Security Analyst

Koitecc Solutions

Duluth (GA)

On-site

USD 70,000 - 95,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Koitecc Solutions is seeking a detail‑oriented Security Analyst to monitor security tooling, triage alerts, and respond to incidents under the guidance of the Senior IT Security Manager.

The role also drives risk and compliance activities, including risk register management, control gap assessments, and vendor risk reviews, with cross‑functional collaboration across IT, Legal, Compliance, HR, and business units.

Qualifications

  • Bachelor's Degree in Information Security, Information Technology, or related field.
  • At least 2 years in security analyst or related roles.
  • Experience with SIEM and EDR/XDR tools.
  • Familiarity with NIST CSF, CIS Controls, ISO 27001, PCI DSS.
  • Strong written communication and reporting skills.
  • Experience performing alert triage and escalation.

Responsibilities

  • Monitor security tooling and alert queues for malicious activity.
  • Perform initial triage to determine severity and scope.
  • Provide first-tier response following playbooks.
  • Review phishing emails and take protective action.
  • Maintain enterprise security records in ticketing systems.
  • Coordinate access reviews with system owners.
  • Support audit, certification, and regulatory activities.
  • Present risk status to Senior IT Security Manager.
  • Assist with vulnerability remediation tracking.
  • Travel as needed to sites across the United States.

Skills

Security monitoring
Phishing analysis
Incident response
Access reviews
Vendor risk review
Risk management
Control assessments
Audit support
Security reporting
Tabletop exercises
Regulatory knowledge
Excellent writing

Education

Bachelor's Degree in Information Security/IT or related field

Tools

SIEM
EDR/XDR tooling
Ticketing system (ServiceNow)

Job description

Position Title: Security Analyst

Job Overview

The Security Analyst provides frontline monitoring, triage, and response coverage for the AGS security program, and carries out day‑to‑day execution of its governance, risk, and compliance program under the Senior IT Security Manager's direction. The role is the first set of eyes on security alerts and employee‑reported threats, and separately drives day‑to‑day operation of the enterprise risk register identifying and logging risks, working with control owners to propose scoring and treatment for management sign‑off, and tracking approved treatment to a documented closure. The role also conducts control gap assessments against enterprise frameworks through documentation review and structured interviews with control and process owners, and coordinates with system, application, and business‑unit owners to scope and verify the resulting remediations. This role suits a detail‑oriented analyst comfortable moving between hands‑on alert triage and structured GRC work, who can produce clear written reporting for both technical and business audiences. The role partners with IT operations, Legal, Compliance, HR, and Business Units.

Responsibilities
  • Monitor security tooling, dashboards, and alert queues for indicators of malicious activity or policy violation.
  • Perform initial triage on security alerts to determine validity, severity, and scope, and document findings clearly.
  • Provide first‑tier response to active security events following established playbooks, and elevate to senior staff with a complete summary of findings.
  • Review and respond to employee‑reported phishing and suspicious email, including header, URL, and attachment analysis, and take protective action where threats are confirmed.
  • Manage email quarantine review and support email threat response activities.
  • Maintain accurate records of security events, actions taken, and resolution in the enterprise ticketing system.
  • Coordinate and support recurring user access and entitlement reviews with system and data owners; track completion, exceptions, and remediation of dormant or excessive access.
  • Review third‑party and vendor security documentation, including security questionnaires, attestations, and independent audit reports, and summarize findings to support risk decisions.
  • Drive day‑to‑day operation of the enterprise risk register: log new risks surfaced through assessments, audits, incidents, and vendor reviews; work with risk and control owners to propose scoring, prioritization, and treatment for the Senior IT Security Manager's approval; and track approved treatment plans to a documented, evidenced closure.
  • Conduct control gap assessments against enterprise frameworks (NIST CSF, CIS Controls, ISO 27001) through control documentation review and structured interviews with control and process owners; document gaps, supporting evidence, and recommended remediation.
  • Coordinate with system, application, and business‑unit owners to scope, sequence, and verify implementation of control remediations identified through assessments, audits, or the risk register, tracking each from assignment through evidenced closure.
  • Support internal and external audit, certification, and regulatory assessment activities through evidence collection, request tracking, and response coordination.
  • Present risk register and control assessment status to the Senior IT Security Manager on a recurring cadence including proposed risk scoring and treatment awaiting sign‑off and flag aging risks or stalled remediation for escalation.
  • Assist with vulnerability scan reporting and track remediation completion by system owners.
  • Produce recurring written updates summarizing security activity, alert trends, and notable events in the environment.
  • Contribute to security metrics and reporting used by security leadership and management stakeholders.
  • Support security awareness activities, including training campaign coordination and simulated phishing exercises.
  • Participate in tabletop exercises and post‑incident reviews.
  • Occasional travel throughout the United States.
Skills/Requirements
  • Security monitoring and alert triage using SIEM and endpoint detection and response tooling.
  • Phishing and email threat analysis, including header, URL, and attachment inspection.
  • Incident response fundamentals and playbook execution, with clear escalation practice.
  • User access and entitlement review coordination, including least privilege and separation of duties concepts.
  • Third‑party and vendor risk review, including security questionnaires and independent audit reports.
  • Risk register facilitation, including risk identification, proposing scoring and treatment plans for management sign‑off, and owner follow‑up through closure.
  • Control gap assessment methodology, including control‑owner interviews, evidence review, and gap documentation against a control framework.
  • Cross‑functional coordination to scope and verify control remediation with system, application, and business owners.
  • Audit and certification support, including evidence collection and request tracking.
  • Working understanding of common attack techniques, including phishing, credential compromise, and malware delivery.
  • Strong written communication, documentation, and recurring reporting skills.
  • Familiarity with industry frameworks (NIST CSF, CIS Controls, ISO 27001, PCI DSS).
  • Bachelor's Degree in Information Security, Information Technology, or a related field, or equivalent work experience.
  • At least 2 years of experience in a security analyst, security operations, governance and risk, or IT operations role.
  • Practical familiarity with security monitoring tooling such as SIEM and EDR/XDR, and with enterprise ticketing systems.
  • Experience performing alert triage and documenting investigative findings for escalation.
  • Experience supporting recurring compliance or review cycles through to completion.
  • Demonstrated experience conducting or directly supporting control assessments walkthroughs, interviews, or audits that produced a documented set of findings.
  • High attention to detail and the discipline to carry recurring review cycles through to completion without prompting.
  • Ability to produce clear written reporting for both technical and non‑technical audiences.
  • Prior experience in a regulated industry preferred.
  • Relevant technical certifications required or strongly preferred: CompTIA Security+, CySA+, SSCP, or equivalent.
Preferred Certification
  • Professional technical certifications such as CompTIA Security+, CySA+, CEH, SSCP, or equivalent. Platform‑specific certifications are considered supplemental to demonstrated hands‑on capability. A GRC‑oriented credential such as CRISC or an ISO 27001 Internal Auditor certification is a plus alongside the technical certifications above.

Note: All offers are contingent upon successful completion of a background check

AGS is an equal opportunity employer

Equal Opportunity Employer, including disability/protected veterans

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Analyst
Security Analyst

Talentify • Duluth (GA)

On-site
USD 85,000 - 110,000
Security Analyst
Security Analyst

AGS - American Gaming Systems • Las Vegas (NV)

On-site
USD 90,000 - 120,000
Security Analyst
Security Analyst

Koitecc Solutions • Atlanta (GA), Northern (KY)

Hybrid
USD 90,000 - 125,000
Senior Security Engineer
Senior Security Engineer

Talentify • Duluth (GA)

On-site
USD 120,000 - 180,000
Senior Security Engineer
Senior Security Engineer

AGS - American Gaming Systems • Atlanta (GA)

On-site
USD 120,000 - 180,000
Security Analyst
Security Analyst

Jobvite, Inc. • Duluth (GA)

Hybrid
USD 70,000 - 110,000
Security Engineer
Security Engineer

Talentify • Duluth (GA)

On-site
USD 110,000 - 140,000
Security Operations & GRC Analyst
Security Operations & GRC Analyst

Talentify • Duluth (GA)

On-site
USD 85,000 - 110,000
Security Engineer
Security Engineer

AGS - American Gaming Systems • Atlanta (GA)

On-site
USD 100,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Koitecc Solutions • Duluth (GA)

On-site
USD 120,000 - 180,000