Cybersecurity Analyst

Socket.dev

San Antonio (TX)

On-site

USD 85,000 - 120,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Santikos Corp is seeking a cybersecurity professional to support daily security operations at the San Antonio office. You will monitor alerts, investigate incidents, and coordinate remediation across on-premises and cloud environments.

The role emphasizes vulnerability management, access controls, and collaboration with IT and external partners to ensure PCI DSS and other compliance requirements are met.

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, or related field or equivalent experience.
  • 3+ years in cybersecurity, security operations, or related role.
  • Certifications like Security+, CySA+, or GIAC preferred.

Responsibilities

  • Monitor security alerts, logs, and telemetry across endpoints, identity, cloud, email, network, and apps.
  • Investigate suspicious activity and elevate incidents as appropriate.
  • Triage and analyze potential security incidents; document findings and support remediation.

Skills

Security monitoring
Incident response
Vulnerability management
Microsoft 365 security
Entra ID/Azure

Education

Bachelor's degree in Cybersecurity

Tools

Vulnerability scanners
Microsoft 365
Entra ID / Azure

Job description

Job Details:

Job Location: Santikos Corp Office - San Antonio, TX, Position Type: Full Time, Salary Range: Undisclosed,

OVERVIEW

Support the day-to-day operation of Santikos' cybersecurity program by monitoring security events, investigating alerts, managing vulnerabilities, supporting identity and access controls, and helping protect systems and data across corporate and theater environments. Play a hands-on role in protecting a multi-location organization while building broad cybersecurity experience across cloud, identity, endpoints, networks, business applications, incident response, vulnerability management, and enterprise security governance. Work closely with the CIO, IT Infrastructure & Operations Manager, Cloud/POS team, support staff, and external security partners to identify risk, coordinate remediation, support security incidents, and maintain evidence for security and compliance requirements.

ROLES & RESPONSIBILITIES
  • Monitor security alerts, logs, and telemetry from endpoint, identity, cloud, email, network, and other security platforms
  • investigate suspicious activity and elevate incidents as appropriate
  • Perform initial triage and analysis of potential security incidents, document findings, preserve relevant evidence, and support containment, remediation, recovery, and post-incident follow-up activities
  • Coordinate vulnerability management activities, including reviewing scan results, validating findings, prioritizing risk, assigning remediation actions, tracking progress, and verifying closure
  • Take ownership of assigned security findings from initial validation through remediation and closure, coordinating with system owners and vendors as needed rather than functioning solely as an alert-monitoring or escalation resource
  • Perform recurring reviews of user access, privileged accounts, administrative roles, service accounts, MFA, conditional access, and other identity controls in Microsoft 365, Entra ID, Azure, and related systems
  • Support privileged-access governance by helping ensure administrative access is appropriately assigned, reviewed, documented, and removed when no longer required
  • Assist with security configuration reviews and hardening efforts across endpoints, servers, cloud services, Microsoft 365, network devices, and business applications
  • Support phishing prevention and response, including investigation of suspicious messages, malicious links or attachments, compromised accounts, credential exposure, and user-reported security concerns
  • Assist with security awareness and training activities, including phishing simulations, employee communications, targeted education, and follow-up for identified risks
  • Maintain and improve security documentation, including incident records, procedures, standards, control evidence, risk items, remediation trackers, and technical security configurations
  • Support PCI DSS and other applicable security or compliance activities by gathering evidence, coordinating control-owner responses, tracking remediation items, and maintaining support documentation
  • Work with the IT Infrastructure & Operations Manager, Cloud/POS team, and support staff to ensure identified vulnerabilities, insecure configurations, and security findings are remediated within appropriate timeframes
  • Support endpoint, email, identity, cloud, network, and web-security technologies used by Santikos and coordinate technical escalations with vendors when specialized support is required
  • Assist with implementation and ongoing improvement of security controls, including endpoint protection, email security, web filtering, logging, monitoring, MFA, conditional access, privileged identity management, and related safeguards
  • Review security advisories, threat intelligence, vendor notices, and emerging vulnerabilities to determine potential impact to Santikos systems and recommend practical response actions
  • Support onboarding, role changes, and employee separations by validating access-control requirements and assisting with rapid revocation of privileged or sensitive access when needed
  • Assist with periodic testing and validation of security controls, including account reviews, vulnerability scans, recovery evidence, logging, alerting, and other operational security checks
  • Own the internal remediation lifecycle for findings identified through independent security assessments, vulnerability scans, audits, penetration testing, and other security reviews; coordinate responsible system owners, establish target dates, track remediation through completion, maintain closure evidence, and escalation overdue or unresolved risks to the CIO
  • Serve as the primary Santikos operational liaison for the independent cybersecurity assurance program and other external security assessments; provide requested evidence, respond to technical questions, coordinate internal owners, and support validation activities while preserving the independence of the assessor
  • Support cyber-insurance, audit, and risk-management requests by helping maintain accurate technical evidence and status information
  • Participate in security-related projects and technology initiatives to ensure appropriate controls are considered during planning, implementation, and change activities
  • Identify opportunities to automate security monitoring, evidence collection, reporting, and repetitive administrative tasks
  • Communicate security findings, risks, and recommended actions clearly to technical staff, business stakeholders, and leadership
  • Maintain confidentiality and use elevated or sensitive system access only for authorised business purposes and in accordance with Santikos policies
  • Perform other cybersecurity and technology-risk duties as assigned
Qualifications:
EDUCATION & EXPERIENCE REQUIREMENTS:

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related field preferred; equivalent combination of relevant education, technical training, certifications, and experience will be considered Minimum of 3 years of progressive experience in cybersecurity, information security, systems administration, network security, security operations, or a closely related technical role Relevant certifications, such as CompTIA Security+, CySA+, Microsoft Security certifications, GIAC, or equivalent industry certifications are preferred Demonstrated hands‑on experience investigating security alerts, suspicious activity, account compromise, malware, phishing, or other security events is required Experience supporting a multi-site or distributed environment is preferred

SKILLS, KNOWLEDGE & ABILITIES:
  • Knowledge of and experience with vulnerability scanning, vulnerability remediation, patching, configuration review, or related exposure-management processes
  • Demonstrated knowledge of and experience with Microsoft 365, Entra ID, Azure security controls, MFA, privileged-access concepts, Windows environments, identity and access management, and multi-factor authentication concepts
  • Ability to support security controls, audits, PCI DSS, NIST CPS, CIS Controls, or other cybersecurity frameworks or compliance requirements is preferred
  • Strong understanding of cybersecurity fundamentals including threats, vulnerabilities, risk, authentication, authorization, encryption, logging, and incident response
  • Ability to analyze security alerts and technical evidence across endpoint, identity, cloud, email, network, and application environments
  • Knowledge of and experience with vulnerability-management tools and the ability to interpret scan findings, assess practical risk, and coordinate remediation
  • Familiarity with endpoint detection and the and available data-analysis with scripting
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst
Cybersecurity Analyst

Santikos Entertainment • San Antonio (TX)

On-site
USD 70,000 - 100,000
IT Infrastructure & Operations Manager
IT Infrastructure & Operations Manager

Socket.dev • San Antonio (TX)

On-site
USD 120,000 - 160,000
IT Infrastructure & Operations Manager
IT Infrastructure & Operations Manager

Santikos Entertainment • San Antonio (TX)

On-site
USD 140,000 - 180,000
IT Security Specialist
IT Security Specialist

ibex • Palestine (TX)

On-site
USD 90,000 - 130,000
Cybersecurity Analyst: Incident Response & Risk Mitigation
Cybersecurity Analyst: Incident Response & Risk Mitigation

Santikos Entertainment • San Antonio (TX)

On-site
USD 70,000 - 100,000
Cybersecurity Analyst — Threat & Vulnerability Lead
Cybersecurity Analyst — Threat & Vulnerability Lead

Socket.dev • San Antonio (TX)

On-site
USD 85,000 - 120,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
Senior Administrator, Cybersecurity
Senior Administrator, Cybersecurity

FALL CREEK FARM & NURSERY • Charlotte (NC)

On-site
USD 110,000 - 160,000
Security Engineer
Security Engineer

Soteria, LLC • Charleston (SC)

Remote
USD 80,000 - 120,000
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000