IT Security Operations Analyst
# IT Security Operations Analyst **Ballast Services** · Oldsmar, FL · `On-site` 🕒 **Статус:** *Опубликовано: сегодня* · *Источник: Indeed* --- ### About the Role Position Summary Ballast is an industry leading cybersecurity services organization based in Tampa Bay Florida. Our business continues to evolve, and we are currently seeking a Security Operations technician to join our growing cybersecurity managed services team. This pivotal role serves as a bridge between Service Desk (TOC), Security Operations (SOC), and Engineering teams, ensuring ITIL based procedures are executed efficiently. The role also serves as a control point for critical customer communications The ideal candidate has strong Windows workstation and server administration skills, enjoys troubleshooting technical issues, and has a genuine interest in building a career in cybersecurity. This individual will be responsible for reviewing security alerts, validating vulnerabilities, supporting patch management efforts, troubleshooting endpoint issues, and assisting with customer infrastructure operations. This is an excellent opportunity for a senior service desk technical lead or systems administrator looking to desiring to expand into cybersecurity. The position provides exposure to enterprise environments in multiple industries with extreme focus on security operations involving hybrid and cloud platforms, endpoints and network technologies. Primary Responsibilities Security Operations - Review and triage endpoint detection and response (EDR) alerts and security incidents. - Investigate suspicious and malicious activity on workstations and servers. - Validate threat remediation activities and document findings. - Monitor endpoint security agent health and coverage. - Assist with incident investigations and containment activities. - Escalate confirmed security events to senior security engineers. Vulnerability Management - Review vulnerability scan results from security platforms. - Validate findings and eliminate false positives. - Research security vulnerabilities and associated business risks. - Track remediation progress and follow up with internal teams and customers. - Assist with monthly vulnerability reporting and customer reviews. - Support vulnerability remediation efforts across Windows, Linux, and cloud environments. Patch Management - Monitor patch compliance across customer environments. - Investigate failed Windows, Office, and third-party application updates. - Assist with deployment and validation of security patches. - Troubleshoot update-related issues using Windows Update, RMM, and endpoint management tools. - Support monthly patch management cycles and maintenance windows. Endpoint Support - Troubleshoot advanced laptop and desktop issues. - Resolve operating system, performance, and application problems. - Diagnose connectivity, authentication, and Microsoft 365 issues. - Support endpoint management and security tooling. Server & Infrastructure Operations - Support Windows Server administration and troubleshooting. - Review event logs and system alerts to identify operational issues. - Support monitoring, backup, and maintenance activities. - Participate in scheduled maintenance windows. - Assist with cloud-based infrastructure in Azure and AWS environments. Security & Operations Documentation - Document investigations, findings, and remediation activities. - Create and update operational runbooks and procedures. - Maintain customer asset, vulnerability, and remediation records. - Contribute to process improvement and automation initiatives. Required Qualifications - 3+ years of experience in IT support, systems administration, or cybersecurity. - Strong knowledge of Windows 10/11 and Windows Server OS. - Experience troubleshooting laptops, desktops, and user issues. - Understanding of: - Entra ID and Active Directory - DNS - DHCP - Group Policy - Microsoft 365 - Experience supporting server infrastructure. - Ability to analyze logs and troubleshoot technical issues. - Strong written communication and documentation skills. Preferred Qualifications - Experience with SentinelOne or other EDR/XDR platforms. - Experience with vulnerability management tools. - Experience supporting patch management programs. - Familiarity with SIEM platforms and log analysis. - Experience with Azure and AWS environments. - Experience working in an MSP or MSSP. - Exposure to Linux administration. - Experience working in a ITSM platform and documenting incident and change management tickets in either service desk or other operations role. Desired Certifications (Not Required) - Security+ - Network+ - SentinelOne Foundations Certification - Microsoft Security Certifications Success Traits The ideal candidate: - Is naturally curious and enjoys investigating issues. - Aggressive in driving issues to resolution with a strong sense of problem ownership - Desire to build a long-term career in cybersecurity. - Has strong server and infrastructure fundamentals. - Can independently research and solve problems. - Strong written and verbal interpersonal skills - Is comfortable communicating with customers. - Maintains strong attention to detail. - Enjoys working across both security and operational IT disciplines. Benefits - Insurance: Medical, Dental, Vision, Life, Optional Supplementary Insurance - Time Off: Sick, Vacations, Holidays, Vacation - Location: Flexible in Tampa office and remote options - Retirement: Company Match 401k
Наблюдалась 2026-10-07, впервые 2026-10-06, источник — Indeed.