Security Analyst I

Ntiva, Inc.
McLean, VA, United States
21 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Experience required
1 year minimum
Compensation
$49,000.0 - $70,000.0
Working hours
Shift work
Languages
English
Job source

Tech stack

Microsoft Windows Cyber Security Desktop Computing Identity and Access Management Intrusion Detection Systems Log Analysis Security Log Security Information and Event Management Wi-Fi Technology Cybercrime Microsoft Sentinel SentinelOne Expertise
+2 more
Event Viewer User Accounts

Job description

As a Security Analyst I, you’ll be our first line of defense against cyber threats. You’ll swiftly respond to security alerts, investigate potential malicious activity, secure compromised accounts, and review change activity to prevent or minimize security events. By managing routine security tool adjustments and escalating complex issues, you’ll ensure our defenses remain effective and responsive, safeguarding our client’s assets and data.

Location and Work Expectations

  • This is a remote position; however, team members should be willing and able to travel if the need arises, though such travel is expected to be infrequent. Candidates with proximity to one of our Centers of Excellence are preferred (Lombard, IL; McLean, VA; Shreveport, LA; Overland Park, KS).
  • Schedule: 4 days on, 3 days off! Friday-Monday, 3pm-2am CST (following a required training period on day shift, M-F 8am-5pm CST - duration varies by individual progress)
  • This role also includes participation in a rotating on-call schedule.

What you will be doing

  • Monitor & Investigate: Actively monitor security dashboards, queues, and alerts from various sources (automated tools, escalated tickets) to detect potential threats.
  • Incident Triage & Response: Conduct initial investigations into security alerts, perform rapid response actions like securing user accounts, and collect necessary log data for analysis.
  • Escalate Effectively: Analyze findings to determine the scope and severity of incidents, resolving straightforward issues and escalating complex cases to Level 2 Analysts with clear, concise information.
  • Security Tool Management: Review and implement authorized, routine changes to security tools, such as processing client exemption requests in the EDR or temporarily adjusting settings for testing.
  • Collaborate with the Security Team: Work closely with fellow analysts and security engineers, sharing information, participating in team discussions, and contributing to a collaborative security environment.
  • Engage with Users/Clients: Communicate professionally and clearly with end-users or clients to gather details about potential security issues, explain security procedures, and provide guidance during incident resolution.
  • Liaise Across Departments: Interact effectively with other teams (e.g., Reactive Support, Client Strategy, NOC) to coordinate security responses and share necessary information.
  • Document Actions: Maintain accurate and detailed records of investigations, actions taken, communications, and resolutions within ConnectWise.
  • Provide Support: Offer timely and helpful support related to security inquiries, upholding a professional and customer-service-oriented approach in all interactions., Team members must establish a dedicated safe workspace that is free from distractions, hazards, and that is secure from unauthorized access. This includes following Ntiva’s IT User and Security Policies that include but are not limited to password-protecting all equipment, keeping confidential and proprietary documents secure, refraining from using public Wi-Fi, having adequate arrangements in place to avoid significant interruptions from caregiving responsibilities during work hours (except in emergency situations with manager approval). Any remote work away from a team member’s normal expected dedicated safe workspace must be requested by team member, is subject to review by management, and must adhere to Ntiva policies and procedures.

Requirements

  • 1-2 years of experience in Cybersecurity
  • 3-5 years in an IT role including log analysis, account/access management, or endpoint troubleshooting
  • This is a full-time role requiring your full alertness and reliable attendance during scheduled hours. Additional outside employment, regardless of hours, is not permitted
  • CySA+, GCIH, or SC-200 (or actively pursuing)
  • Hands-on exposure to at least one EDR/SIEM platform (e.g., SentinelOne, CrowdStrike, Microsoft Defender, Microsoft Sentinel)
  • Direct hands-on experience using ConnectWise Manage for ticket documentation, with a demonstrated track record of clear, timestamped, audit-ready incident notes
  • Must have practical familiarity with at least one of: SIEM log correlation, Windows Event Viewer (Security log IDs like 4624/4625/4648), or a ticketing-based alert queue
  • Sharp attention to detail with a proactive approach to accuracy and thoroughness
  • Passion for delivering outstanding customer service, with a track record of exceeding client expectations
  • Strong enthusiasm for learning new things and ability to adapt to evolving technology trends and industry advancements
  • This role involves extended periods of sitting or standing and regular use of computers and office equipment

Required language skills

  • Ability to communicate professionally, in English, both written and orally
  • Ability to write business correspondence and process procedures
  • Ability to effectively present information and respond to questions from groups of managers, clients, and the general public

Benefits & conditions

Pulled from the full job description

  • Referral program
  • Tuition reimbursement
  • AD&D insurance
  • 401(k)
  • Health insurance
  • 401(k) matching
  • Paid time off, Benefits and Perks
  • Medical, Dental and Vision coverage for employee and family

  • 401k + company-matched contributions 4% match on 5% contribution - no vesting period! (Employee and Company contribute after 90 days)

  • Group Term Life and Accidental Death and Dismemberment coverage (company provided)

  • Short-Term (voluntary enrollment) and Long-Term Disability coverage (company provided)

  • Health Savings Account (HSA) Options / PPO Options

  • Employee Assistance Program

  • Paid Time Off (PTO) + Volunteer Time Off (VTO) + 8 Paid Holidays + 3 Floating Holidays

  • Education Reimbursement Program

  • Generous Employee Referral Program - cash bonus for successful referrals!

  • Dynamic Recognition and Rewards

  • Clear Promotion and Advancement Tracks

  • Work with Industry-Leading Talent

The base pay range for this position is expected to be between $49,000.00 and $70,000.00 per year. The base pay offered may vary depending on multiple non-discriminatory factors including, but not limited to, market location, job-related knowledge, skills, and experience. The total compensation package for this position also includes medical benefits, 401(k) eligibility, and PTO. Additional details of participation in these benefit plans will be provided if an employee receives an offer of employment.

About the company

Are you looking for limitless career opportunities with a company that values growth, innovation, and teamwork? At Ntiva, we’re more than a Managed Services Provider, we’re a community dedicated to helping each other, our clients, and their businesses thrive both personally and professionally. Ntiva is a culture of people who are passionate about the work…and each other.

Our clients view us as an essential part of their teams, relying on us for strategic guidance, fast solutions to complex challenges, and proactive support. With strategic locations across the U.S. and leadership from our founder, Steven Freidkin, we’re on the front lines of a fast-paced industry, facing cybersecurity threats and rapid technology changes together.

If you thrive in a dynamic, supportive environment and enjoy going above and beyond, we’d love to meet you. Come explore one of our many opportunities and grow with us!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

11:18 min

Addressing audience questions on security and microservice architectures

Reinhard Kugler · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

37 sec

Investigating anomalous operational metric logs directly and securely

Modood Alvi · WWC 2025

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:44 min

Tracking mutable data updates with blockchain-secured historical logs

Wei Hu Wei Hu · WWC 2023

Videos

See all

Related articles

See all