, or professional networks where you engage with fellow security analysts to share insights and experiences.

Join Rise to see the full answer
Describe a time when you identified a security vulnerability. How did you handle it?

In this response, you should provide a situational example of a security vulnerability you encountered. Describe the steps you took to identify, analyze, and resolve the issue, emphasizing the impact of your actions on the organization. Make sure to communicate the importance of collaboration with other teams and any measures put in place to prevent future occurrences.

Join Rise to see the full answer
What experience do you have with import security frameworks like NIST or ISO 27001?

When answering this question, outline your familiarity and direct experience with different security frameworks such as NIST Cybersecurity Framework or ISO 27001. Discuss how you have applied these frameworks in previous roles, focusing on compliance audits, risk assessments, or policy development that aligns with SiteMinder's security standards.

Join Rise to see the full answer
How would you approach integrating third-party vendor assessments into your security process?

To answer this question effectively, explain the importance of third-party vendor security and outline a structured approach you would take. Discuss how you would conduct assessments, communicate findings, and what criteria you would use to evaluate vendor security measures. Highlight the significance of ongoing communication and creating a culture of security awareness across the organization.

Join Rise to see the full answer
What techniques do you use for incident response and mitigation?

In this response, share your preferred methodologies for handling security incidents, such as playbook development and the practice of updating detection rules. Illustrate how you document and communicate incidents, analyze them for root cause, and outline how those incidents inform future improvements in the security architecture at SiteMinder.

Join Rise to see the full answer
Can you explain the importance of compliance in your work as a Security Analyst?

When discussing the importance of compliance, emphasize how adherence to regulations like PCI DSS and GDPR minimizes risks and builds trust with customers. Explain how you ensure that security controls are aligned with compliance requirements and how you incorporate best practices into daily security operations at SiteMinder.

Join Rise to see the full answer
What role does collaboration play in your work as a Security Analyst?

In your answer, speak to the importance of teamwork and communication in the role of a Security Analyst. Illustrate how you work with cross-functional teams to share information about security incidents, develop training sessions, and foster a security-first mindset throughout the organization. This will illustrate your understanding of how collaboration strengthens SiteMinder’s overall security posture.

Join Rise to see the full answer
What motivates you to work in cybersecurity, particularly as a Security Analyst at SiteMinder?

While answering this, share your passion for cybersecurity and what drives your interest in the field. Highlight what specifically draws you to SiteMinder’s mission and culture, and how you see your contributions impacting the company and its customers. This will demonstrate your alignment with SiteMinder's values and vision.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
SiteMinder Remote No location specified
Posted 13 days ago
Photo of the Rise User
Posted 13 days ago
Photo of the Rise User
Posted 13 days ago
Photo of the Rise User
Posted 9 days ago
Photo of the Rise User
Posted 21 hours ago
Photo of the Rise User
Procore Technologies Hybrid 221 West 6th Street, Austin, TX
Posted 5 days ago
Photo of the Rise User
Posted 13 days ago
Photo of the Rise User
Posted 7 days ago
Photo of the Rise User
Posted 4 days ago

To liberate hoteliers with technology that makes a world of difference

63 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
January 4, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!