Information Security Analyst I
Job Description
Join a hybrid security operations and governance team supporting monitoring, incident support, and vulnerability management.
Responsibilities
- Monitor and respond to information security alerts from platforms including SIEM, Firewall/Proxy, AV/EDR, IDS/IPS, E-mail security gateways, password vaults, and other systems as needed.
- Support day-to-day information security operations, including investigation of vulnerability reports.
- Assist with management and onboarding of new vendors into the VRM portal, addressing stakeholder concerns and conducting IRQ assessments to facilitate vendor management through the VRM process.
- Administer key technology within the information security program and act as a first line of contact for platform user support.
- Assist users and administrators with investigations and incident response.
- Troubleshoot applications, servers, and security services to maintain IT security posture; document results with knowledge articles.
- Maintain and troubleshoot access management systems, including assistance with upgrades and new feature planning.
- Provide backup support to senior staff for tasks related to PAM (privileged access management).
- Assist with GRC activities such as audit review, data governance review, access review, and compliance support.
- Patch, maintain, and support security systems under guidance from senior staff.
- Evaluate and mitigate security vulnerabilities; remain aware of security posture improvements and escalate security issues as appropriate.
- Participate in DR test processes and develop understanding of DR principles and procedures used at PERA.
- Identify opportunities to improve confidentiality, integrity, and availability across supported systems.
- Support system integrations and application upgrades as directed by senior staff.
- Participate in vendor security reviews and help identify and resolve issues with vendor solutions or configurations.
- Independently research and test work; seek guidance after making conclusions and gathering evidence. Assist internal stakeholders with evidence gathering and analysis.
- Perform other duties as assigned.
Requirements
- Degree in a technical (STEM) field or one year of experience in a technical role.
- Demonstrated working experience in an IT discipline supporting any of: Windows Active Directory, networking, security, virtualization, help desk, or other IT disciplines.
- Experience configuring devices and services to meet organizational security standards.
- Ability to read and understand configuration documents, security alerts, and log data; comfortable responding to security incidents.
- Experience configuring and testing platform upgrades or performing new software rollouts.
- Demonstrated ability to be resourceful, make sound decisions, balance multiple initiatives, and drive issues to closure.
- Passion for information security in practice and a desire to continuously learn across IT and technology.
- Experience working with systems and software within the assigned technology domain is preferred.
- Knowledge of Windows and Linux operating systems, server administration, desktop administration, troubleshooting, and user support is preferred.
- Preferred knowledge of administration tasks including user/group/role administration, security permissions administration, access authentication and authorization schemes, and user provisioning.
- Self-starter in systems administration and patching, including ability to track changes and provide security reporting on assigned systems is preferred.
- Experience supporting Windows virtual desktop environments, Windows server infrastructure, vmWare, Linux, or vendor-provided platforms is preferred.
- Understanding of network devices and principles including routers, switches, gateways, physical access systems, and wireless access systems is preferred.
- Basic knowledge of computer networking protocols, authentication protocols, and secure communications in a Windows domain environment is preferred.
- Exposure to monitoring and escalating security events, including email phish investigation and OS security, is preferred.
Technologies
- MS Windows, Windows Active Directory, Windows virtual desktop environments, Windows server infrastructure
- vmWare, Linux
- SIEM, Firewall/Proxy, AV/EDR tools, IDS/IPS tools
- E-mail security gateways, password vaults
- VRM portal, PAM, GRC, DR
- Windows domain environment, routers, switches, gateways, physical access systems, wireless access systems
- Authentication protocols
Location and Work Setup
- Location: Denver, CO (hybrid)
- Hybrid work option: Opportunity to work from home up to three days per week (eligibility dependent on PERA’s Work from Home Policy)
Working Conditions
- Standard office environment with frequent telephone communication and computer operation; other office productivity machinery (e.g., copy and printer machine)
- Occasional moving and positioning supplies exceeding 20 pounds
- Professional presentation aligned with the financial services industry
- Ability to sit for prolonged periods
- Ability to operate standard PC equipment
- Ability to manage frequent deadlines and tight schedules
Additional Information
- Reports to: Information Security Manager
- Division: Information Technology
- Job status: Full Time / Exempt
- Compensation: USD 72,000 - 88,000 per year (commensurate with experience)
- Posting dates: 10/09/2026 to 10/25/2026
- Disclaimer: Job duties may change or new ones may be assigned with or without notice
- Candidate eligibility: Not able to consider candidates requiring sponsorship (now or in the future) or located outside the US