Security Analyst
Job Description
Athens Administrators seeks a Security Analyst to strengthen protection of enterprise systems, data, and user access through monitoring, incident work, compliance support, and vulnerability lifecycle management.
Responsibilities
- Monitor and investigate security alerts from DataDog SEIM, CrowdStrike EDR, Duo, Mimecast, and other security tooling
- Review unusual login activity, access anomalies, and endpoint behaviors; escalate as appropriate
- Support incident response by managing incident response playbooks and assisting with root cause analysis (RCA) documentation
- Coordinate with system administrators to isolate, triage, and remediate threats
- Operate and analyze Qualys vulnerability scan results across servers, endpoints, cloud resources, and network devices
- Work with System Administrators to validate patch deployment and remediation timelines
- Participate in annual and ad-hoc penetration testing remediation efforts, including taking point on remediation items raised
- Support configuration, policy tuning, and operational use of CrowdStrike, Duo MFA, Cloudflare Zero Trust, OKTA/Entra ID, and Mimecast
- Perform geo-blocking, conditional access rule reviews, and file transfer audits via Secure FTP
- Review and maintain Athens security policies and procedures to support compliance with industry standards and regulations
- Ensure Athens team members are educated on and acknowledge Athens Policies and Procedures based on their role
- Serve as primary point of contact for SOC 1 and SOC 2 auditors
- Work within Athens to support progress toward TX Ramp status (primary point person within Athens)
- Prepare and maintain system logs, evidence, and control testing documentation for SOC 1 and SOC 2 audits
- Monitor Data Loss Prevention (DLP) violations across M365, Secure FTP, and SIMS/CXP claims platforms
- Enforce access controls and support system onboarding/offboarding with audit-ready tracking
- Assist with staff security awareness activities including security awareness training and phishing simulations
- Maintain and enhance internal documentation for policy, incident response, and security tool configuration
- Contribute to the security roadmap by proposing improvements to detection, prevention, and automation
- Schedule and take point for annual Disaster recovery testing
- Answer security questionnaires from prospects, customers, carriers, and the insurance company
Requirements
- Bachelor’s degree in information technology, computer science, or a related field, or equivalent practical experience
- CISSP certification required
- Relevant certifications such as CompTIA Security+, CompTIA Project+, Microsoft SC-200, or AWS Certified Security are highly desirable; willingness to pursue further certifications encouraged
- 3–5 years in IT security operations, SOC monitoring, or vulnerability management
- Knowledge of relevant software including Microsoft Windows 10 and 11, Office 365, and hardware such as PCs, laptops, monitors, and printers
- Working knowledge of DataDog, CrowdStrike, Duo, OKTA, Mimecast, and Cloudflare
- Hands-on experience with Qualys, BitLocker, InTune, and Secure FTP
- Familiarity with Microsoft 365 DLP, Zoom security configuration, and AWS IAM policies
- Experience supporting audit frameworks including SOC 1/2, HIPAA, or ISO 27001
- Experience with privacy regulations including CCPA, CPRA, and GPDR
- TX Ramp and/or State Ramp experience is a huge bonus
- Proficiency with log analysis tools such as DataDog and scripting in PowerShell or Python
- Strong customer service and interpersonal skills
- Ability to work effectively individually and in a team environment with clients and employees
- Ability to assess problems independently and quickly, including knowing when to seek additional expertise
- Ability to meet employer attendance and hybrid remote work policy requirements, including time zone requirements
- Ability to type quickly and accurately for prolonged periods, sit for prolonged periods, and lift up to 20 lbs
- Valid driver’s license and ability to travel locally; occasional travel to other offices
- Reasoning ability: research and analyze facts, identify issues, and recommend solutions
- Trustworthy, dependable, and team-oriented; acts with integrity in challenging situations
- Ability to handle confidential, proprietary, and highly sensitive information (including health records, client financials, and personal data) with honesty and integrity
Schedule & Location
- Location: Concord, CA (hybrid)
- Remote: may be remote if employee meets technical requirements and resides in an operating state: AZ, CA, FL, ID, IL, MA, NV, NJ, NY, NC, OR, TX, or VA
- Onsite: employees living within 26 miles of an Athens office (Concord, CA; Orange, CA; Lake Mary, FL; San Antonio, TX) are required to work onsite once per week on a day designated by their supervisor between Tuesday and Thursday
- Office hours: Monday through Friday, 7:30 a.m. to 5:30 p.m. local time
- Standard schedule: Monday through Friday, 37.5 hours per week, start time no later than 9:00 a.m. local time
Salary
- USD 120,000 - 160,000 per year
Benefits
- Medical, Vision, Dental
- Life and AD&D
- Long Term Care
- Critical Care, Accidental, Hospital Indemnity
- HSA & FSA options
- 401k (and Roth)
- Company-Paid STD & LTD
Technology Stack
- DataDog SEIM, CrowdStrike EDR, Duo, Mimecast
- Qualys
- Duo MFA, Cloudflare Zero Trust, OKTA/Entra ID
- Secure FTP
- Microsoft Windows 10 and 11, Office 365, M365
- Data Loss Prevention (DLP), SIMS/CXP claims platforms
- SOC 1, SOC 2
- PowerShell, Python
- BitLocker, InTune, Zoom, AWS IAM policies
Apply
- Submit resume and application: athensadmin.com/careers/job-openings
- Cover letter is optional
- All applications are reviewed by the in-house Corporate Recruitment team
- Qualified applicants with arrest or conviction records will be considered in accordance with the Los Angeles Fair Chance Ordinance and the California Fair Chance Act