The Security Analyst provides frontline monitoring, triage, and response coverage for the AGS security program, and carries out day-to-day execution of its governance, risk, and compliance program under the Senior IT Security Manager's direction. The role is the first set of eyes on security alerts and employee-reported threats, and separately drives day-to-day operation of the enterprise risk register — identifying and logging risks, working with control owners to propose scoring and treatment for management sign-off, and tracking approved treatment to a documented closure. The role also conducts control gap assessments against enterprise frameworks through documentation review and structured interviews with control and process owners, and coordinates with system, application, and business-unit owners to scope and verify the resulting remediations. This role suits a detail-oriented analyst comfortable moving between hands‑on alert triage and structured GRC work, who can produce clear written reporting for both technical and business audiences. The role partners with IT operations, Legal, Compliance, HR, and Business Units.
Responsibilities
- Monitor security tooling, dashboards, and alert queues for indicators of malicious activity or policy violation.
- Perform initial triage on security alerts to determine validity, severity, and scope, and document findings clearly.
- Provide first‑tier response to active security events following established playbooks, and elevate to senior staff with a complete summary of findings.
- Review and respond to employee‑reported phishing and suspicious email, including header, URL, and attachment analysis, and take protective action where threats are confirmed.
- Manage email quarantine review and support email threat response activities.
- Maintain accurate records of security events, actions taken, and resolution in the enterprise ticketing system.
- Coordinate and support recurring user access and entitlement reviews with system and data owners; track completion, exceptions, and remediation of dormant or excessive access.
- Review third‑party and vendor security documentation, including security questionnaires, attestations, and independent audit reports, and summarize findings to support risk decisions.
- Drive day‑to‑day operation of the enterprise risk register: log new risks surfaced through assessments, audits, incidents, and vendor reviews; work with risk and control owners to propose scoring, prioritization, and treatment for the Senior IT Security Manager's approval; and track approved treatment plans to a documented, evidenced closure.
- Conduct control gap assessments against enterprise frameworks (NIST CSF, CIS Controls, ISO 27001) through control documentation review and structured interviews with control and process owners; document gaps, supporting evidence, and recommended remediation.
- Coordinate with system, application, and business‑unit owners to scope, sequence, and verify implementation of control remediations identified through assessments, audits, or the risk register, tracking each from assignment through evidenced closure.
- Support internal and external audit, certification, and regulatory assessment activities through evidence collection, request tracking, and response coordination.
- Present risk register and control assessment status to the Senior IT Security Manager on a recurring cadence — including proposed risk scoring and treatment awaiting sign‑off — and flag aging risks or stalled remediation for escalation.
- Assist with vulnerability scan reporting and track remediation completion by system owners.
- Produce recurring written updates summarizing security activity, alert trends, and notable events in the environment.
- Contribute to security metrics and reporting used by security leadership and management stakeholders.
- Support security awareness activities, including training campaign coordination and simulated phishing exercises.
- Participate in tabletop exercises and post‑incident reviews.
- Occasional travel throughout the United States.
Skills/Requirements
- Security monitoring and alert triage using SIEM and endpoint detection and response tooling.
- Phishing and email threat analysis, including header, URL, and attachment inspection.
- Incident response fundamentals and playbook execution, with clear escalation practice.
- User access and entitlement review coordination, including least privilege and separation of duties concepts.
- Third‑party and vendor risk review, including security questionnaires and independent audit reports.
- Risk register facilitation, including risk identification, proposing scoring and treatment plans for management sign‑off, and owner follow‑up through closure.
- Control gap assessment methodology, including control‑owner interviews, evidence review, and gap documentation against a control framework.
- Cross‑functional coordination to scope and verify control remediation with system, application, and business owners.
- Audit and certification support, including evidence collection and request tracking.
- Working understanding of common attack techniques, including phishing, credential compromise, and malware delivery.
- Strong written communication, documentation, and recurring reporting skills.
- Familiarity with industry frameworks (NIST CSF, CIS Controls, ISO 27001, PCI DSS).
- Bachelor's Degree in Information Security, Information Technology, or a related field, or equivalent work experience.
- At least 2 years of experience in a security analyst, security operations, governance and risk, or IT operations role.
- Practical familiarity with security monitoring tooling such as SIEM and EDR/XDR, and with enterprise ticketing systems.
- Experience performing alert triage and documenting investigative findings for escalation.
- Experience supporting recurring compliance or review cycles through to completion.
- Demonstrated experience conducting or directly supporting control assessments — walkthroughs, interviews, or audits — that produced a documented set of findings.
- High attention to detail and the discipline to carry recurring review cycles through to completion without prompting.
- Ability to produce clear written reporting for both technical and non‑technical audiences.
- Prior experience in a regulated industry preferred.
- Relevant technical certifications required or strongly preferred: CompTIA Security+, CySA+, SSCP, or equivalent.
Preferred Certification
- Professional technical certifications such as CompTIA Security+, CySA+, CEH, SSCP, or equivalent. Platform‑specific certifications are considered supplemental to demonstrated hands‑on capability. A GRC‑oriented credential such as CRISC or an ISO 27001 Internal Auditor certification is a plus alongside the technical certifications above.
Note: All offers are contingent upon successful completion of a background check
*Posted positions are not open to third party recruiters and unsolicited resume submissions will be considered free referrals.