Security Operations Analyst

Franchise World Headquarters, LLC

Shelton (CT)

On-site

USD 85,000 - 115,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical & Life Insurance
Pension/401K
Bonus
Mobility Allowance
Tuition Reimbursement
Company Holidays
Volunteer time

Job summary

Franchise World Headquarters, LLC is seeking a Security Operations Analyst to manage identity security within Subway's cybersecurity program in Shelton, CT. You will operate identity threat detection with CrowdStrike, support authentication governance, and investigate anomalies using Falcon Next-Gen SIEM.

You will collaborate with IAM and Detect & Respond teams, perform runbooks, and contribute to audit-ready evidence for PCI-DSS 4.0 and cyber-insurance programs.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field, or equivalent work experience.
  • 1-3 years in security operations or identity/security scope in SOC/IT ops.
  • Working knowledge of IAM: authentication, MFA, SSO, directory services, lifecycle, least-privilege.
  • Hands-on exposure to Okta or comparable identity provider.
  • Familiarity with SOC practices: alert triage, escalation, evidence handling, incident documentation.
  • Exposure to SIEM or security analytics platform; willingness to develop CQL proficiency.
  • Active Directory fundamentals and Entra ID / M365 concepts.
  • Experience with ServiceNow or similar ITSM in ticket-driven ops.

Responsibilities

  • Operate identity threat detection and response with CrowdStrike Falcon Identity Protection and triage identity-based detections.
  • Support tuning of identity detections, dashboards, and alert quality with Detect & Respond.
  • Run Okta Identity Governance access certification campaigns end to end including audits for PCI-DSS 4.0.
  • Apply least-privilege daily: flag over-broad access, maintain evidence for audits.
  • Triage backlog: investigate and close identity-risk findings with SLAs.
  • Handle Tier-2/3 identity escalations and respond to investigations with proper documentation.
  • Author runbooks and knowledge-base articles for identity security operations.

Skills

IAM fundamentals
SOC practices
incident documentation
LLM tools usage
threat detection

Education

Bachelor's degree in CS/IT/Cybersecurity or equivalent

Tools

CrowdStrike Falcon Identity Protection
Okta Identity Governance
CrowdStrike Falcon Next-Gen SIEM
ServiceNow
Microsoft Entra ID / AD

Job description

Security Operations Analyst

Franchise World Headquarters, LLC


Shelton, CT


Why Join Subway?

At Subway, we are not standing still. We are building.


This is a business focused on what matters most: growing franchisee profitability, strengthening our brand and creating long-term value. The people who thrive here are the ones who want to make a real impact.


You will not just do the work. You will shape it.


We move fast. We think like owners. We make decisions that matter. We hold ourselves to a high standard because what we do directly impacts thousands of franchisees around the world.


If you bring energy, accountability and a bias for action, you will fit right in.


We take the work seriously, but we also know the best results come from teams that support each other, celebrate wins and show up ready to build something better every day.


This is your chance to be part of what's next.


Position Overview

The Security Operations Analyst operates the identity security and access-governance layer of Subway's Cybersecurity program. Sitting within the Identity & Access Management team, this role is the operational bridge between IAM and the Detect & Respond function - identity-first in day-to-day work, but grounded in general security operations center (SOC) practice. The Analyst runs access-governance controls that keep the enterprise least-privileged and audit-ready, operates identity threat detection and response using CrowdStrike Falcon Identity Protection, and investigates access anomalies in Falcon Next-Gen SIEM. This role is designed as a genuine growth seat and launchpad into the broader Cybersecurity program, with development paths toward senior identity security, threat detection engineering, security engineering, or IAM engineering.


Responsibilities


  • Operate identity threat detection and response with CrowdStrike Falcon Identity Protection: monitor and triage identity-based detections, assess risk and severity, apply risk-based policy actions within defined guardrails, and elevate confirmed threats to the Detect & Respond team; investigate access anomalies end to end using identity telemetry in CrowdStrike Falcon Next-Gen SIEM - authentication events, MFA activity, privileged-account usage, and provisioning changes.

  • Support tuning of identity detections, dashboards, and alert quality with the Detect & Respond team; participate in incident response for identity-related incidents including account compromise, credential abuse, and unauthorized access - executing containment actions such as session revocation, credential reset, and access suspension under team runbooks; monitor privileged and service-account activity for anomalous behavior and policy violations.

  • Run Okta Identity Governance access certification campaigns end to end: campaign setup and scoping, reviewer coordination and follow-up, revocation execution, exception tracking, and production of audit-ready evidence for PCI-DSS 4.0 and cyber-insurance programs; support access request workflow operations including approval-path exceptions and escalations outside self-service.

  • Apply least-privilege principles in daily work: flag over-broad group and role assignments, validate time-bound privileged access, and drive cleanup of dormant, orphaned, or over-privileged accounts; produce and maintain access evidence for internal and external audits and compliance programs.

  • Work down the standing identity-risk case backlog: investigate, prioritize, remediate, and close findings such as dormant accounts, stale privileged access, weak authentication paths, and unowned service accounts; track remediation against service-level targets and report progress and systemic patterns to Cybersecurity leadership.

  • Handle Tier-2/3 identity escalations remaining after automation - complex access requests, provisioning exceptions, and onboarding/offboarding edge cases; manage assigned tickets in ServiceNow meeting SLA targets; support access-related requests from investigations, legal holds, and HR partners with appropriate discretion and documentation; participate in the team's shared on-call rotation.

  • Author and maintain runbooks, triage guides, and knowledge-base articles for identity security operations and certification processes; track and report on identity-risk backlog burn-down, certification completion rates and detection quality metrics; propose governance, detection, and automation improvements from observed patterns.


Qualifications


  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field - or equivalent work experience.

  • 1-3 years in security operations, identity operations, a security operations center (SOC), or IT operations with significant identity or security scope.

  • Working knowledge of IAM fundamentals: authentication and MFA, SSO concepts, directory services, joiner/mover/leaver lifecycle, and least-privilege access.

  • Hands-on exposure to Okta or a comparable identity provider: user and group administration, MFA management, and basic application assignment; Okta strongly preferred.

  • Familiarity with SOC practices: alert triage, severity assessment, escalation paths, evidence handling, and incident documentation.

  • Exposure to a SIEM or security analytics platform - querying logs, investigating events, and reading detections; CrowdStrike Falcon Next-Gen SIEM a plus; willingness to develop CQL proficiency required.

  • Active Directory fundamentals (users, groups, OUs) and familiarity with Microsoft Entra ID and Microsoft 365 administration concepts.

  • Experience with an ITSM platform (ServiceNow preferred) in a ticket-driven operations environment.

  • Strong written documentation habits - investigations, evidence, and runbooks that others can follow and auditors can rely on.

  • Comfort using LLM and generative AI tools in day-to-day technical and analytical work.


Preferred Qualifications


  • Direct experience with identity threat detection and response tooling (CrowdStrike Falcon Identity Protection or similar ITDR platform).

  • Exposure to Okta Identity Governance or another IGA/access-certification platform (SailPoint, Saviynt, Omada).

  • Familiarity with identity-focused attack techniques - credential stuffing, MFA fatigue, token theft, Kerberos abuse, lateral movement - and the MITRE ATT&CK framework.

  • Basic scripting in PowerShell or Python for reporting, reconciliation, and evidence gathering.

  • Awareness of non-human identity concepts: service accounts, credential scoping, and access patterns for LLM and agentic AI integrations.

  • Exposure to attack surface/asset management (CAASM) tooling.

  • Relevant certification: CompTIA Security+, Okta Certified Professional, Microsoft SC-300, or GIAC entry-level certification.


What do we offer?


  • Insurance Plans (Medical, Life)

  • Pension/401K/RSP (country specific)

  • Competitive Bonus

  • Mobility Allowance

  • Tuition Reimbursement

  • Company Holidays

  • Volunteering time

  • And More.....

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Analyst
Security Operations Analyst

Subway • Shelton (CT)

On-site
USD 80,000 - 120,000
Insurance Plans (Medical Life)
Pension/401K/RSP
Competitive Bonus
+5
Sr. IAM Engineer
Sr. IAM Engineer

Franchise World Headquarters, LLC • Shelton (CT)

On-site
USD 130,000 - 170,000
Insurance Plans (Medical, Life)
Pension/401K/RSP
Competitive Bonus
+4
Sr. IAM Engineer
Sr. IAM Engineer

Pho Prime, LLC • Shelton (CT)

On-site
USD 120,000 - 170,000
Mobility Allowance
IAM Engineer
IAM Engineer

Pho Prime, LLC • Shelton (CT)

On-site
USD 120,000 - 160,000
IAM Engineer
IAM Engineer

Franchise World Headquarters, LLC • Shelton (CT)

On-site
USD 110,000 - 150,000
Medical & Life Insurance
401K / Pension
Competitive Bonus
+4
IAM Engineer
IAM Engineer

Subway • Shelton (CT)

On-site
USD 110,000 - 140,000
Insurance Plans (Medical) and Life
Pension/401K
Competitive Bonus
+5
Identity Security Operations Analyst
Identity Security Operations Analyst

Subway • Shelton (CT)

On-site
USD 80,000 - 120,000
Insurance Plans (Medical Life)
Pension/401K/RSP
Competitive Bonus
+5
Identity Security Ops Analyst: Impactful IAM Role
Identity Security Ops Analyst: Impactful IAM Role

Franchise World Headquarters, LLC • Shelton (CT)

On-site
USD 85,000 - 115,000
Medical & Life Insurance
Pension/401K
Bonus
+4
Senior Identity Protection Specialist
Senior Identity Protection Specialist

Jobtailor • Morrisville (NC)

On-site
USD 140,000 - 190,000
Manager, Platform Professional Services (Remote)
Manager, Platform Professional Services (Remote)

CrowdStrike • California (MO)

On-site
USD 140,000 - 195,000
Market-leading compensation
Comprehensive wellness programs
Paid parental leaves
+2