Southwest Airlines Logo

Southwest Airlines

Cybersecurity Analyst

Posted 2 Days Ago
Be an Early Applicant
In-Office
Dallas, TX
99K-110K Annually
Mid level
In-Office
Dallas, TX
99K-110K Annually
Mid level
Monitor, analyze, and respond to cybersecurity events while translating threat intelligence into actionable outcomes. Lead incident response, threat hunting, vulnerability management, security infrastructure improvements, GRC, privacy, and security awareness initiatives. Develop intelligence reports, map adversary behavior to MITRE ATT&CK, support Red and Purple Team operations, improve detection workflows, mentor analysts, and collaborate with leadership and cross-functional stakeholders.
The summary above was generated by AI

Department:

Technology

Our Company Promise

We are committed to provide our Employees a stable work environment with equal opportunity for learning and personal growth. Creativity and innovation are encouraged for improving the effectiveness of Southwest Airlines. Above all, Employees will be provided the same concern, respect, and caring attitude within the organization that they are expected to share externally with every Southwest Customer.

Job Description:

Job Summary
Ready to help strengthen and defend Southwest’s cybersecurity posture? As a Cybersecurity Analyst focused on Threat Intelligence and Threat Operations, you will actively monitor, analyze, and respond to security events while translating adversary intelligence into actionable outcomes. You will support Threat Hunting, Red Team, and Purple Team activities by ensuring detection and response strategies are grounded in real‑world threat behavior. This role also contributes to the continuous improvement of cybersecurity policies and procedures, strengthens protection of digital assets, and promotes a strong culture of security awareness and compliance across the organization.

Additional details:

  • This role is offered as a remote workplace position, which may require travel for trainings, meetings, conferences, etc. Outside of those required visits, the majority of your working time may be spent in an approved remote location, away from our Corporate Campus. Please note, while this is a remote position, there is limited group of states or localities ineligible for Employees to regularly perform their work off-site. Those ineligible locations are: Alaska, California, Colorado, Delaware, Illinois, Iowa, Massachusetts, Maryland, Montana, New Jersey, New Hampshire New York, North Dakota, South Dakota, Oregon, Pennsylvania, Vermont, Washington, West Virginia, and Wyoming, and Puerto Rico. 
  • U.S. citizenship or current authorization to work in the U.S. required and no current or future work authorization sponsorship available.  

We’re committed to fair hiring practices and to making employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity, gender expression, national origin, age, military or veteran status, disability, genetic information, or other legally protected characteristics. 

Responsibilities
  • Demonstrate advanced analytical skills across diverse cybersecurity domains, leading the identification and resolution of complex cybersecurity issues in areas such as Incident Response, Threat Intelligence, Governance, Risk, and Compliance (GRC), Privacy, Vulnerability Management, and Engineering Operations
  • Lead and actively participate in high-priority incident response efforts, taking ownership of critical activities related to the identification, containment, and resolution of security incidents, and providing mentorship to junior analysts
  • Drive advanced threat intelligence initiatives, including the development of threat hunting strategies, proactive identification of emerging threats, and the implementation of innovative solutions to enhance the organization's security posture
  • Take a lead role in vulnerability management, overseeing and improving the vulnerability assessments and scanning processes, and providing mentorship to junior and mid-level analysts
  • Architect and lead the optimization of the organization's security infrastructure, overseeing the implementation of advanced cybersecurity controls, and ensuring the organization is prepared to address evolving cyber threats
  • Take a leadership role in maturing GRC initiatives, ensuring comprehensive understanding, and proactively shaping cybersecurity regulations, standards, and best practices within the organization
  • Lead privacy initiatives, overseeing the implementation and enforcement of privacy controls and practices, and ensuring the protection of sensitive information in compliance with relevant regulations
  • Drive the continual improvement of cybersecurity practices and resilience, staying at the forefront of industry trends and emerging technologies to shape and enhance the organization’s advanced security posture
  • Lead the development and execution of comprehensive cybersecurity training and awareness initiatives, tailoring programs to different audiences and providing mentorship to junior team members
  • Play a key role in fostering collaboration across the organization, engaging with senior leadership, cross-functional teams, and external stakeholders, and representing the cybersecurity function at a strategic level
  • May perform other job duties as directed by Employee's Leaders
Knowledge, Skills and Abilities
  • Knowledge of various cybersecurity frameworks and standards (e.g., NIST, ISO 27001) to guide security initiatives
  • Knowledge of data protection and privacy regulations (e.g., GDPR, CCPA) to ensure the safeguarding of sensitive information
  • Knowledge of incident response procedures and methodologies for effective response to security incidents
  • Skilled in conducting risk assessments and developing risk mitigation strategies
  • Skilled in using security monitoring tools, SIEM systems, and intrusion detection systems for threat detection and analysis
  • Skilled in written and verbal communication skills for reporting and conveying technical information to non-technical stakeholders
  • Ability to proactively identify and assess risks, and implement mitigation strategies to protect the organization's assets
  • Ability to monitor program risks, issues, and scope related to cybersecurity initiatives with the appropriate level of priority and escalation
  • Skilled in collaborating with cross-functional teams and stakeholders to drive cybersecurity initiatives and risk management
  • Ability to adapt to evolving threats, technologies, and best practices in the dynamic field of cybersecurity
Education
  • Required: High School Diploma or GED
Experience
  • Required: Intermediate-level experience, fully functioning broad knowledge in cybersecurity principles and concepts, developing skills and knowledge in information technology (IT) operations, programming, systems/software development or another IT related field
  • Preferred: Experience as a specialized Threat Intelligence and Threat Operations individual contributor responsible for providing actionable, intelligence driven support to Threat Hunting, Red Team, and Purple Team operations.
  • Preferred: Experience in translating adversary intelligence into operational outcomes, ensuring that threat hunting, detection engineering, and adversary emulations are grounded in real world threat actor behavior.
  • Preferred: Experience in deep threat actor analysis and tracking of adversary behaviors and TTP evolution.
  • Preferred: Experience in mapping intelligence findings to MITRE ATT&CK to support detection and emulation
  • Preferred: Experience producing intelligence reports and technical packages for Red, Purple, and Hunt teams.
  • Preferred: Experience supporting threat hunting operations with actionable intelligence and hunt hypotheses.
  • Preferred: Experience developing and operationalizing IOC driven hunting workflows.
  • Preferred: Experience partnering with engineering and hunting teams to mature and automate threat informed processes
  • Preferred: Experience delivering intelligence briefings to technical teams and leadership.
Licensing/Certification
  • Preferred: GIAC Cyber Threat Intelligence (GCTI)
  • Preferred: Certified Threat Intelligence Handler (CTIH)
  • Preferred: CompTIA Cybersecurity Analyst (CySA+)
  • Preferred: CISSP (ISC2 Certified Information Systems Security Professional)
Physical Abilities
  • Ability to perform work duties from [limited space work station/desk/office area] for extended periods of time
  • Ability to communicate and interact with others in the English language to meet the demands of the job
  • Ability to use a computer and other office productivity tools with sufficient speed and accuracy to meet the demands of the job
Other Qualifications
  • Must maintain a well-groomed appearance per Company appearance standards as described in established guidelines
  • Must be a U.S. citizen or have authorization to work in the United States as defined by the Immigration Reform Act of 1986
  • Must be at least 18 years of age
  • Must be able to comply with Company attendance standards as described in established guidelines
  • Must be able to travel and /or attend Company and non-Company facilities and remote locations such as remote-based offices as necessary

Pay & Benefits

Competitive market salary from $98,650 - $109,600 per year* depending on qualifications and experience, with opportunity for future pay increases based on performance and market movement. For eligible leadership and individual contributor roles, additional bonus opportunities are available and awarded at the discretion of the company.

Benefits you’ll love:

  • Fly for free, as a privilege, on any open seat on all Southwest flights (your eligible dependents too) 

  • Southwest will help fund your Retirement Savings Plan with Company contributions up to 9.3% of your eligible earnings** 

  • Potential for annual ProfitSharing contribution in the Southwest Retirement Savings Plan- when Southwest profits, you profit*** 

  • Competitive health insurance for you and your eligible dependents (including pets) 

  • Southwest offers health plan coverage options that start from the very first day of employment. You will have 30 days to select and enroll in your health plan with coverage retroactively available to your first day of employment. 

  • Explore more Benefits you’ll love: https://careers.southwestair.com/benefits

*Pay amount doesn’t guarantee employment for any particular period of time

**401(k) match contributions are subject to the plan’s vesting schedule and applicable IRS limits

***ProfitSharing contributions are subject to plan’s vesting schedule and are made at the discretion of the Company

Southwest Airlines is an Equal Opportunity Employer.
Please print/save this job description because it won't be available after you apply.

Similar Jobs

2 Hours Ago
In-Office
Austin, TX, USA
Senior level
Senior level
Security
Administers Armis Centrix and performs Tier 3 SOC cybersecurity operations for a state government customer. Responsibilities include network security monitoring, incident investigation and response, threat and vulnerability analysis, forensic evidence collection, incident containment, secure system restoration, threat intelligence analysis, tool configuration, vendor coordination, metrics reporting, and executive briefings.
Top Skills: Armis Centrix
Yesterday
In-Office
Austin, TX, USA
Senior level
Senior level
Information Technology • Security • Consulting • Cybersecurity
Monitor and investigate cybersecurity alerts across enterprise platforms, triage and validate incidents, analyze threats and indicators of compromise, document investigations, coordinate containment and recovery, escalate confirmed threats, tune detection capabilities, review vulnerabilities, and develop SOC procedures and playbooks within a 24x7 operations environment.
Top Skills: Cloud SecurityCrowdstrikeEdrEmail SecurityFirewallsIdentity ProtectionIntrusion Detection SystemsIntrusion Prevention SystemsMicrosoft SentinelNetwork SecurityPrismaQualysSIEMSplunkTenableThreat IntelligenceZscaler
Yesterday
Hybrid
Junior
Junior
Fintech • Financial Services
Executes cybersecurity governance and risk initiatives by developing policies, standards, and procedures; managing audits, remediation tracking, security requirements, and compliance reporting. Partners with business and technical teams to protect information assets, monitor adherence to controls, and address threats. The role requires knowledge of networking, infrastructure, security frameworks, IT service management, cloud technologies, and relevant regulations. It operates in a flexible hybrid environment with four office days weekly.
Top Skills: AgileCloud TechnologiesDevOpsDnsHTTPIbm IseriesIbm PseriesIso 27001Microsoft CopilotMS OfficeNist 800-53Nist Cybersecurity FrameworkOsi ModelSshSslTcp/IpTmshTsmUmlVisioVlan

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account