> Markdown version of [/jobs/ext/1388244-security-analyst-i](https://www.wearedevelopers.com/jobs/ext/1388244-security-analyst-i). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Analyst I - **Company:** Ntiva, Inc. - **Location:** McLean, VA, United States (Remote available) - **Experience:** Starter - **Salary:** $49,000.0 - $70,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Cyber Security, Desktop Computing, Identity and Access Management, Intrusion Detection Systems, Log Analysis, Security Log, Security Information and Event Management, Wi-Fi Technology, Cybercrime, Microsoft Sentinel, SentinelOne Expertise, Event Viewer, User Accounts - **Published:** July 22, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=8c4e03e53061f344 ## About the Role * 1-2 years of experience in Cybersecurity * 3-5 years in an IT role including log analysis, account/access management, or endpoint troubleshooting * This is a full-time role requiring your full alertness and reliable attendance during scheduled hours. Additional outside employment, regardless of hours, is not permitted * CySA+, GCIH, or SC-200 (or actively pursuing) * Hands-on exposure to at least one EDR/SIEM platform (e.g., SentinelOne, CrowdStrike, Microsoft Defender, Microsoft Sentinel) * Direct hands-on experience using ConnectWise Manage for ticket documentation, with a demonstrated track record of clear, timestamped, audit-ready incident notes * Must have practical familiarity with at least one of: SIEM log correlation, Windows Event Viewer (Security log IDs like 4624/4625/4648), or a ticketing-based alert queue * Sharp attention to detail with a proactive approach to accuracy and thoroughness * Passion for delivering outstanding customer service, with a track record of exceeding client expectations * Strong enthusiasm for learning new things and ability to adapt to evolving technology trends and industry advancements * This role involves extended periods of sitting or standing and regular use of computers and office equipment Required language skills * Ability to communicate professionally, in English, both written and orally * Ability to write business correspondence and process procedures * Ability to effectively present information and respond to questions from groups of managers, clients, and the general public ## Description As a Security Analyst I, you'll be our first line of defense against cyber threats. You'll swiftly respond to security alerts, investigate potential malicious activity, secure compromised accounts, and review change activity to prevent or minimize security events. By managing routine security tool adjustments and escalating complex issues, you'll ensure our defenses remain effective and responsive, safeguarding our client's assets and data. Location and Work Expectations * This is a remote position; however, team members should be willing and able to travel if the need arises, though such travel is expected to be infrequent. Candidates with proximity to one of our Centers of Excellence are preferred (Lombard, IL; McLean, VA; Shreveport, LA; Overland Park, KS). * Schedule: 4 days on, 3 days off! Friday-Monday, 3pm-2am CST (following a required training period on day shift, M-F 8am-5pm CST - duration varies by individual progress) * This role also includes participation in a rotating on-call schedule. What you will be doing * Monitor & Investigate: Actively monitor security dashboards, queues, and alerts from various sources (automated tools, escalated tickets) to detect potential threats. * Incident Triage & Response: Conduct initial investigations into security alerts, perform rapid response actions like securing user accounts, and collect necessary log data for analysis. * Escalate Effectively: Analyze findings to determine the scope and severity of incidents, resolving straightforward issues and escalating complex cases to Level 2 Analysts with clear, concise information. * Security Tool Management: Review and implement authorized, routine changes to security tools, such as processing client exemption requests in the EDR or temporarily adjusting settings for testing. * Collaborate with the Security Team: Work closely with fellow analysts and security engineers, sharing information, participating in team discussions, and contributing to a collaborative security environment. * Engage with Users/Clients: Communicate professionally and clearly with end-users or clients to gather details about potential security issues, explain security procedures, and provide guidance during incident resolution. * Liaise Across Departments: Interact effectively with other teams (e.g., Reactive Support, Client Strategy, NOC) to coordinate security responses and share necessary information. * Document Actions: Maintain accurate and detailed records of investigations, actions taken, communications, and resolutions within ConnectWise. * Provide Support: Offer timely and helpful support related to security inquiries, upholding a professional and customer-service-oriented approach in all interactions., Team members must establish a dedicated safe workspace that is free from distractions, hazards, and that is secure from unauthorized access. This includes following Ntiva's IT User and Security Policies that include but are not limited to password-protecting all equipment, keeping confidential and proprietary documents secure, refraining from using public Wi-Fi, having adequate arrangements in place to avoid significant interruptions from caregiving responsibilities during work hours (except in emergency situations with manager approval). Any remote work away from a team member's normal expected dedicated safe workspace must be requested by team member, is subject to review by management, and must adhere to Ntiva policies and procedures. ## Related Videos - [Building Security Champions](https://www.wearedevelopers.com/videos/193-building-security-champions) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [GenAI Is a Junior Dev With Root Access](https://www.wearedevelopers.com/videos/100191-genai-is-a-junior-dev-with-root-access) - [Leveraging Large Language Models for Legacy Code Translation: Challenges and Solutions](https://www.wearedevelopers.com/videos/1157-leveraging-large-language-models-for-legacy-code-translation-challenges-and-solutions) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk)