Location: Sacramento, CA
Job Type: Full-Time
Department: Information Systems / Cybersecurity
Reports To: Senior Cybersecurity Engineer
Position Summary
The Security Analyst I is an entry-level cybersecurity position responsible for supporting the day-to-day operation of the company's information security program. Working under the direction of senior cybersecurity staff, this position assists with security alert monitoring, vulnerability and patch management oversight, software security reviews, security configuration monitoring, audit support, and security reporting.
This role is designed for an individual who has a foundational understanding of information technology and cybersecurity and is interested in developing a career in security operations. The Security Analyst I is not expected to independently design or engineer security solutions. The position works closely with senior security personnel, Information Systems teams, our Managed Service Provider (MSP), Managed Security Service Provider (MSSP), and other technology partners to ensure security activities are completed and appropriately documented.
Key Responsibilities
Security Monitoring & Alert Review
- Review and triage security alerts generated by security monitoring platforms, endpoint security tools, email security systems, and other security technologies.
- Perform initial investigation and gather relevant information related to security events.
- Follow established procedures for documenting, escalating, and tracking potential security incidents.
- Work with senior cybersecurity staff and security service providers to support incident investigation and response activities.
- Maintain appropriate documentation and evidence related to security events and incidents.
Vulnerability & Patch Management
- Assist with the company's vulnerability and patch management program.
- Review vulnerability and patching reports and track identified vulnerabilities through remediation.
- Coordinate with the MSP and internal technology teams to ensure required patches and security updates are completed within established timelines.
- Follow up on outstanding or failed patching activities and escalate exceptions when necessary.
- Assist with validating and documenting remediation activities.
- Prepare regular vulnerability and patch compliance reporting for senior security staff.
Software & Technology Security Reviews
- Assist with the security review of new software, applications, browser extensions, and other technologies requested for use within the company.
- Gather required security and vendor information using established review processes and checklists.
- Review basic security considerations such as data access, authentication, permissions, software source, and requested system privileges.
- Identify requests requiring additional technical or security review and escalate them to senior cybersecurity staff.
- Maintain documentation of software reviews, approvals, exceptions, and security requirements.
Endpoint, System & Security Configuration Monitoring
- Assist with monitoring security configurations across company-managed endpoints, systems, and security platforms.
- Review security dashboards and reports to identify devices or systems that are missing required security controls or are not meeting established security standards.
- Coordinate remediation activities with the appropriate internal team or service provider.
- Assist with tracking security configuration exceptions and corrective actions.
- Support senior security personnel with security configuration reviews and compliance reporting.
Security Operations & Administration
- Perform routine administrative activities within approved security tools and platforms under established procedures.
- Assist with maintaining security policies, procedures, standards, operational documentation, and security records.
- Generate routine security metrics, dashboards, and management reports.
- Assist with tracking security findings, remediation activities, exceptions, and open action items.
- Support the continuous improvement of cybersecurity processes and procedures.
Identity & Access Security
- Assist with periodic user access and security reviews.
- Support reviews of privileged accounts, inactive accounts, access exceptions, and other identity-related security controls.
- Assist with gathering documentation and evidence related to identity and access management controls.
- Escalate identified access concerns or exceptions to senior cybersecurity personnel.
Security Awareness
- Assist with cybersecurity awareness and training initiatives.
- Support phishing simulation and security awareness activities.
- Help develop and distribute security communications and educational materials.
- Assist employees with basic security questions and reinforce established security practices and policies.
Disaster Recovery & Business Continuity
- Assist with maintaining cybersecurity-related Disaster Recovery (DR) and Business Continuity Planning (BCP) documentation.
- Support preparation and coordination of DR and BCP exercises.
- Document testing results, identified issues, and follow-up activities.
- Assist with tracking remediation items resulting from exercises and tests.
Audit & Compliance Support
- Assist the cybersecurity team with responses to regulatory, state, investor, customer, and internal audit requests.
- Gather documentation, reports, screenshots, logs, and other evidence required to demonstrate security controls.
- Maintain organized records of audit evidence and security documentation.
- Assist with tracking security findings and remediation activities through completion.
- Support compliance activities associated with the company's cybersecurity framework and regulatory obligations.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field or equivalent education, training, certifications, or relevant technical experience.
- Approximately 0–2 years of experience in cybersecurity, information technology, help desk, systems administration, network support, or another related technical field.
- Foundational understanding of cybersecurity concepts, including:
- Endpoint security
- Malware and phishing
- Authentication and access controls
- Vulnerability and patch management
- Basic networking concepts
- Security monitoring and incident escalation
- Basic familiarity with Windows environments and Microsoft technologies.
- Ability to review technical information, identify potential issues, and follow established escalation procedures.
- Strong attention to detail and organizational skills.
- Ability to maintain accurate documentation and track multiple security activities through completion.
- Strong written and verbal communication skills.
- Ability and willingness to learn new cybersecurity technologies, processes, and concepts.
- Ability to work collaboratively with senior technical staff, internal technology teams, and third-party service providers.
Preferred Qualifications
The following qualifications are helpful but not required:
- CompTIA Security+, Network+, or similar entry-level technology/security certification.
- Internship, coursework, lab, or professional experience involving cybersecurity or IT operations.
- Familiarity with SIEM, endpoint detection and response (EDR), vulnerability management, or security monitoring technologies.
- Familiarity with Microsoft Azure, Microsoft 365, Entra ID, or Microsoft Intune.
- Exposure to Proofpoint or other email security technologies.
- Exposure to SentinelOne or other endpoint detection and response platforms.
- Basic understanding of the NIST Cybersecurity Framework (NIST CSF), CIS Controls, or similar cybersecurity frameworks.
- Basic familiarity with PowerShell, Python, or other scripting/automation technologies.
- Experience working with an MSP, MSSP, SOC, help desk, or other technology service provider.
Knowledge & Skills
Successful candidates should demonstrate:
- Curiosity and a desire to develop a career in cybersecurity.
- Good analytical and troubleshooting skills.
- Strong attention to detail.
- Ability to recognize when an issue requires escalation.
- Ability to follow established processes while identifying opportunities for improvement.
- Ability to communicate technical information clearly to both technical and non-technical audiences.
- Strong organizational and follow-through skills.
- Sound judgment when handling confidential or sensitive information.
Career Development
The Security Analyst I position is intended as an entry point into the company's cybersecurity career path. The employee will receive guidance and mentoring from senior cybersecurity personnel while developing deeper expertise in security operations, vulnerability management, incident response, cloud security, security architecture, and cybersecurity risk management.
As experience and technical capabilities develop, the position may progress into more advanced Security Analyst or Cybersecurity Engineer responsibilities.
- Locations
- Sacramento, California, United States
- Education
- bachelor degree
- Experience
- No experience required