Security Operations Administrator

MetroSys, Inc.

United States

Remote

USD 55,000 - 83,000

Part time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

MetroSys, Inc. seeks a dependable Security Operations Administrator for a short-term contract to support security monitoring and response.

You will review, triage, document, and respond to alerts across client platforms, coordinating with help desk and infrastructure teams as needed. The ideal candidate has hands-on experience with endpoint and email security, identity-related alerts, and incident response workflows, and can work independently within a 24/7 alerting environment with a daily

Qualifications

  • 3+ years of experience in security administration, SOC operations, or security incident response.
  • Hands-on experience with Mimecast, KnowBe4 / phishing remediation workflows, Sophos EDR/XDR and Intercept X.
  • Understanding of security incident response workflows, endpoint and network security concepts, identity and access management fundamentals.
  • Experience reviewing and analyzing security alerts and event data.
  • Strong documentation and communication skills.
  • Ability to work independently and manage daily operational responsibilities efficiently.

Responsibilities

  • Review and respond to security alerts and tickets generated from the client’s monitoring and security platforms.
  • Investigate and triage alerts related to endpoint security events, email threats, phishing activity, suspicious authentication attempts, and firewall/network security events.
  • Perform incident response activities including documentation, initial remediation actions, escalation, coordination, and post-mortem reporting.
  • Validate email and phishing-related incidents using Mimecast and KnowBe4 / PhishER / PhishRip workflows.
  • Monitor and respond to endpoint alerts within Sophos EDR/XDR and Sophos Intercept X Advanced.
  • Investigate identity and authentication alerts from Microsoft environments (sign-in risk, suspicious token, IP/location anomalies).
  • Support security investigations involving Sophos firewall alerts, Fortinet environments, MFA and YubiKey platforms.
  • Coordinate with client help desk and infrastructure teams for remediation support and escalation handling.
  • Maintain accurate documentation of incidents, actions taken, and recommendations.

Skills

Security operations
Incident response
Documentation

Tools

Mimecast
KnowBe4
PhishER
PhishRip
Sophos EDR/XDR
Intercept X
Microsoft 365 security

Job description

MetroSys is seeking a dependable and detail-oriented Security Operations Administrator for a short-term contract engagement supporting a client's security monitoring and response operations. This role is responsible for reviewing, triaging, documenting, and responding to alerts generated across the client's security platforms and infrastructure environment.

The ideal candidate has hands-on experience with endpoint security, email security, identity-related alerts, and incident response workflows, and can work independently while coordinating with help desk and infrastructure teams as needed.

This role is structured around a daily operational review window (~2 hours per day) while supporting a 24/7 alerting environment.

Key Responsibilities
  • Review and respond to security alerts and tickets generated from the client’s monitoring and security platforms
  • Investigate and triage alerts related to:
    • Endpoint security events
    • Email threats and phishing activity
    • Suspicious authentication attempts
    • Firewall and network security events
  • Perform incident response activities including:
    • Documentation
    • Initial remediation actions
    • Escalation and coordination
    • Post-mortem reporting
  • Validate email and phishing-related incidents using:
    • Mimecast
    • KnowBe4 / PhishER / PhishRip workflows
  • Monitor and respond to endpoint alerts within:
    • Sophos EDR/XDR
    • Sophos Intercept X Advanced
  • Investigate identity and authentication alerts from Microsoft environments, including:
    • Sign-in risk events
    • Suspicious token or authorization activity
    • IP/location anomalies
  • Support security investigations involving:
    • Sophos firewall alerts
    • Fortinet networking environments
    • MFA and authentication platforms (including YubiKey environments)
  • Coordinate with client help desk and infrastructure teams for remediation support and escalation handling
  • Maintain accurate documentation of incidents, actions taken, and recommendations
Required Qualifications
  • 3+ years of experience in security administration, SOC operations, or security incident response
  • Hands-on experience with:
    • Mimecast
    • KnowBe4 / phishing remediation workflows
    • Sophos EDR/XDR and Intercept X
    • Microsoft 365 security and sign-in risk analysis
  • Understanding of:
    • Security incident response workflows
    • Endpoint and network security concepts
    • Identity and access management fundamentals
  • Experience reviewing and analyzing security alerts and event data
  • Strong documentation and communication skills
  • Ability to work independently and manage daily operational responsibilities efficiently
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations Analyst: 2-Hour Daily Review Window
Security Operations Analyst: 2-Hour Daily Review Window

MetroSys, Inc. • United States

Remote
USD 55,000 - 83,000
IT Security Specialist
IT Security Specialist

ibex • Palestine (TX)

On-site
USD 90,000 - 130,000
Security Operations Center Analyst
Security Operations Center Analyst

Charter Solutions • Minneapolis (MN), Saint Paul (MN)

Hybrid
USD 70,000 - 100,000
Systems Security Specialist
Systems Security Specialist

Prosum • Tallahassee (FL)

On-site
USD 110,000 - 150,000
Analyst, Cyber Security II
Analyst, Cyber Security II

TALENT Software Services • Columbia (SC)

On-site
USD 90,000 - 140,000
Security Analyst II
Security Analyst II

Gilder Search Group • Cleveland (OH)

On-site
USD 70,000 - 100,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Cyber Security Engineer
Cyber Security Engineer

Access Search, Inc. • Tinley Park (IL)

On-site
USD 100,000 - 140,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

TriCom Technical Services • Saint Paul (MN)

Hybrid
USD 70,000 - 110,000
Contract position
401(k) match
Paid time off
+1
Information Security Operations Engineer
Information Security Operations Engineer

Connect Tech+Talent • Walnut Creek (CA)

On-site
USD 90,000 - 120,000