- Location
- United States
- Workplace
- Remote
- Employment
- Full time
- Level
- Mid level
- Posted
- 3 weeks ago
About this role
Description
Zafran is actively looking for an experienced Cyber Security Analyst to join the Sales Engineering organization at our dynamic cybersecurity startup. We are looking for an individual who thrives on unraveling the intricacies of computing environments and attackers' techniques, and who turns that understanding into tooling, data, and evidence our customers can act on. This role sits with the field rather than in R&D: you will research live customer and partner environments for risk, own threat intelligence for the go-to-market team, and build the tooling that makes every evaluation faster.
About Zafran:
Our Mission: To stop the exploitation of vulnerabilities, everywhere.
What makes us different: In a world where AI-enabled attackers weaponize vulnerabilities within minutes, the old scan-and-patch-everything model no longer holds. Zafran's Exposure Graph continuously maps every vulnerability across your hybrid environment, chains exploitability through real attack paths and proves 90% of "critical" vulnerabilities can't actually reach you. It then neutralizes the real 10% using your compensating controls and safely remediates only where it matters.
Who’s behind us: Zafran is backed by Menlo Ventures, Sequoia Capital, Cyberstarts, and a deep belief that cybersecurity should move as fast as attackers do. We’re one of the fastest-growing companies in the industry, scaling to meet demand from the world’s most advanced, security-obsessed organizations.
What you will do:
Build and maintain the tooling the field runs on - scripts, automations, and data utilities that shorten POV setup and remove manual work from the Sales Engineering team.
Partner with Sales Engineers to stand up Proofs of Value: tenant configuration, integration scoping, data validation, and instrumentation of success criteria.
Bring in customer data. Connect the customer's existing security stack, validate coverage and data quality, and resolve the ingestion issues that quietly stall evaluations.
Research customer and partner environments for risk. Analyze vulnerability posture, deployed security controls, and exposure paths to separate what is genuinely exploitable from what is already mitigated by controls the customer already owns.
Own threat intelligence for the go-to-market organization. Track emerging CVEs and active exploitation campaigns, drive rapid response when something breaks in the news, and arm the field with a credible answer within hours.
Present findings directly to customer security teams, and back up Sales Engineers when a conversation needs research depth.
Collaborate with Product, R&D, and Research - feeding field findings, data gaps, and detection misses back with the specifics needed to act on them, and validating new mitigation logic against real customer data.
Requirements:
3+ years of experience in cybersecurity, with a proven track record in research analysis, threat intelligence, threat detection engineering, or threat hunting.
Ability to collect, process, analyze, and interpret large and imperfect datasets to derive actionable insights, and to reach a conclusion you can defend under challenge.
Proficiency in programming/scripting languages, with a default instinct to automate a repetitive problem rather than repeat it.
Working knowledge of enterprise security controls - EDR, NGFW, WAF, CNAPP and cloud security, vulnerability scanners - and how each one actually mitigates risk in practice.
Experience with network/security-related data analysis.
Proficiency in SQL and TCP/IP network fundamentals.
Comfort working directly with customers. You can hold technical ground with a skeptical security team and explain a finding clearly instead of hiding behind jargon.
Strong team player with excellent collaboration skills, and experience managing multi-departmental interactions with cybersecurity professionals, engineering teams, and product managers.
Self-directed, low-ego, and comfortable with ambiguity and the pace of a fast-growing startup.
Experience with the following is a plus:
Extensive experience in GO/Python programming languages
Pre-sales, professional services, or another customer-facing technical role
Building internal tooling or automation for a field or go-to-market team
Agentic and LLM-based workflows, and MCP-style integrations
Prior experience at an early-stage security startup
At Zafran, people matter! We provide a robust benefits program that includes flexible PTO, health insurance plans (medical, dental, vision), a monthly stipend for phone and internet, 401k, flexible spending account, and a home office stipend when joining!
We also provide access to frontier AI models, including Claude, so every employee can work smarter, move faster, and build an AI-first career from day one.
At Zafran, we’re proud to be an equal opportunity employer. We believe the best teams are built by people who think differently, come from all kinds of backgrounds, and aren’t afraid to challenge the status quo. We welcome everyone across race, religion, gender, gender identity or expression, sexual orientation, age, disability, national origin, and veteran status, because what matters most is what you bring to the table.
If you’re curious, fun, and someone who gets things done, we’d love to meet you
As published by Zafran Security. Applications are handled on their site.
Skills this posting mentions
About Zafran Security
Zafran is an AI-native exposure management platform that eliminates the manual toil of vulnerability management by cutting through noise, revealing what is truly exploitable, and automating mitigation and remediation using the security controls teams already have. We are a team of practitioners and builders shaped by high-stakes security moments, where clarity and speed mattered, and manual processes came at a real cost. We’re on a mission to proactively stop the exploitation of vulnerabilities, everywhere.
All 31 openings at Zafran SecurityOne click, then it is written
Apply to Zafran Security with a resume written for this role.
Queue Cyber Security Analyst, Sales Engineering and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Zafran Security’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at Zafran Security
See all- Today
- Yesterday
- Last week
- 2 weeks ago
- 2 weeks ago
- 3 weeks ago
Similar roles elsewhere
See more- Today
Regional Account Executive, Washington & Oregon
FlaiUnited StatesRemote
$150k - $250k/yrMid levelSales - Today
- Yesterday
Delivery Solutions Architect - Digital Native Business
DatabricksUnited StatesRemote
$180k - $248k/yrSales
Put this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board Zafran Security publishes. Refolk is not the employer and does not handle their hiring. Applications go to Zafran Security directly.