
IT Security Analyst
CarringtonCrisp
full-time
Posted on:
Location Type: Remote
Location: United States
Visit company websiteExplore more
Salary
💰 $90,000 - $120,000 per year
Tech Stack
About the role
- Responsible for cybersecurity, data security, governance, and compliance across IT, cloud, applications, and enterprise data platforms.
- Has core security engineering responsibilities with advanced data protection, compliance, and Microsoft Purview capabilities.
- Protects organizational systems and information assets against unauthorized access, disclosure, modification, or destruction, while ensuring compliance with regulatory, legal, and contractual obligations.
- Perform all duties in accordance with the company’s policies and procedures, all US state and federal laws and regulations, wherein the company operates.
Requirements
- Bachelor’s degree in Computer Science, Information Technology, Engineering, or related field, or equivalent experience.
- Minimum of 3–5 years’ experience in information security, cybersecurity engineering, or data security.
- Manage and monitor enterprise security controls including network, cloud, application, and endpoint security.
- Design, implement, and maintain data protection controls including Data Loss Prevention (DLP), information protection, and encryption.
- Implement and manage Microsoft Purview solutions including Information Protection, DLP, Insider Risk Management, eDiscovery, Audit, Data Governance, and Data Security Posture Management.
- Conduct security monitoring, investigations, and incident response in coordination with SOC teams.
- Manage firewall, CASB, web filtering, EDR, IDS/IPS, and vulnerability management technologies.
- Document and maintain security policies, standards, procedures, and technical playbooks.
- Participate in system access reviews, compliance audits, and evidence collection for internal and external auditors.
- Provide security guidance for new projects, applications, AI solutions, and non‑standard IT requests.
- Collaborate with Legal, HR, Risk, and business teams on insider risk, investigations, and regulatory matters.
- Remain current on emerging security threats, regulatory requirements, and security technologies.
- Strong knowledge of IT cybersecurity principles, network and application security, and data protection controls.
- Hands‑on experience with Microsoft security platforms including Microsoft Purview, Defender, and Azure security controls.
- Understanding of regulatory frameworks such as NIST, ISO 27001/27002, CIS, FINRA, and SEC.
- Experience with SIEM, audit logging, forensic analysis, and security investigations.
- Strong analytical, organizational, and problem‑solving skills.
- Excellent written, verbal, and presentation communication skills.
- Ability to assess business risk and apply appropriate security controls.
- Professionalism, integrity, confidentiality, and ability to work under pressure.
Benefits
- Comprehensive healthcare plans for you and your family.
- Plus, a discretionary 401(k) match of 50% of the first 4% of pay contributed.
- Access to several fitness, restaurant, retail (and more!) discounts through our employee portal.
- Customized training programs to help you advance your career.
- Employee referral bonuses so you’ll get paid to help Carrington and Vylla grow.
- Educational Reimbursement.
- Carrington Charitable Foundation contributes to the community through causes that reflect the interests of Carrington Associates.
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
cybersecuritydata securitysecurity engineeringdata protectionData Loss Prevention (DLP)encryptionincident responsevulnerability managementforensic analysissecurity monitoring
Soft Skills
analytical skillsorganizational skillsproblem-solving skillscommunication skillsprofessionalismintegrityconfidentialityability to work under pressure
Certifications
Bachelor’s degree in Computer ScienceBachelor’s degree in Information TechnologyBachelor’s degree in EngineeringNISTISO 27001ISO 27002CISFINRASEC