
IT Security Analyst - Day Shift
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in Philippines.
• Safeguard a Microsoft-based environment globally through security monitoring, incident response, identity and access management, vulnerability management, and ongoing enhancement of cyber security measures.
• Evaluate and investigate alerts from Microsoft Defender and escalations from Arctic Wolf SOC, including phishing, malware, suspicious sign-ins, and endpoint activities.
• Facilitate containment, eradication, and recovery efforts in collaboration with Arctic Wolf and internal IT teams, ensuring incident documentation and escalating significant incidents as necessary.
• Assist in Microsoft Defender endpoint protection, bolster Microsoft 365 security posture, implement security hardening, and enhance endpoint detection and response.
• Assess vulnerabilities based on exploitability, exposure, and business importance, and monitor remediation until closure.
• Aid in establishing security baselines and ensuring patch compliance using Microsoft management tools and NinjaOne.
• Analyze and fortify Active Directory and Microsoft Entra ID security, including MFA, Conditional Access, least-privilege access, and periodic access reviews.
• Examine privileged accounts, role-based access, service accounts, and application permissions while facilitating identity-related threat responses.
• Contribute to the enhancement of Essential Eight controls, maintain evidence of remediation actions, and verify implementation with control owners.
• Assist with security risk assessments, policy reviews, and audits, converting control gaps into prioritized actions.
• Document and manage security incidents, requests, problems, and changes in Freshservice according to ITSM processes.
• Conduct root cause analysis, maintain response playbooks and knowledge articles, and support ongoing improvement of recurring security challenges.
• Provide reports on incident response, remediation aging, Defender coverage, identity risks, and Essential Eight progress.
• Collaborate with service desk, infrastructure, application, and business teams to address security concerns while ensuring operational continuity.
• Offer practical security advice and assist in phishing awareness and user education initiatives.
• Support incident transitions across various time zones and engage in after-hours incident response arrangements as necessary.
• Carry out other duties pertinent to the position as they arise.
• A minimum of 3 years of relevant experience in cyber security operations, incident response, or an IT role with significant hands-on security responsibilities is required.
• Proven experience in securing Microsoft enterprise environments and investigating threats using Microsoft Defender for Endpoint or similar EDR tools is essential.
• Direct experience with Active Directory, Microsoft Entra ID, MFA, Conditional Access, and access reviews is crucial.
• Familiarity with a SIEM and managed SOC or MDR provider is essential; experience with Arctic Wolf is highly regarded.
• Knowledge of Essential Eight implementation or assessment and ITIL-aligned IT service management processes is vital; experience with Freshservice is preferred.
• Strong understanding of Microsoft 365 and Windows security, encompassing Exchange Online, Windows endpoints, and Windows Server, is fundamental.
• Experience in log analysis and threat investigation, including common attack techniques, phishing, and ransomware, is essential.
• Solid understanding of networking principles, including TCP/IP, DNS, firewalls, and VPNs, is necessary.
• Proficiency in PowerShell or Kusto Query Language (KQL) for investigation and automation is desirable.
• Familiarity with Intune, Defender for Office 365, and Defender for Identity is a plus.
• Experience within global or multi-site operations is advantageous.
• Relevant qualifications in cyber security, information technology, or a related field, or equivalent practical experience, are required.
• Relevant Microsoft security or identity certifications, CompTIA Security+, ITIL Foundation certification, or Essential Eight assessment training are preferred.
• Strong analytical judgment, problem-solving skills, and clear written and verbal communication abilities are crucial.
• The capacity to prioritize competing incidents and manage sensitive information with discretion and accountability is essential.
• Work from home
• Mon - Fri: 9:00 AM – 6:00 PM AEST/AEDT (adjustments will be made for daylight saving time)
• HMO with 2 free dependents and medical reimbursements
• Government-mandated benefits
• Opportunities to collaborate with leading companies in Australia and beyond
• Training programs for career advancement
• Engaging company outings, team activities, and wellness sessions
• Supportive and inclusive culture
• Dedicated managers focused on your growth and success
• Competitive compensation and benefits
• Additional entitlements
• Structured career development programs
• People-first culture prioritizing stability, growth, and genuine care
• Equal opportunity and inclusive workplace
Cooperativa Central Ailos
NBCUniversal
BDR Solutions LLC
Sigma Software Group
Get handpicked remote jobs straight to your inbox weekly.