R0119880 Cloud Info Security Analyst – Intermediate Level
USAA
- Location
- San Antonio Home Office I
- Work model
- On-Site
- Level
- Entry
- Posted
- Sep 16, 2026
Skills
About this role
Why USAA? At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military community and their families. Embrace a fulfilling career at USAA, where our core values – honesty, integrity, loyalty and service – define how we treat each other and our members. Be part of what truly makes us special and impactful. We are proud to support active-duty military spouses. USAA roles may offer remote or hybrid flexibility for active-duty military spouses consistent with applicable policy and business needs.
The Opportunity
Join the Cloud Incident Response team within USAA's Cyber Threat Operations Center (CTOC) and help protect one of the nation's leading financial services organizations from evolving cyber threats. In this role, you'll investigate and respond to security incidents across AWS, Azure, Google Cloud, and SaaS platforms while working with advanced security technologies in a large scale cloud environment. You'll collaborate with engineers, threat hunters, and security leaders to strengthen detection capabilities, enhance response processes, and help secure critical business services. We offer a flexible work environment that requires an individual to be in the office 4 days per week. This position can be based in one of the following locations: San Antonio, TX, Plano, TX, Phoenix, AZ, Charlotte, NC or Colorado Springs, CO. Relocation assistance is not available for this position.
What you'll do
Maintains awareness of the latest critical information security vulnerabilities, threats, and exploits. Independently investigates and responds to moderately complex security events, leveraging root cause analysis to identify threats, contain risk, and improve detection and response capabilities. Monitors internal and external networks, systems, and applications for security anomalies, suspicious activity, attacks, and potential security incidents while collaborating across teams to strengthen the organization's security posture. Respond to cyber incidents, performing moderately complex analysis using security tools. Builds a broad range of knowledge, understanding, and experience (e.g. forensics, networking, servers, coding, etc.) to determine a malicious actor's tactics, techniques, and procedures. Use the discoveries from the incident response process to make basic improvements to the existing detection capabilities and security controls. Documents findings of completed alerts and assists with incident documentation. Serves as a resource to team members on escalated issues of a routine nature. Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled in accordance with risk and compliance policies and procedures. What you have: Bachelor's degree; OR 4 years of relevant education and/or experience. 2 years of related experience in Information Security, Cybersecurity and/or Information Technology with a security focus to include accountability for moderately complex tasks and/or projects. 1 year of related experience in one of the following domains: Security and Risk Management, Asset Security, Security Architecture and Engineering, Communications and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, Software Development Security. Developing level of business acumen in the areas of business operations, risk management, industry practices and emerging trends. What sets you apart: Experience investigating cloud security incidents across AWS, Azure, GCP, and SaaS platforms. Strong understanding of IAM, cloud networking, logging, and cloud native services. Ability to analyze security events, determine root cause, and drive remediation efforts. Experience with SIEM, EDR, and cloud security tools such as CrowdStrike, Sentinel, Splunk, Elastic, Wiz, or Prisma Cloud. Knowledge of cloud threats