Security Analyst II
Listed on 2026-05-17
-
IT/Tech
Cybersecurity
Description
This role is onsite in our St. Cloud office.
Why North Risk PartnersAre you interested in doing work that matters everyday with an organization intentional about building and living out a values-driven team culture? North Risk Partners is a fast-growing firm dedicated to serving the insurance and risk management needs of businesses and individuals. We provide expertise in Commercial Lines, Employee & Individual Benefits, Personal Lines, Surety, Claims, and Risk Management. Our team consists of over 450 employees working in over 30 locations across five states, including Minnesota, Iowa, North Dakota, South Dakota, and Nebraska.
At North Risk Partners, our #oneTEAM lives out #one MISSION: to provide extraordinary #service to our clients, to each other, and to our communities while living out our core values each day. Our team environments are designed to provide #oneTEAM members opportunity to focus on collaborative relationships (clients and team), variety from day‑to‑day, constant learning, and the tools and resources to learn and grow at work and in life.
Type
Full‑time
Job SummaryThe Security Analyst II plays a key role in operating, improving, and maturing North Risk’s security program. This role focuses on detection, investigation, vulnerability management, access governance, endpoint and email security, and compliance support aligned to NIST CSF 2.0, NY DFS, and HIPAA requirements. The Security Analyst II serves as a hands‑on, technical contributor responsible for daily security operations, incident support, control engineering, and continuous improvement of security tooling, policies, and standards.
This role reports to the Director of Infrastructure & Security and offers growth opportunities as the security program matures.
Detection, Investigation, and Response
- Perform security alert triage across endpoint, email, identity, and cloud security platforms
- Investigate suspicious activity, validate threats, and support containment and remediation
- Tune detection logic and alerting rules to reduce false positives and improve signal quality
- Document investigations, findings, and outcomes with clear, auditable notes
- Provide Tier 1‑2 incident response support, including evidence collection and timeline development
- Triage and classify reported phishing emails using automated and manual analysis tools; communicate findings to end users
Access Governance
- Conduct regular user and privileged access reviews to support least privilege principles
- Identify and remediate access risks across Entra , groups, and role assignments
- Partner with identity and infrastructure teams on access governance improvements
- Support Conditional Access policy review, testing, and troubleshooting in coordination with identity and infrastructure teams
Tooling and Endpoint Security
- Administer and support Microsoft Defender, Intune, email security, and related tools
- Validate endpoint compliance, protection coverage, and configuration alignment
- Support tool configuration changes following change control practices
Vulnerability and Compliance
- Define KPIs & success metrics (e.g., model accuracy, adoption, cycle time, business impact, risk/incident rate)
- Oversee observability: data drift, model decay, cost tracking, usage analytics, and incident response processes
- Manage budgets, vendor relationships, and licensing for AI platforms and tools
Security Engineering and Improvement
- Improve technical security controls across identity, endpoint, and email systems
- Develop and maintain security hardening standards and baseline configurations
- Partner with infrastructure, network, and cloud teams on secure design initiatives
- Identify gaps, recommended enhancements, and help drive security maturity
- Develop and maintain scripts and automations to improve efficiency of security operations tasks
- Support security assessments and integration activities for acquired agencies, including access provisioning, endpoint onboarding, and baseline validation
- A combination of education and experience generally attained through an associate’s degree (in Information Technology, Cybersecurity, Networking, or related field strongly…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).