Hands-on tier-one IT Security Operations Analyst monitoring Microsoft Defender and Sentinel for threats, triaging alerts, investigating phishing and account compromises, performing access audits, and supporting SOC 2/ISO audits. Requires 1-2 years security or sysadmin experience and familiarity with Microsoft security tools.
Salary not listed
On-site2+ YOESecurity Engineering
About the role
What you get to do everyday
Monitor Microsoft Defender and Microsoft Sentinel for security alerts, and triage each one to determine whether it represents a real threat, a policy violation, or a false positive.
Conduct a monthly review of user accounts and access rights across AlertMedia’s systems, flagging stale, orphaned, or over-permissioned accounts for remediation.
Investigate reported phishing emails: trace headers, check URLs and attachments against threat intelligence, and determine whether any employee interacted with the message before it was reported.
Respond to suspected account compromises by containing the affected account, resetting credentials, reviewing sign-in and audit logs for unauthorized activity, and documenting the full timeline.
Triage and remediate other security incident types, escalating complex or high-severity incidents to senior analysts according to AlertMedia’s incident response playbooks.
Maintain accurate, detailed incident records and investigation notes that hold up to internal review and external audit.
Support annual SOC 2 and ISO 27001 audits by gathering evidence, documenting controls, and responding to auditor requests alongside the security and compliance teams.
Assist with identity and access management tasks, including provisioning, deprovisioning, and periodic access reviews tied to employee onboarding and offboarding.
Contribute to and help keep current the security playbooks and standard operating procedures used across the team.
Support employee security awareness efforts, including targeted follow-up training after phishing or social engineering incidents.
Create and maintain consistent simulated phishing campaigns.
What you bring to the role
One to two years of experience in IT security, security operations, systems administration, or a related technical role.
Working familiarity with Microsoft Defender (Endpoint, Identity, or Office 365) and Microsoft Sentinel, or comparable SIEM and EDR tools.
A methodical, detail-oriented approach to investigation.
Clear written and verbal communication; you can explain a technical finding to both an engineer and a non-technical stakeholder.
A basic understanding of identity and access management concepts, including least privilege and account lifecycle management.
What sets you apart
Exposure to compliance frameworks such as SOC 2, ISO 27001, or NIST, including audit evidence collection preferred.
A relevant certification such as CompTIA Security+, CompTIA CySA+, or Microsoft SC-200 preferred.
Familiarity with Microsoft 365 administration, Azure Active Directory (Entra ID), or basic KQL queries.
Basic scripting ability in PowerShell for investigation and light automation preferred.
1-2 years experience in security/security operations or 3-5 years experience in system administration preferred.
Why you’ll love working at AlertMedia
Competitive base salary + Company-wide bonus program.
Generous and flexible time and parental leave policies.
Health benefits - Medical, Dental, Vision and Life Insurance 100% paid for employees!
401K with a generous company match.
Amazing rewards and incentives – we love celebrating each other!
Commitment to community service with opportunities to give back.
A Best Places to Work company 10 years in a row and numerous other awards.
Access to brand new downtown office with 360 views of Austin, high-tech building gym, and nearby running trails.
Ongoing career development opportunities with our Learning and Development team.
Skills
microsoft defendermicrosoft sentinelSIEMedrSOC 2ISO 27001PowerShellkqlmicrosoft 365entra idcomptia security+comptia cysa+microsoft sc-200
Entry-level cybersecurity analyst supporting clients, compliance, IT, and business operations while learning frameworks, tools, and industry certifications. The role requires strong communication, follow-through, curiosity, resilience, and willingness to work a demanding on-site schedule.
Supports Cloudflare’s security compliance and risk programs through control evaluations, audits, risk assessments, and automation. The internship requires familiarity with security frameworks, risk management, Python, application development, and AI-enabled workflows.
Salary not listedOn-siteEntry levelSecurity Engineering
Cyber Security Intern
LabelboxSan Francisco, CA
Security Engineering Intern at Labelbox supporting vulnerability management, IAM workflows, cloud access controls, SIEM optimization, and CI/CD security. Requires current pursuit of a CS/Cybersecurity degree, interest in cloud/data security, and basic cloud platform knowledge.
40 – 55/hrHybridEntry levelSecurity Engineering
Detection Engineer II
InstacartUnited States
Detection Engineer building and operating high-fidelity detection systems, threat hunting, and automated response across endpoint, cloud, container, and SaaS environments at Instacart. Requires 2+ years in detection/IR/offensive security, cloud experience, deep attacker TTP knowledge, macOS internals, and detection-as-code practices.
142k – 181k/yrRemote2+ YOESecurity Engineering
Security Guard
IdmeMcLean, VA
Unarmed Security Guard responsible for patrolling facilities, controlling access, responding to emergencies, and ensuring safety at ID.me offices. Requires 2+ years security experience, DCJS certification (or equivalent), physical fitness, and ability to obtain Public Trust clearance.