We’re Hiring: Cybersecurity Analyst | Santa Ana, CA — HybridWe’re looking for an experienced Cybersecurity Analyst to support the day-to-day operation, monitoring, and continuous improvement of our cybersecurity program.This is a hands-on technical role responsible for helping protect the organization’s infrastructure, networks, endpoints, identities, cloud services, and data. The Cybersecurity Analyst will work closely with Systems Engineering, Network Engineering, Endpoint Services, Helpdesk, and external security partners to identify risk, investigate security incidents, remediate vulnerabilities, strengthen security controls, and continuously improve the organization’s cybersecurity posture.This role is ideal for someone with a strong technical foundation across systems, networking, infrastructure, and cybersecurity who can investigate security issues across multiple technology layers rather than simply triaging alerts.
Location: Santa Ana, CA — HybridPay Range: $100,000–$110,000 annually, depending on experience (DOE)What You’ll Do:Monitor, investigate, and triage security alerts, suspicious activity, and potential cybersecurity incidents Determine the scope, severity, and potential business impact of security events and coordinate containment, remediation, recovery, and escalation activities Support incident response exercises, post-incident reviews, and improvements to security detection and response capabilities Coordinate vulnerability scanning, prioritization, remediation, validation, patch management, and reporting across servers, endpoints, networks, and other technology platforms Support identity and access security, including MFA, Conditional Access, Single Sign-On, privileged access, access reviews, and least-privilege initiatives Support security configuration and monitoring across Microsoft 365, Entra ID, endpoints, and related cloud services Investigate phishing, suspicious email, malicious attachments, account compromise activity, and other potential threats Support endpoint security, encryption, compliance, threat protection, security baselines, and configuration standards Assist with the administration, configuration, and optimization of SIEM, EDR/XDR, vulnerability management, email security, identity security, and other cybersecurity platforms Work with external SOC/MDR providers to investigate security events, validate findings, and coordinate remediation Support cybersecurity risk assessments, policies, standards, audits, compliance initiatives, customer security requests, and third-party/vendor security reviews Track security findings, risks, vulnerabilities, incidents, and corrective actions through completion Support security awareness and phishing simulation programs and help employees identify and report suspicious activity Maintain security procedures, incident documentation, technical documentation, dashboards, operational metrics, audit evidence, and cybersecurity reporting for IT leadership What Success Looks Like:Security events are thoroughly investigated, documented, escalated, and remediated appropriately Vulnerabilities and security findings are prioritized based on risk and tracked through resolution Endpoint, identity, network, server, and cloud security controls are consistently maintained and improved Access controls follow least-privilege principles, with unnecessary or outdated permissions identified and addressed Security tools, monitoring platforms, and external security partnerships provide effective detection and response capabilities Security documentation, metrics, audit evidence, and compliance records remain accurate and current Cybersecurity risks and recurring trends are identified and communicated to support continuous improvement Required Qualifications:4+ years of progressive IT experience across systems administration, networking, infrastructure, and/or cybersecurity, with increasing responsibility 2+ years of hands-on cybersecurity or security-focused responsibilities Strong working knowledge of enterprise networking concepts including TCP/IP, DNS, DHCP, VLANs, routing, switching, VPNs, firewalls, and network segmentation Strong working knowledge of Windows Server, Active Directory, Group Policy, and enterprise identity environments Experience administering or securing Microsoft 365 and Entra ID environments Experience with endpoint security, operating system hardening, patching, and vulnerability remediation Experience investigating security alerts, suspicious activity, or cybersecurity incidents Understanding of authentication, authorization, privileged access, MFA, Conditional Access, and least-privilege principles Ability to analyze security issues across multiple technology layers, including endpoint, identity, server, network, and cloud Experience working with security technologies such as EDR/XDR, SIEM, vulnerability management, email security, firewalls, or similar platforms Strong troubleshooting and root-cause analysis skills Ability to independently investigate technical issues and determine appropriate escalation or remediation Strong documentation, organization, and written/verbal communication skills Preferred Qualifications:Previous experience as a Systems Administrator, Systems Engineer, Network Administrator, Network Engineer, or similar infrastructure role before or alongside moving into cybersecurity Experience securing hybrid environments consisting of on-premises infrastructure and Microsoft cloud services Experience with Microsoft Defender, Intune, Entra ID, Purview, or related Microsoft security technologies Experience with enterprise firewall, SASE, or network security platforms Experience supporting vulnerability and patch management programs Experience working with SOC/MDR providers and validating or responding to their findings Experience with backup, disaster recovery, and business continuity from a cybersecurity perspective Experience with privileged access management and reducing standing administrative privileges Experience with NIST CSF, CIS Controls, CMMC, NIST SP 800-171, or similar frameworks Security+, CySA+, SSCP, CCNA, Microsoft security certifications, or equivalent technical certifications preferred