IT Security Analyst

Corporate Imaging Concepts (CIC)

Northbrook (IL)

Hybrid

USD 95,000 - 110,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical, Dental, and Vision insurance
Life Insurance
Paid Time Off
401K Plan and Employer Discretionary M

Job summary

Corporate Imaging Concepts (CIC) is seeking an IT Security Analyst to own CIC's security posture, controls, and compliance. You will partner with the Infrastructure Manager and lead incident response, vendor risk assessments, and security tooling decisions in a hands-on role within a small IT team.

Responsibilities include managing MFA, endpoint and email security, and PCI-related obligations, while supporting day-to-day IT tasks.

Qualifications

  • 3-6 years of hands-on security experience in an analyst or engineer role.
  • Practical depth in Microsoft 365 / Entra ID security, endpoint protection, and email security.
  • Experience answering client security questionnaires or completing vendor risk assessments.
  • Working familiarity with PCI-DSS concepts; ecommerce/retail/SaaS environment a strong plus.
  • Strong judgment to operate as a one-person security function.
  • Generalist IT work experience including tickets and infrastructure tasks.
  • Certifications such as Security+, CySA+, SSCP are welcome; senior certs not required.

Responsibilities

  • Own day-to-day security posture, including identity and access controls (MFA, conditional access, privileged accounts).
  • Support endpoint protection, email security, and patching priorities with Infrastructure.
  • Monitor and triage alerts and advise on tooling growth.
  • Advise leadership on security risk in clear, prioritized terms and costs.
  • Own client-facing security compliance, including security questionnaires and vendor risk assessments.
  • Maintain practical security documentation and policies for CIC’s size.
  • Support PCI-related obligations with processing partners.
  • Run vendor security reviews for platforms and integrations.
  • Own incident response process including triage and post-incident follow-up.
  • Run security awareness activities and phishing simulations.

Skills

Microsoft 365 security
Entra ID security
Endpoint protection
Email security
PCI-DSS concepts
Vendor risk assessments
Security questionnaires
PowerShell
Python

Tools

PowerShell
Python
Azure security tooling
Microsoft 365 administration

Job description

Corporate Imaging Concepts (CIC) is a branded merchandise and e-commerce company headquartered in Northbrook, Illinois, with a full warehouse and operations facility in Alpharetta, Georgia. CIC builds and runs online storefronts and fulfillment programs for enterprise clients, which means the company manages payment flows, customer data, and the security expectations that come with serving large organizations.

About the Role

The IT Security Analyst owns security as a discipline for CIC, including security posture, compliance, vendor risk, and incident response. This is a hands-on individual contributor role with broad ownership and visible impact. The role partners closely with the Infrastructure Manager, who owns networks, servers, and endpoints as systems, while this position owns the security controls, policies, and compliance obligations that sit on top of them and the role would be reporting directly to IT leadership. CIC has a small IT team, so this role requires comfort with shared team responsibilities. Security is the primary mandate, but the IT Security Analyst should also expect to support ticket management and hands-on infrastructure support alongside the Infrastructure Manager. The right candidate values variety, pragmatism, and the opportunity to secure the full environment of a growing company without overbuilding an enterprise-scale security program.

Responsibilities
Security Posture & Controls
  • Own day-to-day security posture, including identity and access controls such as MFA, conditional access, and privileged accounts.
  • Support endpoint protection, email security, and patching priorities in partnership with Infrastructure.
  • Monitor and triage alerts using appropriately scaled tooling and recommend where tooling should or should not grow.
  • Advise leadership on security risk in clear, prioritized terms, including what matters now, what can wait, and what it costs.
  • Own client-facing security compliance, including security questionnaires and vendor risk assessments.
  • Maintain security documentation and policies that are practical, current, and appropriate for CIC’s size and environment.
  • Support payment cards, PCI-related obligations with CIC’s processing partners.
  • Run vendor security reviews for the platforms and integrations CIC relies on.
  • Own the incident response process, including first-line triage, coordination during events, and post-incident follow-through.
  • Run right-sized security awareness activities, including phishing simulation, onboarding training, and practical guidance people can follow.
Shared IT Team Responsibilities
  • Work on the support queue by triaging, resolving, and managing user support tickets as part of the IT team’s shared rotation.
  • Provide hands-on infrastructure support alongside the Infrastructure Manager, including endpoints, accounts, Microsoft 365 administration, and day-to-day systems work as needed.
Qualifications
  • 3-6 years of hands-on security experience in an analyst or engineer role, with recent personal experience deploying, tuning, and maintaining security controls.
  • Practical depth in Microsoft 365 / Entra ID security, endpoint protection, and email security.
  • Experience answering client security questionnaires or completing vendor risk assessments, including the ability to triage large, detailed assessments against deadlines.
  • Working familiarity with PCI-DSS concepts; experience in an e-commerce, retail, or SaaS environment is a strong plus.
  • Strong judgment to operate as a one-person security function, including prioritizing strategically, deferring accurately, and communicating clearly.
  • Genuine comfort with generalist IT work, including support tickets and infrastructure tasks.
  • Relevant certifications such as Security+, CySA+, or SSCP is welcome; senior certifications are not required.
Preferred Skills
  • MSP or small-team IT background with experience managing breadth, ticket discipline, and shifting priorities.
  • SOC 2 or similar attestation exposure, either client-side or audit-side.
  • Experience with Azure security tooling and scripting such as PowerShell or Python for automation.
  • Experience working alongside SAP or other ERP environments.
What This Role Is Not

This is not a management role with direct reports, a pure-security seat, or a SOC shift position. Part of the week will include support tickets and infrastructure work because CIC operates with a small IT team. The opportunity is to serve as the security function for a growing company with real ownership from day one and room for the role to grow as the business grows.

Why This Role Matters

The IT Security Analyst helps protect CIC’s people, clients, data, systems, and brand reputation. This role brings practical structure to security and compliance while staying grounded in the realities of a hands-on, fast-moving business.

Location and pay

Hybrid from our Northbrook, IL headquarters or our Alpharetta, GA warehouse and operations facility — regular onsite presence is part of the role, given the hands-on infrastructure and support responsibilities at both sites. Candidates should be within commuting distance of Northbrook or Alpharetta. Base salary range $95,000–$110,000 depending on experience, plus benefits.

  • Medical, Dental, and Vision insurance
  • Life Insurance
  • Paid Time Off
  • 401K Plan and Employer Discretionary Match
Equal Opportunity Statement

CIC is committed to diversity and inclusivity in the workplace.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Ecommerce Security & Compliance Analyst (Hybrid)
Ecommerce Security & Compliance Analyst (Hybrid)

Corporate Imaging Concepts (CIC) • Northbrook (IL)

Hybrid
USD 95,000 - 110,000
Medical, Dental, and Vision insurance
Life Insurance
Paid Time Off
+1
Cyber Security Engineering Lead
Cyber Security Engineering Lead

CACI • North Charleston (SC)

On-site
USD 86,000 - 180,000
IT Security Operations Analyst
IT Security Operations Analyst

Cognex Corporation • Natick (MA)

On-site
USD 110,000 - 140,000
Cyber Security Analyst
Cyber Security Analyst

CACI International Inc • Chantilly (VA)

On-site
USD 113,000 - 238,000
Cybersecurity Analyst, Security and AI Governance
Cybersecurity Analyst, Security and AI Governance

C.C.D. Cogent Communications Deutschland GmbH • Washington

On-site
USD 100,000 - 120,000
Health Insurance
Dental Insurance
Vision Insurance
+3
Cyber Security Engineer
Cyber Security Engineer

CACI International Inc • North Charleston (SC)

On-site
USD 72,000 - 150,000
Cyber Security Engineer
Cyber Security Engineer

CACI International Inc. • North Charleston (SC)

On-site
USD 72,000 - 150,000
Security Analyst
Security Analyst

Purity Technology LLC • Tomball (TX)

On-site
USD 55,000 - 75,000
Hybrid work schedule
Certification support
Competitive salary and benefits
INFORMATION SECURITY MANAGER
INFORMATION SECURITY MANAGER

Catalyst Acoustics Group • Columbus (OH)

Hybrid
USD 150,000 - 170,000
Cybersecurity Analyst, Security and AI Governance - Washington, DC
Cybersecurity Analyst, Security and AI Governance - Washington, DC

Cogent Communications • Washington

On-site
USD 100,000 - 120,000
Health Insurance
Dental Insurance
Vision Insurance
+2