Security Analyst
AI in this role
Security analyst responsible for incident response, threat hunting, and security automation tooling at Lyft.
At Lyft, our purpose is to serve and connect. We aim to achieve this by cultivating a work environment where all team members belong and have the opportunity to thrive.
Lyft connects people to transportation to change the way we live and get around our communities. Lyft’s engineering team is growing rapidly, and we are looking for Security Analysts to help us scale. Come be part of a team at Lyft focused on enabling and empowering engineering teams to deliver at scale.
Our drivers and passengers entrust Lyft with their personal information and travel details to get where they're going and expect us to keep that data safe. Lyft's security team leads efforts across the company to ensure our systems are secure and worthy of our users' trust.
Lyft Security builds systems to protect and defend infrastructure and services from cyber attacks. We consult with teams as they build and launch new products and features, proactively plans for the unexpected, and responds to incidents that occur. Our work has company wide impact and takes place at all levels of the stack, from infrastructure to web application security, as well as mobile apps, IT, bikes, scooters, etc. We believe in scaling security through engineering fundamentals, automation, and tooling. Check out our blog posts at https://eng.lyft.com/tagged/security to learn more about some of the things we’ve built.
Our Incident Response team lives at the intersection of speed and precision. We own the full lifecycle of security incidents and stay ahead of the curve with our Threat Hunting program.
We are looking for a Security Analyst who is passionate about refining feedback loops and executing proactive security actions. In this fast-paced, ever-evolving landscape, we prioritize knowledge sharing and mentorship. You will collaborate closely with Senior Analysts to sharpen your technical edge, ensuring that as our environment grows, your expertise grows with it.
Responsibilities:
- Incident Response: Respond promptly to security incidents by orchestrating coordinated responses across engineering teams and other relevant disciplines.
- Analyze and Prioritize High-Quality Security Alerts: Assess and prioritize security alerts of high quality with the potential to impact the organization, based on SOCLess approach.
- Develop Automation and Tooling: Create and maintain automation tools to enhance the efficiency and impact of the incident response team's activities.
- Collaborate with the Detection Engineering Team: Work closely with the Detection Engineering Team to identify and implement new security strategies aimed at detecting threats, reducing the attack surface, and enhancing the organization's overall cybersecurity posture.
- Conduct Threat Hunting Operations: Define and execute threat hunting operations across the organization's systems and services, aiming to uncover detection gaps, identify weaknesses in security controls, and refine existing processes.
- Assess the Organization's Threat Landscape: Evaluate the threat landscape specific to the organization to prioritize proactive security measures and actions.
- Cultivate and Maintain Key Partnerships: Establish and nurture relationships with critical partners both within the organization and externally to foster collaboration and information sharing.
Experience:
- Cybersecurity Knowledge:
- A strong drive to learn and ambition for continuous growth within the cybersecurity domain.
- An understanding of cybersecurity principles, including threat landscape and security best practices.
- Familiarity with TTPs (tactics, techniques and procedures), anomaly detection, and behavior analysis.
- Technical Skills:
- Automation & Cloud: Scripting and automation skills, basic experience with cloud technologies such as AWS/GCP and their tech stack.
- Systems & Networking: Strong understanding of operating systems (Windows, Linux, macOS) and networking, including their security features.
- Investigative Mindset: A natural curiosity to find the 'root cause' of problems through log analysis and forensic trail-following.
- Data Analytics: Ability to aggregate and correlate datasets to identify suspicious patterns and outliers.
- AI Augmentation: Proficiency in leveraging AI tools to accelerate workflows, such as scripting, automating repetitive tasks or summarizing complex technical documentation.
- Communication Skills:
- Strong communication skills to collaborate effectively with other team members, stakeholders, and management.
- Ability to document technical activities clearly and concisely.
- Capable of communicating technical concepts in a confident, well-organized manner to both technical and non-technical audiences.
- Adaptability and Collaboration:
- The ability to adapt to evolving technologies and cybersecurity threats and stay current with industry trends.
- Ability to manage multiple tasks and priorities, and work independently.
- Ethical Considerations:
- A strong ethical foundation and commitment to handling sensitive data and incidents with integrity and discretion.
Please submit your resume in English.
How we rate this
Security Analyst at Lyft rates 0 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.
Little AI. AI is not part of the work.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- Tell me about a project where incident response was part of your work. What did you do?
- Tell me about a project where threat hunting was part of your work. What did you do?
- Tell me about a project where security automation was part of your work. What did you do?
- Tell me about a project where alert prioritization was part of your work. What did you do?
- Walk me through how you've used Automation Tools in your day-to-day work.
Adapt your resume
- List these exact terms on your resume: Incident Response, Threat Hunting, Security Automation, Alert Prioritization, and Automation Tools. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
Want an expert to read your CV for this job?
Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.
Get a free CV reviewGet new remote cybersecurity jobs by email
One email a week with the new remote cybersecurity jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Security roles that involve little AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step