IT Security Analyst
Listed on 2026-08-03
-
IT/Tech
Cybersecurity
About the Company
Corporate Imaging Concepts (CIC) is a branded merchandise and e-commerce company headquartered in Northbrook, Illinois, with a full warehouse and operations facility in Alpharetta, Georgia. CIC builds and runs online storefronts and fulfillment programs for enterprise clients, which means the company manages payment flows, customer data, and the security expectations that come with serving large organizations.
About the RoleThe IT Security Analyst owns security as a discipline for CIC, including security posture, compliance, vendor risk, and incident response. This is a hands-on individual contributor role with broad ownership and visible impact. The role partners closely with the Infrastructure Manager, who owns networks, servers, and endpoints as systems, while this position owns the security controls, policies, and compliance obligations that sit on top of them and the role would be reporting directly to IT leadership.
CIC has a small IT team, so this role requires comfort with shared team responsibilities. Security is the primary mandate, but the IT Security Analyst should also expect to support ticket management and hands-on infrastructure support alongside the Infrastructure Manager. The right candidate values variety, pragmatism, and the opportunity to secure the full environment of a growing company without overbuilding an enterprise-scale security program.
Security Posture & Controls
- Own day-to-day security posture, including identity and access controls such as MFA, conditional access, and privileged accounts.
- Support endpoint protection, email security, and patching priorities in partnership with Infrastructure.
- Monitor and triage alerts using appropriately scaled tooling and recommend where tooling should or should not grow.
- Advise leadership on security risk in clear, prioritized terms, including what matters now, what can wait, and what it costs.
- Own client-facing security compliance, including security questionnaires and vendor risk assessments.
- Maintain security documentation and policies that are practical, current, and appropriate for CIC's size and environment.
- Support payment cards, PCI-related obligations with CIC's processing partners.
- Run vendor security reviews for the platforms and integrations CIC relies on.
- Own the incident response process, including first-line triage, coordination during events, and post-incident follow-through.
- Run right-sized security awareness activities, including phishing simulation, onboarding training, and practical guidance people can follow.
- Work on the support queue by triaging, resolving, and managing user support tickets as part of the IT team's shared rotation.
- Provide hands-on infrastructure support alongside the Infrastructure Manager, including endpoints, accounts, Microsoft 365 administration, and day-to-day systems work as needed.
- 3-6 years of hands-on security experience in an analyst or engineer role, with recent personal experience deploying, tuning, and maintaining security controls.
- Practical depth in Microsoft 365 / Entra , endpoint protection, and email security.
- Experience answering client security questionnaires or completing vendor risk assessments, including the ability to triage large, detailed assessments against deadlines.
- Working familiarity with PCI-DSS concepts; experience in an e-commerce, retail, or SaaS environment is a strong plus.
- Strong judgment to operate as a one-person security function, including prioritizing strategically, deferring accurately, and communicating clearly.
- Genuine comfort with generalist IT work, including support tickets and infrastructure tasks.
- Relevant certifications such as Security+, CySA+, or SSCP is welcome; senior certifications are not required.
- MSP or small-team IT background with experience managing breadth, ticket discipline, and shifting priorities.
- SOC 2 or similar attestation exposure, either client-side or audit-side.
- Experience with Azure security tooling and scripting such as Power Shell or Python for automation.
- Experience working alongside SAP or other ERP environments.
This is not a management role with direct reports, a pure-security seat, or a SOC shift position. Part of the week will include support tickets and infrastructure work because CIC operates with a small IT team. The opportunity is to serve as the security function for a growing company with real ownership from day one and room for the role to grow as the business grows.
WhyThis Role Matters
The IT Security Analyst helps protect CIC's people, clients, data, systems, and brand reputation. This role brings practical structure to security and compliance while staying grounded in the realities of a hands-on, fast-moving business.
Location and payHybrid from our Northbrook, IL headquarters or our Alpharetta, GA warehouse and operations facility - regular onsite…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).