Security Analyst
Listed on 2026-09-12
-
IT/Tech
Cybersecurity
If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.
Security AnalystFull Time Regular Non-Manager HYBRID NON-MNGR Atlanta, GA, US
2 days ago Requisition
Please do not respond to direct messages with your personal information. All job applications and your sensitive, personal information should only be submitted via our official job platform.
Job Title:
Information Security Analyst (hybrid- onsite Monday
- Thursday)
Location: US-GA-Atlanta (Sandy Springs)
FLSA :
Exempt
#LI-Hybrid
Job Overview :
Safeguard is seeking an Information Security Analyst to support the day-to-day operation and improvement of our security program. This is a hands‑on, operationally focused role: you will triage and resolve security requests, serve as a first responder for potential security incidents, administer our physical access control and surveillance systems, and operate the platforms that protect our endpoints, network traffic, data, and infrastructure.
The role sits at the intersection of several teams. You will partner regularly with infrastructure, application, and end-user support groups to make sure security requirements are understood, implemented, and sustained — not just documented. Success in this position looks like fewer recurring issues, cleaner detection signal, faster response, and stronger working relationships with the teams whose systems you help secure.
Safeguard is an AI‑first organization. We expect our security team to use AI assistants as part of their normal working rhythm: summarizing and correlating log data, drafting and refining detection logic, accelerating investigation write‑ups, researching threats and techniques, and automating repetitive queue work. You do not need to be an AI specialist, but you should be genuinely comfortable working alongside these tools and interested in getting better at it.
Job Responsibilities:
- Own an assigned queue of security requests, access reviews, escalations, and remediation tasks, driving each to documented completion within defined service levels.
- Maintain clear, auditable records of actions taken, decisions made, and evidence collected.
- Identify recurring ticket drivers and recommend automation, configuration changes, or process improvements to reduce them.
- Serve as first‑level responder for security alerts and reported events: validate, triage, contain where appropriate, and elevate to senior staff with a clear written handoff.
- Perform initial investigation using endpoint, network, identity, and log telemetry to determine scope and impact.
- Contribute to post‑incident documentation, root cause analysis, and follow‑up remediation tracking.
- Participate in an on‑call or after‑hours escalation rotation as required.
- Operate and maintain the organization's core security tooling, including:
- Endpoint detection and response (EDR/XDR) — policy configuration, agent health and coverage, detection triage.
- Cloud‑delivered secure web and network access (SSE/SWG/ZTNA) — policy management, traffic inspection rules, and access enforcement.
- Data security and access governance — monitoring sensitive data access, flagging anomalous activity, supporting permissions remediation and stale‑data cleanup.
- Vulnerability management — scan configuration and scheduling, result validation, risk‑based prioritization, and remediation tracking with system owners.
- Monitor platform health, licensing, agent/sensor coverage gaps, and upgrade cycles.
- Tune and maintain detection content in the organization's SIEM platform: refine correlation and detection rules, reduce false positives, and improve alert fidelity and context.
- Onboard and validate new log sources; verify parsing, field normalization,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).