Staritas logo
StaritasPosted 2 weeks ago

Security Analyst III

$110,000–$125,000 year

RemoteUnited States

Full TimeSmall

Job Summary

Lead security monitoring and response operations leveraging SIEM and integrated security platforms; tune alerts, develop use cases, and drive continuous improvement in detection capabilities. Own SIEM platform management, including onboarding new log sources, correlation rule development, and integration with endpoint, cloud, and network security tools. Develop, implement, and enforce security policies, standards, and procedures aligned with SOC 2 and industry best practices. Lead incident response activities, including investigation, containment, root cause analysis, and documentation; coordinate with internal and external stakeholders as required. Manage vulnerability management program, including scanning, prioritization, remediation tracking, and reporting to leadership. Own and administer the security awareness program, including KnowBe4 rollout, phishing simulations, reporting, and targeted training campaigns. Serve as primary owner for SOC 2 compliance activities, including control documentation, evidence collection, audit coordination, and continuous control monitoring. Partner with IT Operations to implement and enforce secure configurations, access controls, and endpoint protection strategies. Lead evaluation, selection, and implementation of new security technologies, including cost analysis and operational integration planning. Manage third-party security services and vendors and ensure contractual and operational expectations are met. Oversee BYOD and endpoint security programs, including MDM enforcement and secure access policies. Support client and regulatory security inquiries, including RFP responses and due diligence requests. Stay current with evolving threat landscape, compliance requirements, and security best practices.

Required Qualifications

  • 7–10+ years of experience in cybersecurity, IT security operations, or related fields
  • Demonstrated experience with SIEM platforms (e.g., Microsoft Sentinel, SUMO, or equivalent) including design, tuning, and operational ownership
  • Proven experience developing and enforcing security policies and governance frameworks (SOC 2 required)
  • Experience leading or supporting SOC 2 audits, including control ownership and evidence management
  • Hands-on experience with security awareness platforms such as KnowBe4, including program rollout and management
  • Experience with incident response, vulnerability management, and endpoint security tooling
  • Experience working with managed security providers (MDR/eSOC)
  • Strong project management and cross-functional collaboration skills
  • Bachelor's degree in Info Tech, Cybersecurity, Computer Science, or related field
  • SIEM platforms (Microsoft Sentinel, SUMO)
  • Endpoint protection and EDR tools
  • Vulnerability management platforms
  • Identity and access management controls
  • Cloud and SaaS security monitoring
  • Microsoft 365 security ecosystem
  • CISSP, CISM, or similar advanced security certification
  • Microsoft Security certifications (e.g., SC-200, SC-300)
  • SOC 2 / compliance-related training or certifications
  • Up to 10% travel, based on business needs

Desired Qualifications

  • Experience leading or supporting SOC 2 audits, including control ownership and evidence management a plus
  • Microsoft Security certifications (e.g., SC-200, SC-300)
  • SOC 2 / compliance-related training or certifications

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce