IT Security Engineer

Trek

Town of Waterloo (NY)

Hybrid

USD 125,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible and fun culture
Competitive health care
401(k) with match and ESOP
12 weeks maternity leave with 100% pay
Employee discounts on all product
Deep partner retail discounts

Job summary

Trek Waterloo HQ is seeking an Information Security Engineer to own IAM and SOC operations in a hybrid role. You will manage identity infrastructure (Microsoft Entra ID, JML, PAM) and serve as Trek’s primary security analyst across CrowdStrike Falcon, Sentinel, and Zscaler.

Join a global security team, collaborate with IT/HR/Legal, and drive threat detection, incident response, and governance for a world-leading bike brand. Innovative AI tools will augment your security workflows.

Qualifications

  • 5+ years’ hands-on IT or information security experience with IAM and SOC ownership.
  • Hands-on experience with Microsoft Entra ID / Azure AD, SSO, MFA, and CA.
  • Strong understanding of RBAC, least privilege, PAM, JML and audits.
  • Experience with CrowdStrike Falcon, Microsoft Sentinel, and Zscaler.
  • Ability to own incident response end-to-end and communicate with stakeholders.

Responsibilities

  • Own IAM program lifecycle: governance, RBAC, joiner-mover-leaver, access certification, policy enforcement.
  • Administer and optimize Entra ID including SSO, MFA, CA, and directory health.
  • Design least-privilege access model across SaaS, cloud, on-premises; manage PAM.
  • Drive access certification campaigns across systems; report outcomes.
  • Develop IAM policies and third-party/service account governance; ensure automation.
  • Detect and investigate identity-based threats and anomalous activity.
  • Partner with HR/IT/app teams to ensure accurate, automated processes.
  • Support audit/compliance with identity evidence and access control docs.
  • Monitor security alerts across CrowdStrike, Sentinel, and Zscaler; triage and respond.
  • Own incident response lifecycle from detection to post-incident review.
  • Develop and tune detection rules; build/run playbooks and runbooks.
  • Integrate IAM data into SOC detection workflows; collaborate across Trek.
  • Threat hunt using telemetry to identify attacker activity; reduce noise.

Skills

Identity & Access Management
SOC Operations
Azure AD / Entra ID
RBAC / Least Privilege
PAM
Threat Hunting
Incident Response
SIEM & EDR
AI in Security

Education

Bachelor’s degree in Computer Science / related field

Tools

CrowdStrike Falcon
Microsoft Sentinel
Zscaler
Azure AD / Entra ID

Job description

A bit about us

Trek is an awesome place to work, with amazing benefits for all employees. We build only products we love, provide incredible hospitality to our customers, and change the world by getting more people on bikes. When you’re on our team, you’re taken care of, encouraged to learn and grow, and given lots of opportunities to do so. Give us your best, and we’ll give it right back. Sound pretty sweet? Then come join us!

Job Description

Location: Trek Waterloo HQ (Hybrid)

Role Summary

Help us secure the Awesome Bus! We are looking for someone to join our global cybersecurity team. We are a highly effective team that works to protect and defend against intrusions into Trek’s systems.

The Information Security Engineer owns two of the security program’s most operationally critical functions: Identity & Access Management (IAM) and Security Operations (SOC). This is a senior individual contributor role — you won’t manage people, but you will own the technical controls that govern who can access Trek’s systems and how threats against those systems are detected and contained.

You will be the hands‑on owner of Trek’s identity infrastructure — Microsoft Entra ID, privileged access, joiner‑mover‑leaver processes, and access governance — while simultaneously operating as Trek’s primary security analyst: monitoring for threats, investigating incidents, and running detection and response workflows across CrowdStrike Falcon, Zscaler, and Microsoft Sentinel. This role demands both the precision of an IAM engineer and the instincts of a SOC analyst. You will work closely with the Director of IT Security and collaborate cross‑functionally with IT, HR, Legal, and engineering teams across Trek’s global environment.

If you want a role where no two days are the same, where you own real enterprise security infrastructure, and where the work you do directly protects a globally recognized brand — this is it.

Key Responsibilities

Identity & Access Management

  • Own the IAM program lifecycle: identity governance, role‑based access control (RBAC), access certification, joiner‑mover‑leaver (JML) processes, and policy enforcement
  • Administer and optimize Microsoft Entra ID (Azure AD) including SSO, MFA, Conditional Access policies, and directory health
  • Design and maintain a least‑privilege access model across SaaS, cloud, and on‑premises systems, including privileged access management (PAM)
  • Drive access certification campaigns: scope, execute, and report on periodic entitlement reviews across all systems
  • Develop and enforce IAM policies, standards, and procedures — including third‑party and service account governance
  • Detect and investigate identity‑based threats: anomalous authentication, lateral movement indicators, credential abuse, and over‑privileged account activity
  • Partner with HR, IT, and application teams to ensure processes are accurate, automated where possible, and consistently enforced
  • Support audit and compliance activities with identity evidence and access control documentation

Security Operations

  • Serve as Trek’s primary security analyst: monitor alerts across CrowdStrike Falcon, Microsoft Sentinel, and Zscaler; triage, investigate, and expedite as warranted
  • Own the incident response lifecycle for security events — from initial detection through containment, eradication, recovery, and post‑incident review
  • Develop, tune, and maintain detection rules and correlation logic across SIEM and EDR platforms to reduce noise and surface high‑confidence detections
  • Build and maintain incident response playbooks, investigation runbooks, and post‑incident documentation
  • Integrate identity signals and IAM data into SOC detection workflows — connecting the IAM and SOC functions into a unified threat detection capability
  • Conduct threat hunting using CrowdStrike, Sentinel, and Zscaler telemetry to proactively identify attacker activity that evades automated detection
  • Orchestrate and automate security operations workflows to improve speed and consistency across the security team
  • Evangelize information security practices within Trek worldwide
  • Perform other duties as assigned
Leveraging AI

At Trek we view artificial intelligence as a competitive advantage and a personnel multiplier, not a replacement for human expertise or judgment. Our Security team is expected to actively leverare AU tools to increase efficiency and sharpen analysis. Specific AI released tasks will include:

  • Using AI to analyze access patterns and entitlement data at scale — identifying over‑provisioning, dormant accounts, anomalous permission combinations, and least‑privilege violations across large user populations
  • Applying AI to accelerate alert triage, reduce noise, and surface high‑confidence detections across SIEM and EDR platforms
  • Leveraging AI to enrich threat intelligence, correlate indicators of compromise (IOCs), and contextualize threats against Trek’s environment
  • Using AI to draft and refine IAM policies, role definitions, access request templates, incident response playbooks, and governance documentation
  • Employing AI coding assistants to automate JML workflows, build security integrations, and maintain detection and reporting pipelines
  • Continuously evaluating new AI‑driven security capabilities and recommending adoption where they meaningfully reduce risk or analyst toil
Required Qualifications
  • 5+ years’ experience in IT or information security, with demonstrable hands‑on ownership across both IAM and security operations functions
  • Deep hands‑on experience with Microsoft Entra ID (Azure AD) including SSO, MFA, Conditional Access, and directory operations
  • Strong understanding of IAM concepts: RBAC, least privilege, PAM, JML processes, access certification, and federated identity
  • Experience with endpoint detection and response (EDR) platforms — CrowdStrike Falcon strongly preferred
  • Experience with SIEM platforms for alert monitoring, investigation, and detection rule management — Microsoft Sentinel preferred
  • Experience with network security monitoring and proxy platforms — Zscaler ZIA/ZPA preferred
  • Demonstrated ability to own incident response end‑to‑end: triage, investigation, containment, eradication, and documentation
  • Strong understanding of Windows and *nix systems, network architecture and protocols (TCP/IP, DNS, HTTPS), and cloud technologies
  • Demonstrated ability to incorporate AI tools into security workflows — not just awareness of them
  • Excellent written and verbal communication skills — able to explain identity risk and security incidents to non‑technical stakeholders
  • Holds or is actively pursuing relevant certification: (ISC)² CISSP/CCSP/SSCP; SANS GIAC GCIH/GCIA/GCFA; Microsoft SC-300; CompTIA Security+; or equivalent
Preferred Qualifications
  • Experience with privileged access management platforms (CyberArk, BeyondTrust, Admin by Request, or similar)
  • Scripting experience — PowerShell or Python — for automating identity workflows, detection pipelines, and security integrations
  • Experience with physical security systems (access control, CCTV) as a secondary function
  • Experience supporting compliance frameworks — PCI DSS, ISO 27001, SOC 2, or similar — with technical evidence and control documentation
  • Experience with threat hunting methodologies and hypothesis‑driven investigation
  • Bachelor’s degree in Computer Science, Information Security, MIS, or equivalent experience

Trek Benefits:

  • Flexible and fun company culture
  • Competitive health care
  • PPO & HDHP medical plan options, Dental insurance, Vision insurance
  • Flexible Spending Accounts (FSA)
  • Free life insurance & optional term life insurance
  • Competitive vacation package
  • 401(k) with match and Employee Stock Ownership Plans (ESOP)
  • 12 weeks of maternity leave with 100% pay
  • Flexible holiday schedule – 10 company holidays
  • Tuition Reimbursement up to $15,000! (Undergraduate & Masters programs)
  • Employee discounts on all product
  • Deep partner retail discounts

We are an Equal Employment Opportunity (“EEO”) Employer. Trek strictly prohibits discrimination on the basis of race, color, creed, religion, gender, gender identity, pregnancy, marital status, partnership status, sexual orientation, age, national origin, veteran or military status, disability, medical condition, genetic information, or any other characteristic prohibited by federal, state and/or local laws. This policy applies to all aspects of employment, including hiring, promotion, demotion, compensation, training, working conditions, transfer, job assignments, benefits, layoff, and termination.

We are an E-Verify employer.

For more information, please click on the following links:
E-Verify Participation Poster: English / Spanish
E-Verify Right to Work Poster: English | Spanish

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Engineer
IT Security Engineer

Trek Bicycle • Town of Waterloo (WI)

Hybrid
USD 120,000 - 180,000
Flexible and fun company culture
Competitive health care
401(k) with match
+1
IT Security Engineer
IT Security Engineer

Trek Bicycle Corporation • Wisconsin

Hybrid
USD 110,000 - 140,000
Flexible and fun company culture
Competitive health care
PPO & HDHP medical plans
+9
IT Security Engineer
IT Security Engineer

Trek Bicycle • Waterloo (IL)

Hybrid
USD 120,000 - 180,000
Flexible vacation policy
Competitive health care (PPO & HDHP)
Dental insurance
+6
Senior IAM & SOC Security Engineer
Senior IAM & SOC Security Engineer

Trek • Town of Waterloo (NY)

Hybrid
USD 125,000 - 180,000
Flexible and fun culture
Competitive health care
401(k) with match and ESOP
+3
Senior IAM & SOC Security Engineer (Hybrid)
Senior IAM & SOC Security Engineer (Hybrid)

Trek Bicycle • Town of Waterloo (WI)

Hybrid
USD 120,000 - 180,000
Flexible and fun company culture
Competitive health care
401(k) with match
+1
Mechanical Engineer - Interconnected Products Team
Mechanical Engineer - Interconnected Products Team

trekbikes • Town of Waterloo (WI)

On-site
USD 85,000 - 110,000
Health insurance
401(k) with match
Maternity leave (12 weeks)
+1
ERP Developer lll
ERP Developer lll

Trek Bikes • Northern (KY)

Hybrid
USD 110,000 - 140,000
Flexible and fun culture
Competitive health care
PPO & HDHP medical plans
+6
Mechanical Engineer - Interconnected Products Team
Mechanical Engineer - Interconnected Products Team

Trek Bicycle • Waterloo (IL)

On-site
USD 90,000 - 130,000
Flexible and fun culture
Competitive health care
ESOP
P1 Assembly Technician Level 2
P1 Assembly Technician Level 2

Trek Bicycle • Town of Waterloo (WI)

On-site
USD 42,000 - 54,000
Health insurance
401(k) with match
Life insurance
+1
Seasonal PT Advisor
Seasonal PT Advisor

Trek Bicycle • Town of Florida (NY)

On-site
USD 40,000 - 65,000
Flexible culture
401(k) match
Employee discounts
+1