Security Operations Analyst
Listed on 2026-08-29
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
At Subway, we are not standing still. We are building.
This is a business focused on what matters most: growing franchisee profitability, strengthening our brand and creating long-term value. The people who thrive here are the ones who want to make a real impact.
You will not just do the work. You will shape it.
We move fast. We think like owners. We make decisions that matter. We hold ourselves to a high standard because what we do directly impacts thousands of franchisees around the world.
If you bring energy, accountability and a bias for action, you will fit right in.
We take the work seriously, but we also know the best results come from teams that support each other, celebrate wins and show up ready to build something better every day.
This is your chance to be part of what’s next.
Position OverviewThe Security Operations Analyst operates the identity security and access-governance layer of Subway's Cybersecurity program. Sitting within the Identity & Access Management team, this role is the operational bridge between IAM and the Detect & Respond function — identity-first in day-to-day work, but grounded in general security operations center (SOC) practice. The Analyst runs access-governance controls that keep the enterprise least-privileged and audit-ready, operates identity threat detection and response using Crowd Strike Falcon Identity Protection, and investigates access anomalies in Falcon Next-Gen SIEM.
This role is designed as a genuine growth seat and launchpad into the broader Cybersecurity program, with development paths toward senior identity security, threat detection engineering, security engineering, or IAM engineering.
- Operate identity threat detection and response with Crowd Strike Falcon Identity Protection: monitor and triage identity-based detections, assess risk and severity, apply risk-based policy actions within defined guardrails, and escalated confirmed threats to the Detect & Respond team; investigate access anomalies end to end using identity telemetry in Crowd Strike Falcon Next-Gen SIEM — authentication events, MFA activity, privileged-account usage, and provisioning changes.
- Support tuning of identity detections, dashboards, and alert quality with the Detect & Respond team; participate in incident response for identity-related incidents including account compromise, credential abuse, and unauthorized access — executing containment actions such as session revocation, credential reset, and access suspension under team runbooks; monitor privileged and service-account activity for anomalous behavior and policy violations.
- Run Okta Identity Governance access certification campaigns end to end: campaign setup and scoping, reviewer coordination and follow-up, revocation execution, exception tracking, and production of audit-ready evidence for PCI-DSS 4.0 and cyber-insurance programs; support access request workflow operations including approval-path exceptions and escalations outside self-service.
- Apply least-privilege principles in daily work: flag over-broad group and role assignments, validate time-bound privileged access, and drive cleanup of dormant, orphaned, or over-privileged accounts; produce and maintain access evidence for internal and external audits and compliance programs.
- Work down the standing identity-risk case backlog: investigate, prioritize, remediate, and close findings such as dormant accounts, stale privileged access, weak authentication paths, and unowned service accounts; track remediation against service-level targets and report progress and systemic patterns to Cybersecurity leadership.
- Handle Tier-2/3 identity escalations remaining after automation — complex access requests, provisioning exceptions, and onboarding/offboarding edge cases; manage assigned tickets in Service Now meeting SLA targets; support access-related requests from investigations, legal holds, and HR partners with appropriate discretion and documentation; participate in the team's shared on-call rotation.
- Author and maintain runbooks, triage guides, and knowledge-base articles for identity security operations and certification processes; track and report on…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).