Identity Security Operations Analyst — Mobility Allowance

Pho Prime, LLC

Shelton (CT)

On-site

USD 70,000 - 100,000

Full time

44 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Mobility allowance

Job summary

Subway is seeking a Security Operations Analyst to manage identity security, access governance, and SOC practices. You will operate CrowdStrike Falcon Identity Protection, monitor identity threats, and support Okta governance with end-to-end access certifications.

You will join the IAM team to drive least-privilege, investigate anomalies, and contribute to PCI-DSS and cyber-insurance readiness. On-call rotation and incident response are involved.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field — or equivalent work experience.
  • 1–3 years in security operations, identity operations, a security operations center (SOC), or IT operations with significant identity or security scope.
  • Working knowledge of IAM fundamentals: authentication and MFA, SSO concepts, directory services, joiner/mover/leaver lifecycle, and least-privilege access.
  • Hands-on exposure to Okta or a comparable identity provider: user and group administration, MFA management, and basic application assignment; Okta strongly preferred.
  • Familiarity with SOC practices: alert triage, severity assessment, escalation paths, evidence handling, and incident documentation.
  • Exposure to a SIEM or security analytics platform — querying logs, investigating events, and reading detections; CrowdStrike Falcon Next-Gen SIEM a plus; willingness to develop CQL proficiency required.
  • Active Directory fundamentals (users, groups, OUs) and familiarity with Microsoft Entra ID and Microsoft 365 administration concepts.
  • Experience with an ITSM platform (ServiceNow preferred) in a ticket-driven operations environment.
  • Strong written documentation habits — investigations, evidence, and runbooks that others can follow and auditors can rely on.
  • Comfort using LLM and generative AI tools in day-to-day technical and analytical work.

Responsibilities

  • Operate identity threat detection and response with CrowdStrike Falcon Identity Protection: monitor and triage identity-based detections, assess risk and severity, apply risk-based policy actions within defined guardrails, and escalated confirmed threats to the Detect & Respond team; investigate access anomalies end to end using identity telemetry in CrowdStrike Falcon Next-Gen SIEM — authentication events, MFA activity, privileged-account usage, and provisioning changes.
  • Support tuning of identity detections, dashboards, and alert quality with the Detect & Respond team; participate in incident response for identity-related incidents including account compromise, credential abuse, and unauthorized access — executing containment actions such as session revocation, credential reset, and access suspension under team runbooks; monitor privileged and service-account activity for anomalous behavior and policy violations.
  • Run Okta Identity Governance access certification campaigns end to end: campaign setup and scoping, reviewer coordination and follow-up, revocation execution, exception tracking, and production of audit-ready evidence for PCI-DSS 4.0 and cyber-insurance programs; support access request workflow operations including approval-path exceptions and escalations outside self-service.
  • Apply least-privilege principles in daily work: flag over-broad group and role assignments, validate time-bound privileged access, and drive cleanup of dormant, orphaned, or over-privileged accounts; produce and maintain access evidence for internal and external audits and compliance programs.
  • Work down the standing identity-risk case backlog: investigate, prioritize, remediate, and close findings such as dormant accounts, stale privileged access, weak authentication paths, and unowned service accounts; track remediation against service-level targets and report progress and systemic patterns to Cybersecurity leadership.
  • Handle Tier-2/3 identity escalations remaining after automation — complex access requests, provisioning exceptions, and onboarding/offboarding edge cases; manage assigned tickets in ServiceNow meeting SLA targets; support access-related requests from investigations, legal holds, and HR partners with appropriate discretion and documentation; participate in the team's shared on-call rotation.
  • Author and maintain runbooks, triage guides, and knowledge-base articles for identity security operations and certification processes; track and report on identity-risk backlog burn-down, certification completion rates, and detection quality metrics; propose governance, detection, and automation improvements from observed patterns.

Skills

IAM fundamentals
Okta administration
SOC practices
SIEM & log analysis
ServiceNow
MFA management
Least privilege
Documentation
AI tooling
Windows & 365
PowerShell/Python

Education

Bachelor’s degree in CS/IT/Cybersecurity or related
Equivalent work experience

Tools

CrowdStrike Falcon Identity Protection
Okta
Okta Identity Governance
CrowdStrike Falcon Next-Gen SIEM
SailPoint
Saviynt
Omada
ServiceNow
PowerShell
Python

Job description

Subway is seeking a Security Operations Analyst to manage identity security, access governance, and SOC practices. You will operate CrowdStrike Falcon Identity Protection, monitor identity threats, and support Okta governance with end-to-end access certifications.

You will join the IAM team to drive least-privilege, investigate anomalies, and contribute to PCI-DSS and cyber-insurance readiness. On-call rotation and incident response are involved.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Identity Security Operations Analyst
Identity Security Operations Analyst

Subway • Shelton (CT)

On-site
USD 80,000 - 120,000
Insurance Plans (Medical Life)
Pension/401K/RSP
Competitive Bonus
+5
Security Operations Analyst
Security Operations Analyst

Pho Prime, LLC • Shelton (CT)

On-site
USD 70,000 - 100,000
Mobility allowance
Security Operations Analyst
Security Operations Analyst

Subway • Shelton (CT)

On-site
USD 80,000 - 120,000
Insurance Plans (Medical Life)
Pension/401K/RSP
Competitive Bonus
+5
Senior Identity Protection Specialist
Senior Identity Protection Specialist

Jobtailor • Morrisville (NC)

On-site
USD 140,000 - 190,000
Security Operations Analyst – SIEM & Cloud
Security Operations Analyst – SIEM & Cloud

Posh Technologies • United States

Remote
USD 75,000 - 120,000
Analyste Opérations Sécurité – IAM & Détection
Analyste Opérations Sécurité – IAM & Détection

Subway • Shelton (CT)

On-site
USD 90,000 - 120,000
Assurance maladie
Régime de retraite 401K/RSP
Bonus compétitif
+2
Sr. IAM Engineer
Sr. IAM Engineer

Pho Prime, LLC • Shelton (CT)

On-site
USD 120,000 - 170,000
Mobility Allowance
Cybersecurity Engineer
Cybersecurity Engineer

Growth For Impact • Los Angeles (CA), Northern (KY)

Hybrid
USD 120,000 - 150,000
Senior IAM Analyst — Access & Compliance
Senior IAM Analyst — Access & Compliance

CB&I • The Woodlands (TX)

On-site
USD 120,000 - 160,000
Mid Level SOC Operations Analyst with Security Clearance
Mid Level SOC Operations Analyst with Security Clearance

Cintel, Inc. • Huntsville (AL)

On-site
USD 75,000 - 95,000