IT and Security Analyst
The IT and Security Analyst manages endpoint and SaaS environments, user access, vulnerability management, security operations, and compliance activities. The role requires at least two years of IT or information security experience, including hands-on Microsoft Intune and endpoint management experience.
About the job
Responsibilities
IT Operations
- Administer Microsoft Intune for endpoint management, device enrollment, and compliance policies.
- Manage user access provisioning and deprovisioning according to least-privilege principles.
- Maintain the SaaS application inventory, including license management and access reviews.
- Support onboarding and offboarding, including identity lifecycle management.
Information Security
- Support the vulnerability management program by tracking, prioritizing, and coordinating remediation.
- Monitor threat intelligence feeds and translate findings into actionable recommendations.
- Assist with incident response and security tooling administration.
Governance, Risk, and Compliance
- Support compliance initiatives aligned with frameworks such as SOC 2, ISO 27001, or NIST.
- Assist with the third-party risk management program, including vendor assessments.
- Complete security questionnaires from customers and partners.
- Maintain security policies and support evidence collection for audits.
Requirements
- 2+ years in an IT, information security, or combined IT/security role.
- Hands-on experience with Microsoft Intune and endpoint management.
- Experience managing user access and permissions in a corporate environment.
- Familiarity with SaaS platforms and IT asset management.
- Exposure to vulnerability management tools and processes.
- Understanding of threat intelligence concepts.
- Familiarity with at least one compliance framework, such as SOC 2, ISO 27001, NIST, or CIS.
- Experience with security questionnaires and/or third-party risk assessments.
- Strong written and verbal communication skills.
Skills
Microsoft Intune, Endpoint Management, Identity Management, Access Management, SaaS, It Asset Management, Vulnerability Management, Threat Intelligence, Incident Response, SOC 2, ISO 27001, Nist, Cis, Third-Party Risk Management
Similar jobs
Security Engineering jobsSecures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
Conduct end-to-end security research on emerging threats, CVEs, misconfigurations, and cloud attack surfaces, then turn findings into scalable detection capabilities. Requires at least five years of security research or related experience, strong scripting skills, and expertise in network and application security.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
Leads information security governance, compliance, security operations, risk management, and incident response for a healthcare AI company. Requires 5+ years of security experience and hands-on expertise with major compliance frameworks, SIEM, incident response, and third-party risk.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.