Cybersecurity Analyst II
Job Description
CareDx, Inc. is seeking a Cybersecurity Analyst II (Brisbane, CA, remote) to help safeguard information systems and data. This role focuses on continuous monitoring, investigation, and response across multiple security platforms, while supporting the organization’s growing AI security efforts.
Key Responsibilities
- Monitor, configure, and maintain AI Detect and Response (AIDR) tooling to identify and reduce risks related to organizational AI usage
- Monitor security alerts, logs, dashboards, and telemetry from SIEM, EDR, ThreatLocker, DLP, cloud, and other cybersecurity platforms
- Investigate, triage, and respond to cybersecurity incidents involving malware, phishing, unauthorized access, suspicious behavior, policy violations, and potential data exposure
- Support ThreatLocker operational response activities, including application control reviews, policy management, and endpoint troubleshooting
- Analyze DLP alerts and assist with investigations involving sensitive data handling, potential exfiltration events, and policy violations
- Conduct vulnerability analysis and coordinate remediation activities with infrastructure, engineering, and application teams
- Assist with threat hunting, threat modeling, security assessments, and control gap analysis
- Participate in incident response tasks including containment, investigation, root cause analysis, remediation coordination, and post-incident reporting
- Support security monitoring and operational governance for technologies and emerging threats
- Assist with development and maintenance of cybersecurity operational procedures, standards, and documentation
- Support compliance, audit, and regulatory activities tied to frameworks including NIST, ISO 27001, HIPAA, SOC 2, and SOX
- Stay current on emerging cybersecurity threats, AI security risks, vulnerabilities, attack techniques, and industry best practices
- Collaborate with IT, Engineering, Compliance, Legal, Risk Management, and business stakeholders to strengthen CareDx’s security posture
Required and Preferred Qualifications
- High School Diploma or GED required
- 2-3 or more years of cybersecurity, security operations, incident-response, or related IT experience
- Associate’s or Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related field preferred
- Experience investigating EDR, MDR, endpoint, identity, or email-security alerts
- Knowledge of Windows, Microsoft 365, Entra ID, endpoint security, and common cyber threats
- Ability to analyze logs, process activity, authentication records, URLs, IP addresses, and file hashes
- Strong skills in investigation, documentation, communication, and prioritization
- Experience with ThreatLocker, CrowdStrike, Microsoft Defender, SIEM, or ticketing platforms preferred
- Industry-recognized cybersecurity certifications such as CompTIA Security+, CySA+, Microsoft SC-200, or comparable certifications preferred
Technologies
- AI Detect and Response (AIDR)
- SIEM, EDR, DLP
- ThreatLocker
- AI security vendors
- NIST, ISO 27001, HIPAA, SOC 2, SOX
- Windows, Microsoft 365, Entra ID
- CrowdStrike, Microsoft Defender
- Ticketing platforms
- CompTIA Security+, CySA+, Microsoft SC-200, MDR
Location and Compensation
Location: Brisbane, CA (remote). Salary: USD 83,000 - 100,000 per year.
Benefits
- Competitive base salary and incentive compensation
- Health and welfare benefits, including a gym reimbursement program
- 401(k) savings plan match
- Employee Stock Purchase Plan
- Pre-tax commuter benefits
- Living Donor Employee Recovery Policy allowing up to 30 days of paid leave annually for a full-time employee who donates an organ or bone marrow
Mission and Team Context
CareDx states that every individual impacts its mission to improve the lives of organ transplant patients worldwide. The company highlights a Total Rewards package for US employees and notes that additional details can be found at https://caredx.com/company/careers.