• Roseville, CA
    4 days ago

    Job Description

    Location: Sacramento, CA

    Job Type: Full-Time

    Department: Information Systems / Cybersecurity

    Reports To: Senior Cybersecurity Engineer

    Position Summary

    The Security Analyst I is an entry-level cybersecurity position responsible for supporting the day-to-day operation of the company's information security program. Working under the direction of senior cybersecurity staff, this position assists with security alert monitoring, vulnerability and patch management oversight, software security reviews, security configuration monitoring, audit support, and security reporting.

    This role is designed for an individual who has a foundational understanding of information technology and cybersecurity and is interested in developing a career in security operations. The Security Analyst I is not expected to independently design or engineer security solutions. The position works closely with senior security personnel, Information Systems teams, our Managed Service Provider (MSP), Managed Security Service Provider (MSSP), and other technology partners to ensure security activities are completed and appropriately documented.

    Key Responsibilities

    Security Monitoring & Alert Review

    • Review and triage security alerts generated by security monitoring platforms, endpoint security tools, email security systems, and other security technologies.
    • Perform initial investigation and gather relevant information related to security events.
    • Follow established procedures for documenting, escalating, and tracking potential security incidents.
    • Work with senior cybersecurity staff and security service providers to support incident investigation and response activities.
    • Maintain appropriate documentation and evidence related to security events and incidents.

    Vulnerability & Patch Management

    • Assist with the company's vulnerability and patch management program.
    • Review vulnerability and patching reports and track identified vulnerabilities through remediation.
    • Coordinate with the MSP and internal technology teams to ensure required patches and security updates are completed within established timelines.
    • Follow up on outstanding or failed patching activities and escalate exceptions when necessary.
    • Assist with validating and documenting remediation activities.
    • Prepare regular vulnerability and patch compliance reporting for senior security staff.

    Software & Technology Security Reviews

    • Assist with the security review of new software, applications, browser extensions, and other technologies requested for use within the company.
    • Gather required security and vendor information using established review processes and checklists.
    • Review basic security considerations such as data access, authentication, permissions, software source, and requested system privileges.
    • Identify requests requiring additional technical or security review and escalate them to senior cybersecurity staff.
    • Maintain documentation of software reviews, approvals, exceptions, and security requirements.

    Endpoint, System & Security Configuration Monitoring

    • Assist with monitoring security configurations across company-managed endpoints, systems, and security platforms.
    • Review security dashboards and reports to identify devices or systems that are missing required security controls or are not meeting established security standards.
    • Coordinate remediation activities with the appropriate internal team or service provider.
    • Assist with tracking security configuration exceptions and corrective actions.
    • Support senior security personnel with security configuration reviews and compliance reporting.

    Security Operations & Administration

    • Perform routine administrative activities within approved security tools and platforms under established procedures.
    • Assist with maintaining security policies, procedures, standards, operational documentation, and security records.
    • Generate routine security metrics, dashboards, and management reports.
    • Assist with tracking security findings, remediation activities, exceptions, and open action items.
    • Support the continuous improvement of cybersecurity processes and procedures.

    Identity & Access Security

    • Assist with periodic user access and security reviews.
    • Support reviews of privileged accounts, inactive accounts, access exceptions, and other identity-related security controls.
    • Assist with gathering documentation and evidence related to identity and access management controls.
    • Escalate identified access concerns or exceptions to senior cybersecurity personnel.

    Security Awareness

    • Assist with cybersecurity awareness and training initiatives.
    • Support phishing simulation and security awareness activities.
    • Help develop and distribute security communications and educational materials.
    • Assist employees with basic security questions and reinforce established security practices and policies.

    Disaster Recovery & Business Continuity

    • Assist with maintaining cybersecurity-related Disaster Recovery (DR) and Business Continuity Planning (BCP) documentation.
    • Support preparation and coordination of DR and BCP exercises.
    • Document testing results, identified issues, and follow-up activities.
    • Assist with tracking remediation items resulting from exercises and tests.

    Audit & Compliance Support

    • Assist the cybersecurity team with responses to regulatory, state, investor, customer, and internal audit requests.
    • Gather documentation, reports, screenshots, logs, and other evidence required to demonstrate security controls.
    • Maintain organized records of audit evidence and security documentation.
    • Assist with tracking security findings and remediation activities through completion.
    • Support compliance activities associated with the company's cybersecurity framework and regulatory obligations.

    Required Qualifications

    • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field or equivalent education, training, certifications, or relevant technical experience.

    • Approximately 0-2 years of experience in cybersecurity, information technology, help desk, systems administration, network support, or another related technical field.

    • Foundational understanding of cybersecurity concepts, including:

    • Endpoint security

    • Malware and phishing

    • Authentication and access controls

    • Vulnerability and patch management

    • Basic networking concepts

    • Security monitoring and incident escalation

    • Basic familiarity with Windows environments and Microsoft technologies.

    • Ability to review technical information, identify potential issues, and follow established escalation procedures.

    • Strong attention to detail and organizational skills.

    • Ability to maintain accurate documentation and track multiple security activities through completion.

    • Strong written and verbal communication skills.

    • Ability and willingness to learn new cybersecurity technologies, processes, and concepts.

    • Ability to work collaboratively with senior technical staff, internal technology teams, and third-party service providers.

    Preferred Qualifications

    The following qualifications are helpful but not required:

    • CompTIA Security+, Network+, or similar entry-level technology/security certification.
    • Internship, coursework, lab, or professional experience involving cybersecurity or IT operations.
    • Familiarity with SIEM, endpoint detection and response (EDR), vulnerability management, or security monitoring technologies.
    • Familiarity with Microsoft Azure, Microsoft 365, Entra ID, or Microsoft Intune.
    • Exposure to Proofpoint or other email security technologies.
    • Exposure to SentinelOne or other endpoint detection and response platforms.
    • Basic understanding of the NIST Cybersecurity Framework (NIST CSF), CIS Controls, or similar cybersecurity frameworks.
    • Basic familiarity with PowerShell, Python, or other scripting/automation technologies.
    • Experience working with an MSP, MSSP, SOC, help desk, or other technology service provider.

    Knowledge & Skills

    Successful candidates should demonstrate:

    • Curiosity and a desire to develop a career in cybersecurity.
    • Good analytical and troubleshooting skills.
    • Strong attention to detail.
    • Ability to recognize when an issue requires escalation.
    • Ability to follow established processes while identifying opportunities for improvement.
    • Ability to communicate technical information clearly to both technical and non-technical audiences.
    • Strong organizational and follow-through skills.
    • Sound judgment when handling confidential or sensitive information.

    Career Development

    The Security Analyst I position is intended as an entry point into the company's cybersecurity career path. The employee will receive guidance and mentoring from senior cybersecurity personnel while developing deeper expertise in security operations, vulnerability management, incident response, cloud security, security architecture, and cybersecurity risk management.

    As experience and technical capabilities develop, the position may progress into more advanced Security Analyst or Cybersecurity Engineer responsibilities.

    Numbers & Facts

    LocationRoseville, CA

    Skills

    • Access Controlunmatched
    • Authenticationunmatched
    • Business Continuity Planning (BCP)unmatched
    • Career Developmentunmatched
    • Cloud Computingunmatched
    • Code Reviewsunmatched
    • Communication Skillsunmatched
    • Communications Security (COMSEC)unmatched
    • CompTIA Network+unmatched
    • CompTIA Security+unmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Continuous Improvementunmatched
    • Corrective Actionunmatched
    • Detail Orientedunmatched
    • Disaster Recoveryunmatched
    • Documentationunmatched
    • Email Securityunmatched
    • Email Technologyunmatched
    • Employee Orientationunmatched
    • Endpoint Securityunmatched
    • Follow Throughunmatched
    • Help Deskunmatched
    • Identify Issuesunmatched
    • Identity Data Managementunmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internal Auditunmatched
    • Internet Securityunmatched
    • Mentoringunmatched
    • Metricsunmatched
    • Microsoft Product Familyunmatched
    • Microsoft Windows Azureunmatched
    • Microsoft Windows Operating Systemunmatched
    • Network Administration/Managementunmatched
    • Operations Managementunmatched
    • Operations Security (OPSEC)unmatched
    • Organizational Skillsunmatched
    • Phishingunmatched
    • Presentation/Verbal Skillsunmatched
    • Procedure Developmentunmatched
    • Process Developmentunmatched
    • Process Improvementunmatched
    • Protective Servicesunmatched
    • Python Programming/Scripting Languageunmatched
    • Regulationsunmatched
    • Reporting Dashboardsunmatched
    • Risk Managementunmatched
    • Scripting (Scripting Languages)unmatched
    • Security Analysisunmatched
    • Security Architectureunmatched
    • Security Attacksunmatched
    • Security Auditingunmatched
    • Security Complianceunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Infrastructureunmatched
    • Security Monitoringunmatched
    • Security Patchesunmatched
    • Security Softwareunmatched
    • Simulationunmatched
    • Software Administrationunmatched
    • Software Patchesunmatched
    • State Laws and Regulationsunmatched
    • Systems Administration/Managementunmatched
    • Team Playerunmatched
    • Technical/Engineering Designunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Web Browsersunmatched
    • Windows PowerShellunmatched
    • Writing Skillsunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder