IT Security Analyst

Alternative Behavior Strategies, Inc.
Sugar Land, TX, United States
18 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$85,000.0 - $115,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Access Microsoft Windows Application Programming Interfaces (APIs) Android Software Development Apple IOS Apple Mac Systems Audit Trail Health Informatics Cloud Computing Cloud Computing Security Cyber Security Data Governance
+24 more
Information Leak Prevention Identity and Access Management Python (Programming Language) Microsoft Security Essentials Microsoft Office OAuth Windows PowerShell Azure Active Directory Cloud Services Phishing Kusto Query Language Software Vulnerability Management EndPointSecurity Enterprise Software Applications Office365 Malware Cyber Threat Analysis Microsoft InTune Microsoft Fabric Information Technology Microsoft Sentinel CIS Benchmarks Security Orchestration, Automation & Response Vulnerability Analysis

Job description

  • Monitor and investigate security alerts across Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps, and Microsoft Sentinel.
  • Respond to phishing, account compromise, malware, unauthorized access, and endpoint threats - coordinating containment, remediation, root-cause analysis, and post-incident documentation with IT and Compliance teams.
  • Coordinate with the ABS Kids managed SOC provider for alert triage, escalation, and incident response. Maintain and improve incident response playbooks and escalation procedures.

Identity & Access Management

  • Administer and monitor MFA, Conditional Access, Privileged Identity Management, role-based access, and least-privilege controls within Microsoft Entra ID.
  • Review risky users, risky sign-ins, privileged roles, guest access, enterprise applications, and OAuth app permissions to identify and remediate identity-related risks.
  • Endpoint Security & Device Management
  • Develop and maintain Intune compliance policies, configuration profiles, security baselines, and application protection controls across Windows, macOS, iOS, and Android.
  • Monitor endpoint compliance, support Defender for Endpoint investigations, and drive remediation of noncompliant or high-risk devices in partnership with IT teams.

Vulnerability Management & Threat Intelligence

  • Conduct vulnerability assessments across Microsoft 365, endpoints, and cloud services. Track findings and work with system owners to remediate vulnerabilities, misconfigurations, and control gaps.
  • Assist with threat hunting, detection tuning, and monitoring improvements. Research emerging threats and assess potential impact to the ABS Kids environment.

Data Protection & Compliance

  • Support Microsoft Purview initiatives including Data Loss Prevention, sensitivity labels, retention policies, audit logging, and data governance controls.
  • Assist with HIPAA security controls, compliance audits, risk assessments, vendor security reviews, and business continuity planning. Manage compliance incident documentation in Healthicity.
  • Maintain the IT Security Register, risk documentation, incident records, and remediation tracking.

Security Awareness & Communication

  • Develop security awareness communications and training on phishing, password security, and safe use of Microsoft 365 tools. Coordinate phishing simulations with IT teams.
  • Communicate security findings and recommendations clearly to technical and non-technical stakeholders, and promote a culture of security accountability across ABS Kids.

Requirements

  • Have a Bachelor’s degree in Cybersecurity, Information Technology, Computer Science or a related field or equivalent experience
  • 3+ years of experience in information security, cloud security, security operations, or systems administration with security responsibilities
  • Experience with Microsoft Sentinel, KQL, Microsoft Purview or Microsoft Security Exposure Management
  • Experience with PowerShell, Python, or Microsoft Graph API for security automation or reporting
  • Experience supporting HIPAA security controls, compliance audits or healthcare IT environments

Benefits & conditions

3.43.4 out of 5 stars Sugar Land, TX Remote $85,000 - $115,000 a year, Pulled from the full job description

  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Dental insurance, * $85,000-$115,000/year + annual bonus
  • PTO - 10 holidays + 15 vacation days
  • Full benefits package - medical, dental, vision, 401K match & more
  • Real career growth and a supportive, mission-driven team, * At ABS Kids we are empowered by the breadth of our differences. Our mission is to create a culture where all people thrive because their diverse stories are heard and celebrated. We commit to an evolving understanding of diversity as we learn from one another.

About the company

This is a brand new remote role that will help protect and improve the security of ABS Kids” Microsoft 365, cloud, identity, endpoint and collaboration environments. This role monitors alerts, investigates incidents, maintains security controls, supports compliance efforts, and promotes security awareness across the organization. The ideal candidate brings hands-on Microsoft 365 security experience - including Defender, Intune, Entra ID, and Purview - and thrives in a fast-paced, compliance-driven healthcare environment. At ABS Kids, we provide top-quality, evidence-based ABA therapy to kids with autism. Our mission? Empower families and create “wow” moments every day-and we can’t do it without amazing people like you., * It’s in the wow moments that we find our purpose at ABS Kids. Our shared experiences are the milestones that influence our work. The mission of our work with children with autism and their families feeds our spirit. With every wow moment, we can see our impact grow.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all