About the RoleRelay is hiring a Senior Cybersecurity Analyst to serve as the technical backbone of our security operations. Reporting to the Sr. Manager of IT & Security and working closely with the SVP of IT & Security, you will be the owner and subject matter expert for our core security platform - Palo Alto Cortex XDR and the day-to-day manager of our relationship with Palo Alto Unit 42, and various outside cybersecurity partners.
This role is equal parts technical depth and organizational trust. You'll be the person every department at Relay works with when a security finding lands on their desk - which means your ability to communicate clearly, build relationships, and set the right tone matters as much as your ability to hunt threats, build tools and manage the tools. You'll need to be firm on what security requires while remaining a partner people genuinely want to work with. If you can hold that line with empathy and credibility, you'll thrive here. We especially value candidates who bring an offensive security mindset - the ability to think like an attacker in order to build stronger defenses, anticipate attack vectors, and design systems that are genuinely difficult to compromise.
About the TeamYou'll join a small, high-leverage IT & Security team responsible for protecting a fast-growing, cloud-first company. We manage a broad technology stack - from identity and device management to SaaS administration and enterprise automation - and we operate as true partners to the business, not just a support function. We move fast, build thoughtfully, and take pride in running a tight, well-integrated environment. We deliberately run a lean internal team amplified by strategic partners and AI-driven tooling, so every member owns real scope, works directly with senior leadership, and sees the impact of their work across the entire organization.
Responsibilities- Lead the Security team in delivering world-class security services to our customers.
- Own and administer the Palo Alto Cortex XDR environment end-to-end as its subject matter expert - configuration, detection tuning, policy management, agent coverage, upgrades, threat hunting (XQL), and incident investigation and response.
- Manage Relay's daily operational relationship with Palo Alto Unit 42, our SOC - coordinate escalations, joint threat hunting, drive incident handoffs and follow-through, review deliverables, and hold the partnership accountable to our expectations.
- Serve as the Cyber subject matter expert for Check Point Harmony, Google Workspace Security, Okta and JumpCloud.
- Act as the primary security liaison to every department at Relay - communicate findings, negotiate remediation timelines, and drive issues to closure while setting a tone that is firm, fair, and constructive.
- Correlate signals across the security stack to deliver a unified view of Relay's security posture, with regular reporting on threats, coverage, and remediation progress to security leadership.
- Investigate and respond to security incidents end-to-end, documenting findings, root causes, and lessons learned in clear runbooks and reports.
- Build automation - scripts, playbooks, and AI-assisted workflows - that reduces manual triage and scales our detection and response capability.
- Support compliance and awareness programs, including Drata evidence collection and KnowBe4 training and phishing simulation campaigns.
Required Qualifications- A degree in Computer Science, IT, or a security-related discipline; equivalent security certifications (CompTIA Security+ or CySA+, ISC2 CiC, Google Cybersecurity Professional, GSEC, GCIH) will be considered in place of a formal degree.
- 5+ years of hands-on experience in a Security Analyst, Security Engineer, or similar security operations role.
- Experience administering Palo Alto Cortex XDR, including detection tuning, posture management, endpoint inventory, and XQL-based investigation and threat hunting or equivalent experience with another SIEM.
- Experience working with or managing an external SOC or MDR provider (Unit 42 experience strongly preferred), including escalation management and incident coordination.
- Hands-on administration experience with Check Point Harmony, Google Workspace security, Okta and JumpCloud.
- Exceptional interpersonal and communication skills: you can explain technical findings in plain language to any department, stay firm on security requirements under pushback, and set a tone that builds trust rather than friction.
- Solid grounding in security fundamentals - the incident response lifecycle, EDR/XDR concepts, vulnerability management, and threat intelligence.
- Proficiency with scripting or automation (XQL, Python, PowerShell, or Bash) to streamline security workflows.
- Offensive security mindset: you think like an attacker when designing defensive security measures - you understand adversary tools, techniques, and tactics (TTPs), and translate that perspective into hardened controls, threat modeling, and proactive detection strategies that anticipate how your systems could be compromised.
Preferred Qualifications- Experience administering Drata and Safebase (or a comparable GRC/compliance - Trust Center automation platform) and supporting SOC 2 / ISO 27001 / HIPAA / NIST 800-53 audit readiness.
- Experience administering KnowBe4 (or a comparable security awareness platform), including phishing simulations and training metrics.
- Relevant certifications such as Palo Alto PCDRA/PCSAE SOAR pathway, Security+, CySA+, GCIH, or equivalent.
- Enthusiasm for applying AI tools to accelerate detection, response, and reporting in day-to-day security work.
- Experience in a fast-paced, cloud-first SaaS environment.
What success and impact looks like in this role:- Within 6 months, you have full, documented ownership of the Cortex XDR environment with tuned detections and 100% endpoint agent coverage.
- The Unit 42 relationship runs on a clear operating rhythm - escalations, incident handoffs, and reporting flow smoothly with no dropped threads.
- Within 3 months, you have a firm relationship with all external business partners, working with pen testers and red teams, and bug bounties on findings.
- Every department knows who you are and views security findings as a collaborative process, not a confrontation - while remediation SLAs are consistently met.
- Checkpoint Harmony, Google Workspace, Okta and JumpCloud configurations are hardened, documented, and continuously improving.
- Automated workflows and AI-assisted processes have measurably reduced manual triage time, and security leadership receives a reliable cadence of posture and threat reporting.
About Relay | Culture, Benefits & PerksOur culture hinges on Relayers getting
LIT up in an environment that fosters Learning, Impact, and Teamwork, where we
CHASE the best work of our lives. We call this
BWIML (Best Work In My Life).
At Relay, we offer:- 100% Paid Insurance: Health, Dental, Vision, Long/Short Term Disability, and Life Insurance for you and your dependents
- Generous Paid Time Off
- 401(k) Savings Plan + Company Match
- Baby Cash Reward + Paid Parental Leave
- Wellness Perks: If you're joining our Raleigh-based HQ, you'll have access to a world-class onsite fitness center with instructor-led classes, plus tennis, basketball, pickleball, and cycling
- Team Events & Culture: From company celebrations to team outings, we work hard and have fun doing it.
- Latest tech, standing desks, and all the tools and software you need to thrive