1

Security Assurance Analyst Jobs (NOW HIRING)

Threat Modeling & Exploitability Analysis * Evaluate the quality, completeness, and realism of product threat models and challenge assumptions through attacker-informed analysis. * Conduct ...

Product Security Assurance Architect

Milpitas, CA ยท On-site

$74 - $95.75/hr

Threat Modeling & Exploitability Analysis * Evaluate the quality, completeness, and realism of product threat models and challenge assumptions through attacker-informed analysis. * Conduct ...

We deliver tailored solutions, tested leadership, and trusted results to enable national security missions worldwide. Overview: SOSi is seeking a highly qualified Quality Assurance Analyst to join ...

We deliver tailored solutions, tested leadership, and trusted results to enable national security missions worldwide. Overview: SOSi is seeking a highly qualified Quality Assurance Analyst to join ...

We deliver tailored solutions, tested leadership, and trusted results to enable national security missions worldwide. Overview: SOSi is seeking a highly qualified Quality Assurance Analyst to join ...

New

Showing results 21-40

Security Assurance Analyst information

See salary details

$29.5K

$84.3K

$136.5K

How much do security assurance analyst jobs pay per year?

As of Jul 24, 2026, the average yearly pay for security assurance analyst in the United States is $84,280.00, according to ZipRecruiter salary data. Most workers in this role earn between $34,000.00 and $105,000.00 per year, depending on experience, location, and employer.

What is a Security Assurance Analyst?

A Security Assurance Analyst is a professional responsible for ensuring that an organization's information systems meet established security standards and compliance requirements. They assess potential risks, review policies and procedures, and conduct audits or tests to verify the effectiveness of security controls. Their work helps protect sensitive data and maintain the overall security posture of the organization. Security Assurance Analysts often collaborate with IT, compliance, and risk management teams to identify vulnerabilities and recommend improvements.

What are typical challenges Security Assurance Analysts face when working with cross-functional teams?

Security Assurance Analysts often work closely with IT, development, and business teams to ensure security standards are met. A common challenge is translating complex security requirements into actionable steps for colleagues who may have varying levels of security knowledge. Balancing compliance needs with project deadlines can also create tension, requiring strong communication and negotiation skills. Building effective partnerships and fostering a culture of security awareness are key to overcoming these challenges and achieving successful outcomes.

What are the key skills and qualifications needed to thrive as a Security Assurance Analyst, and why are they important?

To thrive as a Security Assurance Analyst, you need a solid understanding of information security principles, risk management, and compliance frameworks, often supported by a degree in cybersecurity or a related field. Familiarity with tools like vulnerability scanners, SIEM systems, and certifications such as CISSP or CISA is typically required. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart in this role. These competencies ensure that organizations can proactively identify, assess, and mitigate security risks to protect sensitive data and maintain regulatory compliance.

What is the difference between Security Assurance Analyst vs Security Compliance Specialist?

AspectSecurity Assurance AnalystSecurity Compliance Specialist
CertificationsCompTIA Security+, CISSP, CISAISO 27001 Lead Auditor, CISSP, CISA
Work EnvironmentIT security teams, corporate security departmentsRegulatory agencies, corporate compliance teams
Employer & IndustryTech companies, financial institutions, governmentAny industry with regulatory requirements, consulting firms
Primary FocusAssessing security controls, risk management, security assuranceEnsuring compliance with security standards and regulations

The Security Assurance Analyst focuses on evaluating and improving security controls and risk management, while the Security Compliance Specialist ensures adherence to security standards and regulatory requirements. Both roles often collaborate but serve different core functions within security teams.

Can you make $500,000 a year in cyber security?

Security Assurance Analysts typically earn salaries ranging from $70,000 to $130,000 annually, depending on experience, certifications, and location. Reaching a $500,000 annual salary generally requires senior roles such as cybersecurity executives, consultants, or specialists with extensive expertise and leadership responsibilities, often supplemented by bonuses or profit sharing.

Is 40 too old for cyber security?

Security Assurance Analysts can enter the cybersecurity field at any age, as experience, skills, and certifications like CISSP or CompTIA Security+ are often more important than age. Many professionals successfully transition into cybersecurity later in their careers, bringing valuable perspectives and expertise. Age should not be a barrier to pursuing a role in cybersecurity or related security fields.

Is SOC an entry level job?

A Security Operations Center (SOC) analyst role is not typically entry-level; it usually requires some experience in cybersecurity, network monitoring, or related fields. Entry-level positions in cybersecurity may include roles like security technician or junior analyst, with SOC roles often requiring certifications such as CompTIA Security+ or SIEM tools knowledge. However, some organizations offer entry-level SOC positions for candidates with foundational skills and a willingness to learn.

Is SOC analyst a high paying job?

A Security Operations Center (SOC) analyst typically earns a competitive salary that varies by experience, certifications, and location. Entry-level positions may start lower, but experienced analysts with certifications like CISSP or CEH can earn higher salaries, often comparable to other cybersecurity roles. Overall, it is considered a well-paying job within the cybersecurity field.
What cities are hiring for Security Assurance Analyst jobs? Cities with the most Security Assurance Analyst job openings:
Who are the top companies hiring for Security Assurance Analyst jobs? The top employers for Security Assurance Analyst jobs are:
Infographic showing various Security Assurance Analyst job openings in the United States as of July 2026, with employment types broken down into 66% Full Time, 4% Part Time, and 30% Contract. Highlights an 61% Physical, 5% Hybrid, and 34% Remote job distribution, with an average salary of $84,280 per year, or $40.5 per hour.
Product Security Assurance Architect

Product Security Assurance Architect

Sandisk

Milpitas, CA โ€ข On-site

$194K - $322K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 2 days ago


Job description

Company Description
Sandisk understands how people and businesses consume data and we relentlessly innovate to deliver solutions that enable today's needs and tomorrow's next big ideas. With a rich history of groundbreaking innovations in Flash and advanced memory technologies, our solutions have become the beating heart of the digital world we're living in and that we have the power to shape.
Sandisk meets people and businesses at the intersection of their aspirations and the moment, enabling them to keep moving and pushing possibility forward. We do this through the balance of our powerhouse manufacturing capabilities and our industry-leading portfolio of products that are recognized globally for innovation, performance and quality.
Sandisk has two facilities recognized by the World Economic Forum as part of the Global Lighthouse Network for advanced 4IR innovations. These facilities were also recognized as Sustainability Lighthouses for breakthroughs in efficient operations. With our global reach, we ensure the global supply chain has access to the Flash memory it needs to keep our world moving forward.
Job Description
Sandisk's Product Security Engineering & Assurance (PSEA) organization is seeking a highly experienced Product Security Assurance Architect to strengthen security assurance across SanDisk's firmware-driven products and storage platforms.
This role is responsible for advancing product security through independent technical security assurance, exploitability analysis, adversarial security assessment, and product security lifecycle effectiveness across the portfolio.
Working in close partnership with Platform Security, product engineering, firmware, ASIC, validation, and PSIRT teams, this position focuses on evaluating the effectiveness, completeness, and defensibility of implemented security controls and product security posture, helping ensure products are resilient against realistic threats and aligned with customer, business, and regulatory expectations.
This role is distinct from embedded product security architecture and implementation functions. Product and Platform Security teams remain responsible for defining and implementing security architectures within products. This role focuses on independent technical assurance, attacker-informed analysis, security lifecycle maturity, and scalable product security risk reduction across the portfolio.
Essential Duties and Responsibilities:
Product Security Assurance & Technical Assessment
  • Conduct independent technical security assessments of firmware-driven products, and embedded platforms to identify security gaps, attack paths, implementation weaknesses, and residual risk.
  • Assess the effectiveness and completeness of implemented security controls, security mechanisms, and architecture decisions from an assurance and exploitability perspective.
  • Evaluate trust boundaries, privileged operations, manufacturing pathways, debug capabilities, firmware update mechanisms, and product lifecycle transitions for potential security weaknesses.

Threat Modeling & Exploitability Analysis
  • Evaluate the quality, completeness, and realism of product threat models and challenge assumptions through attacker-informed analysis.
  • Conduct exploitability and attack surface analysis across firmware and embedded systems, including:
    • secure boot and roots of trust,
    • authentication and authorization controls,
    • secure firmware update paths,
    • manufacturing and RMA workflows,
    • debug interfaces (UART/JTAG),
    • provisioning and lifecycle security,
    • cryptographic implementations and key management approaches.
  • Partner with engineering teams to recommend practical, risk-informed mitigations and compensating controls.

Security Lifecycle Assurance
  • Advance secure development lifecycle (SDL) effectiveness across product teams by assessing security rigor, implementation quality, and evidence readiness.
  • Evaluate effectiveness of product security activities including:
    • threat modeling,
    • secure coding practices,
    • SAST and static analysis,
    • SBOM and dependency management,
    • vulnerability scanning,
    • fuzzing and penetration testing,
    • compiler hardening and secure build configurations,
    • security validation evidence.
  • Help establish scalable assurance methodologies and minimum expectations appropriate to product risk and business objectives.

Adversarial Security Assessment
  • Partner with adversarial security engineering and product teams to evaluate realistic attack scenarios and challenge defensive assumptions.
  • Assess firmware attack surfaces and identify practical attack paths against embedded systems and storage products.
  • Translate security findings into durable engineering guidance and portfolio-wide lessons learned.

Security Incident & Vulnerability Feedback
  • Partner with PSIRT and product teams to identify recurring vulnerability patterns and systemic product security weaknesses.
  • Translate security incidents, vulnerability trends, and field learnings into improvements in secure development and security assurance practices.
  • Support risk assessment and remediation prioritization for significant product security issues.

Customer, Regulatory & Executive Security Assurance
  • Support customer-facing technical security inquiries, security assessments, and product assurance activities.
  • Provide technically grounded assessments to support customer security questionnaires, product evaluations, and audit activities.
  • Strengthen product readiness for evolving security expectations, regulatory obligations, and industry cybersecurity frameworks.
  • Support executive and product leadership in understanding product security posture and residual risk.

Cross-Functional Collaboration
  • Partner closely with:
    • Platform Security Architects,
    • Firmware Engineering,
    • ASIC and hardware teams,
    • Product Engineering,
    • Quality and Validation,
    • PSIRT,
    • Product Security Assurance,
    • External security assessment partners.
  • Drive outcomes through technical influence, collaboration, and pragmatic risk-based decision making.

Qualifications
Required:
  • Bachelor's, Master's, or PhD degree in Computer Science, Electrical Engineering, Computer Engineering, Cybersecurity, or a related technical field.
  • 10+ years of experience in firmware security, embedded systems security, product security, platform security, or related disciplines.
  • Strong expertise in firmware and embedded security concepts, including:
    • secure boot,
    • roots of trust,
    • authentication and authorization,
    • secure communications,
    • firmware update security,
    • cryptographic protections,
    • debug and manufacturing security controls,
    • secure provisioning and lifecycle security.
  • Strong understanding of attacker techniques, exploitability analysis, and adversarial thinking applied to embedded systems.
  • Experience evaluating threat models, security controls, and product security effectiveness.
  • Strong analytical and problem-solving skills with the ability to balance security rigor with business realities.
  • Excellent written and verbal communication skills with the ability to communicate effectively with engineering teams, vendors, product leadership, and executives.

Preferred:
  • Experience with SSD architectures, flash memory systems, storage controllers or embedded hardware platforms.
  • Experience with secure development lifecycle (SDL), vulnerability management, PSIRT, or product security assurance functions.
  • Familiarity with:
    • secure coding standards,
    • static analysis and security tooling,
    • fuzz testing,
    • penetration testing,
    • security certifications and regulatory expectations (e.g., FIPS, Common Criteria, CRA).
  • Experience working with external security research organizations or third-party product security assessments.
  • Strong technical depth in firmware and embedded system security.
  • Ability to challenge assumptions and assess security from an attacker perspective.
  • Strong documentation, analytical, and technical communication skills.
  • Ability to influence technical direction through collaboration and technical credibility.
  • Strong judgment in balancing product risk, customer commitments, and business priorities.

Additional Information
Sandisk is committed to providing equal opportunities to all applicants and employees and will not discriminate against any applicant or employee based on their race, color, ancestry, religion (including religious dress and grooming standards), sex (including pregnancy, childbirth or related medical conditions, breastfeeding or related medical conditions), gender (including a person's gender identity, gender expression, and gender-related appearance and behavior, whether or not stereotypically associated with the person's assigned sex at birth), age, national origin, sexual orientation, medical condition, marital status (including domestic partnership status), physical disability, mental disability, medical condition, genetic information, protected medical and family care leave, Civil Air Patrol status, military and veteran status, or other legally protected characteristics. We also prohibit harassment of any individual on any of the characteristics listed above. Our non-discrimination policy applies to all aspects of employment. We comply with the laws and regulations set forth in the "Know Your Rights: Workplace Discrimination is Illegal" poster. Our pay transparency policy is available here.
Sandisk thrives on the power and potential of diversity. As a global company, we believe the most effective way to embrace the diversity of our customers and communities is to mirror it from within. We believe the fusion of various perspectives results in the best outcomes for our employees, our company, our customers, and the world around us. We are committed to an inclusive environment where every individual can thrive through a sense of belonging, respect and contribution.
Sandisk is committed to offering opportunities to applicants with disabilities and ensuring all candidates can successfully navigate our careers website and our hiring process. Please contact us at jobs.accommodations@sandisk.com to advise us of your accommodation request. In your email, please include a description of the specific accommodation you are requesting as well as the job title and requisition number of the position for which you are applying.
Based on our experience, we anticipate that the application deadline will be 09/22/2026 (3 months from posting), although we reserve the right to close the application process sooner if we hire an applicant for this position before the application deadline. If we are not able to hire someone from this role before the application deadline, we will update this posting with a new anticipated application deadline.
#LI-KH1
Compensation & Benefits Details
  • An employee's pay position within the salary range may be based on several factors including but not limited to (1) relevant education; qualifications; certifications; and experience; (2) skills, ability, knowledge of the job; (3) performance, contribution and results; (4) geographic location; (5) shift; (6) internal and external equity; and (7) business and organizational needs.
  • The salary range is what we believe to be the range of possible compensation for this role at the time of this posting. We may ultimately pay more or less than the posted range and this range is only applicable for jobs to be performed in California, Colorado, New York or remote jobs that can be performed in California, Colorado and New York. This range may be modified in the future.
  • You will be eligible to participate in Sandisk's Short-Term Incentive (STI) Plan, which provides incentive awards based on Company and individual performance. Depending on your role and your performance, you may be eligible to participate in our annual Long-Term Incentive (LTI) program, which consists of restricted stock units (RSUs) or cash equivalents, pursuant to the terms of the LTI plan. Please note that not all roles are eligible to participate in the LTI program, and not all roles are eligible for equity under the LTI plan. RSU awards are also available to eligible new hires, subject to Sandisk's Standard Terms and Conditions for Restricted Stock Unit Awards.
  • We offer a comprehensive package of benefits including paid vacation time; paid sick leave; medical/dental/vision insurance; life, accident and disability insurance; tax-advantaged flexible spending and health savings accounts; employee assistance program; other voluntary benefit programs such as supplemental life and AD&D, legal plan, pet insurance, critical illness, accident and hospital indemnity; tuition reimbursement; transit; the Applause Program, employee stock purchase plan, and the Sandisk's Savings 401(k) Plan.
  • Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company's sole discretion unless and until paid and may be modified at the Company's sole discretion, consistent with the law.