IT Cybersecurity Analyst II

Club Car LLC
  • Evans, GA
    6 days ago

    Job Description

    Club Car boasts a 60+ year history of industry-leading innovation and design, initially focused on golf cars and then expanding to commercial utility vehicles and personal-use transportation.

    GENERAL JOB DESCRIPTION

    The Cybersecurity Analyst II plays a critical role in protecting the organization's information systems by maintaining, monitoring, and continuously improving cybersecurity operations and controls. This position is responsible for day-to-day security operations, including Identity and Access Management (IAM), Privileged Access Management (PAM), Endpoint Detection and Response (EDR), Security Operations Center (SOC) functions, IT General Controls (ITGC), vulnerability management, compliance support, and security monitoring activities. The ideal candidate possesses a strong understanding of cybersecurity frameworks, security best practices, and hands-on experience with security technologies, and operates with a high degree of independence while partnering with IT teams, managed security service providers, and cybersecurity leadership to reduce organizational risk.

    Essential Job Functions:

    Identity and Access Management (IAM):

    • Manage and support IAM tools and systems, ensuring secure authentication and authorization mechanisms are in place.
    • Oversee the provisioning and de-provisioning of user accounts, ensuring appropriate access levels based on the principle of least privilege.
    • Monitor and audit user access logs, ensuring compliance with security policies.
    • Administer, support, and enforce Multi-Factor Authentication (MFA) and Single Sign-On (SSO) solutions.
    • Collaborate with HR, IT, and other departments to ensure role-based access controls (RBAC) are in place and up to date.
    1. Privileged Access Management (PAM):
    • Administer, support, and continuously improve PAM solutions to ensure secure management of privileged accounts.
    • Perform periodic reviews and audits of privileged accounts, ensuring access is limited and monitored.
    • Manage and automate the rotation of privileged credentials, ensuring secure password management.
    • Monitor privileged sessions in real-time and respond to potential security threats associated with misuse of privileged accounts.
    • Maintain the inventory of all privileged accounts and provide continuous improvement recommendations.
    1. Endpoint Detection and Response (EDR):
    • Administer, configure, and maintain EDR solutions across corporate endpoints.
    • Continuously monitor and analyze EDR alerts, logs, and endpoint activity; investigate security events to support threat detection, incident response activities, and root cause analysis.
    • Develop, tune, and refine endpoint detection rules to improve visibility into suspicious or malicious activity.
    • Collaborate with managed security providers and IT teams to ensure timely investigation and remediation of security events identified through EDR tools.
    • Maintain EDR platform health, agent coverage, and configuration compliance across enterprise endpoints.
    • Support endpoint security initiatives, including hardening, patch validation, and control effectiveness reviews.
    1. Security Operations Center (SOC) Tasks:
    • Collaborate with the SOC to identify, investigate, and respond to cybersecurity threats and incidents.
    • Monitor security alerts and events from SIEM and other monitoring tools.
    • Conduct incident triage and escalate potential incidents based on established procedures.
    • Support incident investigations, containment, eradication, recovery, and post-incident reviews under the direction of cybersecurity leadership.
    • Maintain up-to-date documentation of security incidents, threat intelligence, and mitigation efforts.
    1. IT General Controls (ITGC) Implementation:
    • Assist in the design, implementation, and continuous improvement of IT General Controls (ITGCs), ensuring alignment with industry best practices and compliance requirements (e.g., SOX, HIPAA, GDPR).
    • Perform periodic reviews and testing of ITGCs to evaluate effectiveness and support audit readiness.
    • Provide recommendations to strengthen IT controls and mitigate identified risks and control deficiencies.
    • Collaborate with internal and external audit teams to ensure ITGCs are properly documented, maintained, and supported with appropriate evidence.
    • Develop, maintain, and periodically review security policies, standards, and procedures aligned with the organization's risk management strategy.
    1. Vulnerability Management:
    • Conduct regular vulnerability assessments across the organization's networks, endpoints, servers, cloud services, and applications.
    • Utilize vulnerability scanning and security assessment tools to identify security weaknesses, outdated software, and misconfigurations.
    • Collaborate with IT teams to prioritize, track, and remediate vulnerabilities based on risk, exploitability, and business impact.
    • Develop and maintain vulnerability metrics, dashboards, and reporting to communicate security posture and remediation progress to leadership.
    • Monitor emerging threats and vulnerabilities and coordinate timely remediation and patch management activities.
    • Validate remediation efforts and track vulnerability trends to measure control effectiveness and risk reduction over time.

    Additional Responsibilities:

    • Participate in cybersecurity awareness training programs, helping to educate employees about security best practices and phishing awareness.
    • Assist with security risk assessments and the development of a risk mitigation strategy.
    • Stay current with the latest cybersecurity trends, attack methods, and defense strategies.
    • Contribute to the continuous improvement of the organization's cybersecurity framework.
    • Participate in security-related projects as needed, providing technical guidance and ensuring adherence to security standards.
    • Review security controls and assist with remediation planning and risk reduction efforts alongside IT stakeholders.
    • Assess and improve security controls across Microsoft 365, cloud platforms, identity systems, SaaS applications, and endpoint technologies.
    • Develop and maintain cybersecurity metrics, dashboards, and reporting to communicate security posture, remediation progress, and risk reduction efforts to leadership.

    EDUCATION, EXPERIENCE & SKILLS

    • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience.
    • 3-5 years of progressively responsible cybersecurity experience.
    • Experience with IAM, PAM, EDR, vulnerability management, security monitoring, incident response support, and compliance activities.
    • Strong knowledge of cybersecurity frameworks (e.g., NIST, ISO 27001, CIS Controls).
    • Hands-on experience with security technologies, including SIEM, EDR, IAM, PAM, and vulnerability management tools.
    • Experience supporting Microsoft 365 security, cloud security controls, and identity governance initiatives.
    • Preferred Certifications:
    • Security+
    • CySA+
    • SSCP
    • GSEC
    • CISSP or CISM (preferred but not required)

    Club Car is a diverse and inclusive environment. We are an equal opportunity employer, dedicated to hiring a diverse workforce; including individuals with disabilities and United States qualified protected veterans.

    Numbers & Facts

    LocationEvans, GA
    Want to know if you’re a fit?
    Upload your resume and let our AI show you.

    Skills

    • Access Controlunmatched
    • Analysis Skillsunmatched
    • Authenticationunmatched
    • Best Practicesunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Cloud Applicationsunmatched
    • Cloud Computingunmatched
    • CompTIA Security+unmatched
    • Computer Hackingunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Continuous Improvementunmatched
    • Documentationunmatched
    • Endpoint Securityunmatched
    • Enterprise Endpointunmatched
    • Establish Prioritiesunmatched
    • External Auditunmatched
    • GSEC - GIAC Security Essentials Certificationunmatched
    • HIPAA (Health Insurance Portability and Accountability Act)unmatched
    • ISO (International Organization for Standardization)unmatched
    • Identity Data Managementunmatched
    • Incident Managementunmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internal Auditunmatched
    • Internet Securityunmatched
    • Inventory Managementunmatched
    • Leadershipunmatched
    • Maintain Complianceunmatched
    • Management Strategyunmatched
    • Metricsunmatched
    • Microsoft Product Familyunmatched
    • Operational Improvementunmatched
    • Organizational Development/Managementunmatched
    • Phishingunmatched
    • Procedure Developmentunmatched
    • Regulatory Complianceunmatched
    • Reporting Dashboardsunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Root Cause Analysisunmatched
    • SSCP - Systems Security Certified Practitionerunmatched
    • Sarbanes-Oxley Act (SOX)unmatched
    • Security Analysisunmatched
    • Security Attacksunmatched
    • Security Complianceunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Monitoringunmatched
    • Single Sign-On (SSO)unmatched
    • Software Patchesunmatched
    • Software as a Service (SaaS)unmatched
    • Staff Trainingunmatched
    • Technical Leadershipunmatched
    • Testingunmatched
    • Time Managementunmatched
    • Training Programunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Vulnerability Scannersunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder