IT Security Analyst
Listed on 2026-09-10
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.
IT Security AnalystFull Time Tampa, FL, US
Role Summary
The IT Security Analyst supports the Firm’s day-to-day security operations, phishing response, vulnerability management, endpoint protection, cloud security review, physical security administration, incident response support, evidence collection, and security reporting activities.
This role performs first-level security analysis, documents findings, coordinates remediation with IT Operations, and escalates high-risk issues to the Firm’s managed service provider IT Security team and internal IT/Security leadership as appropriate.
This position is intended for an entry- to mid-level security professional who can follow defined procedures, perform structured analysis, maintain audit-ready evidence, and support recurring operational security tasks.
At ALAW, we’re committed to supporting the well-being and success of our team. We offer a comprehensive benefits package that includes:
- Medical, dental, and vision Insurance
- 401(k) plan with company match
- Company-paid life insurance, short-term and long-term disability coverage
- Generous PTO and paid holidays
- Employee recognition programs
- Wellness resources and employee assistance program (EAP)
- Employee referral program with bonus incentives
Key Responsibilities
- Monitor and triage security alerts involving suspicious sign-ins, malware, phishing, endpoint activity, email threats, administrative changes, and unusual network or cloud activity.
- Investigate user-reported phishing messages, analyze relevant indicators, identify similar messages, and coordinate quarantine or removal when appropriate.
- Support identity and access reviews, including inactive, vendor, and privileged accounts; MFA enrollment;
Conditional Access coverage; suspicious sign-ins; and mailbox forwarding or inbox rules. - Monitor endpoint security coverage and compliance, identify devices with missing or outdated security tools, and coordinate remediation with IT Operations.
- Review vulnerability and patch-compliance reports, prioritize findings based on risk, create remediation tickets, and validate completion through rescans or supporting evidence.
- Review Microsoft 365, Azure, and AWS security findings, including external sharing, guest access, configuration exceptions, logging, encryption, and least-privilege controls.
- Assist with security awareness training, phishing simulations, employee follow-up, and reporting on participation and phishing trends.
- Support incident response by collecting evidence, documenting timelines, assisting with approved containment activities, and tracking action items through closure.
- Maintain organized security records and assist with evidence collection for audits, client questionnaires, compliance reviews, and governance reporting.
- Support physical security administration and periodic access reviews for systems such as Brivo and ADT.
- Prepare concise security updates, alert summaries, incident documentation, and compliance reports for leadership review.
Preferred Qualifications
- Experience with Microsoft Sentinel, Microsoft Defender, Entra , Intune, Proofpoint, Sentinel One, Nessus, Fortinet, DNSFilter, Brivo, ADT, or comparable technologies.
- Familiarity with security frameworks or regulatory standards such as NIST CSF, CIS Controls, SOC 2, or the GLBA Safeguards Rule.
- Experience supporting phishing investigations, vulnerability remediation, access reviews, endpoint security, cloud security, or physical access administration.
- Security+, CySA+, SC-200, AZ-900, MS-900, or a comparable certification is preferred but not required.
Requirements
- One to three years of experience in cybersecurity, IT support, security operations, infrastructure support, audit support, or a related technical role.
- Working knowledge of Windows endpoints, Microsoft 365, phishing analysis, vulnerability management, security alerts, and ticketing workflows.
- Ability to review logs and technical findings, follow established procedures, document conclusions, and escalate concerns appropriately.
- Strong attention to detail and organizational skills, particularly when maintaining evidence for audit, compliance, and governance purposes.
- Effective written and verbal communication skills.
Scope of Authority
The IT Security Analyst performs initial analysis, documents findings, coordinates routine remediation, and escalates high-risk or…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).