Senior Cybersecurity Analyst - 1702

Full Time
On-Site

United States

Posted within last 24 Hours

West Star is the fastest growing maintenance repair organization in the industry and we recognize this is the result of our talented team of trusted employees working together to deliver customer service excellence. We are committed to providing our employees with personal and professional growth opportunities while fostering a culture of respect and well-being with a small company feel.

When you join our team we don’t think you should have to wait for your benefits to kick in. That’s why when you start, they start with you! This includes medical, dental, 401K match, time off accruals, weekly pay days and much more. We don’t want you to live to work, we want you to work and live.

What you can expect as a Senior Cyber Security Analyst at West Star:
The Senior Cybersecurity Analyst leads day-to-day execution of West Star Aviation’s enterprise cybersecurity program across business applications, infrastructure, data, and company locations. The role turns leadership’s security priorities into practical controls, measurable risk reduction, and clear response procedures. It combines hands-on analysis with coordination of technology teams, business owners, and external security partners. The analyst identifies and escalates material risks and recommends policy, and exception decisions to the Technology executive.

You will be ESSENTIAL to many FUNCTIONS including:

Security program and governance

  • Maintain a risk-based security roadmap, control inventory, security standards, and risk register; assess gaps against a recognized framework such as NIST Cybersecurity Framework 2.0 and track owners, deadlines, and accepted exceptions.
  • Draft, maintain, and operationalize security policies and procedures covering access, endpoint and network protection, data handling, acceptable use, third-party access, incident response, and secure technology changes.
  • Coordinate security assessments, penetration tests, audit evidence, and remediation plans; work with Legal, Quality, Finance, and business leaders on applicable customer, contractual, privacy.

Detection and incident response

  • Oversee security alert triage and investigation across endpoint, email, identity, network, cloud, and application signals; use internal tools and managed detection partners to validate threats and drive timely containment.
  • Own and exercise incident response playbooks for ransomware, phishing, business email compromise, account compromise, data exposure, and vendor/payment fraud; lead technical coordination, evidence preservation, escalation, and post-incident corrective actions.
  • Define monitoring requirements, logging coverage, escalation thresholds, and service expectations for security providers; review performance and close gaps in detection and response.

Protective controls and resilience

  • Lead vulnerability management, including scanning coverage, risk-based prioritization, assignment to system owners, verification of remediation, and documented treatment of exceptions.
  • Partner with infrastructure and application teams to strengthen identity and access controls, multifactor authentication, privileged access, endpoint configuration, patching, network segmentation, and secure remote access.
  • Review the security of critical SaaS and cloud services, integrations, customer-facing platforms, and AI-enabled capabilities before deployment or material change; recommend proportionate controls and document residual risk.
  • Partner with operations and data teams on backup security, restoration testing, disaster recovery, data protection, and cyber resilience at company sites.

Security awareness and employee behavior

  • Create and launch an enterprise security awareness program using Mimecast Awareness Training or a comparable platform, including platform configuration, employee enrollment, a recurring content calendar, new-hire training, and role-based modules.
  • Design phishing simulations and short, timely campaigns that address real company risks, including business email compromise, vendor bank-change fraud, suspicious links and attachments, password and MFA practices, data handling, and approved AI use.

Employee reporting and awareness measurement

  • Establish an easy way for employees to report suspicious messages and security concerns; coordinate prompt feedback, targeted follow-up training, and positive reinforcement with HR and business leaders.
  • Measure completion, reporting behavior, simulation results, repeat-risk patterns, and program improvement; present trends and recommended actions to Technology and business leadership without relying on completion rates alone.

Third-party risk and leadership reporting

  • Perform security due diligence for new and renewing technology vendors, review evidence and contractual security commitments, track remediation, and coordinate decisions on material third-party risk.
  • Provide concise reporting on material incidents, control coverage, vulnerabilities, open risks, partner performance, and awareness outcomes; translate technical findings into business impact, priorities, and decisions.
  • Advise project teams on security requirements and design reviews, mentor technology colleagues on secure practices, and participate in urgent incident response and occasional site visits as business needs require.

What you'll need to bring with you:

Your Education:
A bachelor’s degree in cybersecurity, information technology, computer science, or a related field, or equivalent directly relevant professional experience, technical training, military experience, or certifications.

A valid driver’s license approved for airline travel and/or a valid passport is ideal, but not mandatory.

Your Experience:

Required:
At least eight years of progressive experience in cybersecurity or a combination of infrastructure and cybersecurity roles, with substantial recent responsibility for enterprise security controls and incident response.

Demonstrated ability to run a broad security workstream independently, prioritize risk, coordinate remediation across teams, and hold managed security providers accountable.
Hands-on experience investigating endpoint, email, identity, and network threats and working with EDR, email security, SIEM or MDR, vulnerability management, and access control technologies.
Working knowledge of Microsoft 365 or similar enterprise platforms, cloud and SaaS security, network fundamentals, authentication, data protection, and backup or recovery controls.
Experience writing practical policies, assessing technology or vendor risk, leading incident exercises, and communicating with both technical teams and executives.

Preferred:
CISSP, CISM, GIAC, or comparable certification; certification is valued but is not a substitute for demonstrated execution.

Experience with Mimecast awareness or email security, SentinelOne, Microsoft Entra ID, and security operations or managed detection services; equivalent platforms are welcome.
Experience in a multi-site organization and with customer or contractual security obligations, application and integration reviews, or operational technology environments.

Your Initiative:
We’re looking for team players who are self-motivated and able to perform in a fast paced environment where working under specific deadlines and time constraints will be common. This person will also need to be able to maintain confidentiality at all times and have excellent organizational skills.

Your Sense of Responsibility:
Attend work every day as scheduled.

Notify supervisor in advance of shift starting if unable to work.
Must have reliable transportation to get to work each and every day.
Follow all company and safety rules during performance of duties.
Maintain customer oriented work habits.

Other particulars:

Physical Requirements
Lift and carry up to 10 lbs.

Routine walking, bending, stooping and sitting.
Sit at a desk and/or computer for extended intervals.
Routine or repetitive physical motion with arms and hands.

Mental Requirements
Work with others in a professional manner.

Understanding and implementation of regulations and guidelines.
Prioritize workload and work under pressure.
Coordinate multiple projects and duties.

Supervision
Work under minimal supervision.

Work with other Managers coordinating projects in a cooperative manner.

Equipment Used
Computer operating with Windows, Microsoft Word, Excel, Outlook and Powerpoint.

Fax machine, copier, cameras, multi-line telephone system etc.

Compensation & Benefit Information

The following information is disclosed according to state specific requirements. If the position applied to is not in a state with these requirements, the following information may not apply. The salary range for this position generally ranges between $100k-$120k. Actual rate will vary and may be above or below the range based on various factors including but not limited to location, experience and performance. The range listed is just one component of the total compensation package. Other forms of compensation include a semi-annual discretionary bonus, as well as medical, dental, vision, life, disability, 401(k), paid holidays and vacation time.

West Star Aviation’s Benefits

  • Benefits Effective Day One for Eligible Employees
  • Medical, Dental and Vision Coverage with Health Savings Account (HSA) and Flexible Spending Account (FSA) options
  • Life Insurance, Disability Benefits & Supplemental Benefits
  • 401(k) Plan with Employee Contributions & Employer Match
  • Paid Company Holidays & Weekly Paid Time Off Accruals
  • Flexible Work Schedules include 5x8, 4x10 and 3x12
  • Weekly Competitive & Industry Leading Pay means you are paid more often
  • Bonus Opportunity based on Company and Site Performance
  • Internal Mobility & Career Advancement opportunities

This position will accept applications until 10/26/2026

Company Description:

With over 78 years of industry experience, West Star Aviation stands as a leading independent Maintenance, Repair and Overhaul (MRO) provider. Employing over 3,000 professionals, we offer comprehensive services from our strategically located full-service facilities in East Alton, IL; Grand Junction, CO; Chattanooga, TN; Millville, NJ; Perryville, Missouri; and Statesville, NC as well as satellite locations in Denver, Houston, Minneapolis and Chicago. Our extensive capabilities encompass maintenance, paint, interior, and avionics services, supported by the largest Aircraft On Ground (AOG) network in the country, ensuring prompt and reliable mobile repair services nationwide.