Cybersecurity & SecOps Analyst
Job Description
Illinois (remote day shift) role with Alvaria Inc offering USD 80,000 - 90,000 annually. In this position, you will own day-to-day internal security operations and SaaS posture management, partnering closely with a 24/7 MDR provider while coordinating escalations and strengthening automation across cloud identity and productivity workflows.
What you will help improve
- SecOps operations that stay lean through continuous automation of routine validation and reduction of false positives.
- Cloud identity and SaaS security posture via ongoing reviews of security portals, threat hunting outputs, and endpoint/XDR coverage status for a remote workforce.
- Faster, cleaner investigations by integrating security alerts into internal communication channels and centralized IT ticketing systems.
- Audit-ready documentation by collecting and packaging evidence logs that support SOC 2 compliance frameworks and internal audits.
Responsibilities
- Act as the primary internal point of contact and liaison for the company’s 24/7 Managed Detection and Response (MDR) service provider.
- Own the internal response and coordination workflow when the external security partner escalates a validated, high-severity threat.
- Review managed security portals, threat hunting reports, and endpoint/XDR coverage status across the remote workforce.
- Manage technical integration of security alerts into team communication channels and centralized IT ticketing platforms.
- Perform daily triage and manual investigation of cloud productivity suite signals, access logs, and application-layer telemetry not fully covered by external tools.
- Conduct internal reviews of cloud administrative changes, OAuth tokens, third-party application integrations, and access exceptions.
- Work with IT to enforce identity policies, MFA compliance, and conditional access rules.
- Identify repetitive manual triage steps and build low-code/no-code automated playbooks (for example, verification workflows for anomalous user login activity).
- Build and maintain automated ticketing workflows that track security issues from discovery to remediation.
- Gather and package evidence logs from endpoint managers, identity providers, and ticketing systems to support SOC 2 frameworks and internal audits.
- Maintain clear documentation on incident playbooks, approved user exceptions, and internal security standards.
Requirements
- 2–4 years of experience in cybersecurity operations, systems administration, or a dedicated IT Support role with heavy security duties.
- Hands-on experience managing centralized Endpoint Management and XDR platforms, including endpoint health, deployment compliance, and alert viewing.
- Strong baseline proficiency with enterprise Cloud Productivity Suite Administration, including security center settings, audit logs, and identity configurations.
- Workflow logic capability, such as setting up conditional logic, API webhooks, or using low-code/no-code automation to connect platforms.
- Exceptional communication skills for clear, empathetic interfaces with internal remote employees during investigations.
Technologies
- MDR
- XDR
- OAuth
- MFA
- API webhooks
- Low-code/no-code automation
- ITSM
- SOC 2
Preferred qualifications
- Prior experience in a remote SaaS or cloud-native company.
- Basic scripting awareness, such as interacting with APIs or formatting data outputs.
- Experience participating in or gathering evidence for formal compliance windows, such as SOC 2 or ISO 27001.
- Foundational, industry-standard security certifications demonstrating operational fundamentals.
Key skills
- Managed Security Service (MSSP/MDR) Vendor Coordination
- Cloud Identity & Access Management (IAM)
- Incident Coordination & Containment
- Low-Code Automation / API Integrations
- IT Service Management (ITSM) & Ticket Lifecycle Management
- Compliance Audit Evidence Collection