Info Security Specialist
Quick Summary
Information Security Specialist We are seeking an Information Security Specialist to help operate, strengthen, and continuously improve our internal information security program. This is a hands-on,
We are seeking an Information Security Specialist to help operate, strengthen, and continuously improve our internal information security program.
This is a hands-on, cross-functional role for a security professional who enjoys working across multiple disciplines. You will contribute to security operations, identity and access management, endpoint and network security, vulnerability management, third-party risk, compliance, and employee security awareness.
Working closely with IT and business teams, you will help reduce risk, strengthen security controls, and protect the organization while supporting a productive and practical working environment.
This position is well suited to someone with at least three years of broad IT and information security experience who is ready to take greater ownership and grow into a senior internal security role.
Responsibilities
~2 min read- →
Monitor and respond to alerts from SIEM, EDR, identity, email security, and other security platforms.
- →
Investigate and triage potential security incidents; escalate issues as appropriate; and assist with containment, remediation, recovery, and post-incident reviews.
- →
Administer identity and access management controls, including SSO, MFA, directory services, privileged access, and employee onboarding, transfer, and offboarding processes.
- →
Conduct periodic access reviews to identify and address stale accounts, excessive permissions, and inappropriate entitlements.
- →
Maintain and improve endpoint security controls, including EDR coverage, patch compliance, secure configuration baselines, disk encryption, and device health.
- →
Review firewall rules, VPN access, network segmentation, and related configurations to identify unnecessary access and security gaps.
- →
Support the vulnerability management lifecycle by coordinating scans, validating findings, prioritizing risk, partnering with system owners on remediation, and reporting program metrics.
- →
Contribute to compliance and assurance activities, including policy maintenance, evidence collection, control testing, customer security questionnaires, and audit preparation.
- →
Conduct third-party security reviews, document vendor risks, and track remediation plans and approved risk acceptances.
- →
Develop and deliver security awareness initiatives, including phishing simulations, onboarding training, employee communications, and practical security guidance.
- →
Serve as a point of contact for employees reporting suspicious messages, lost or stolen devices, access concerns, and other security-related issues.
- →
Create and maintain security standards, procedures, runbooks, diagrams, and operational documentation.
- →
Identify and implement opportunities to automate repetitive security and IT processes through scripting and workflow tools.
- →
Participate in the security on-call rotation and assist with urgent incidents outside normal business hours when necessary.
Requirements
~1 min read-
At least three years of professional experience in information security, IT operations, infrastructure, systems administration, or a related field.
-
Hands-on experience across multiple security domains, such as security operations, identity and access management, endpoint security, vulnerability management, network security, or compliance.
-
Working knowledge of security technologies such as SIEM, EDR, vulnerability scanning platforms, email security tools, and identity providers.
-
Experience administering an identity platform such as Microsoft Entra ID, Okta, or a comparable solution.
-
Familiarity with at least one major cloud platform, such as Microsoft Azure, Amazon Web Services, or Google Cloud Platform.
-
Strong understanding of networking, operating systems, authentication, authorization, and common security controls.
-
Experience using PowerShell, Python, Bash, or another scripting language for automation, reporting, or troubleshooting.
-
Strong written and verbal communication skills, including the ability to explain security risks and requirements to nontechnical audiences.
-
Ability to work independently, manage competing priorities, and collaborate effectively with technical and business teams.
-
A relevant industry certification, such as CompTIA Security+, CySA+, CISSP, CISM, CISA, CRISC, GIAC, or an equivalent credential.
-
Willingness to participate in an on-call rotation.
During your first year, you will be expected to:
-
Improve visibility into security events and strengthen alert response and incident-management processes.
-
Expand endpoint, identity, patching, and vulnerability-management coverage.
-
Strengthen access reviews and employee lifecycle controls.
-
Improve audit readiness and the quality, consistency, and accessibility of security documentation.
-
Identify and implement practical opportunities to reduce risk through automation and process improvement.
Location & Eligibility
Listing Details
- Posted
- September 30, 2026
- First seen
- September 30, 2026
- Last seen
- September 30, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 57%
- Scored at
- September 30, 2026
Signal breakdown
Similar Security Specialist jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.