> Markdown version of [/jobs/ext/197919-systems-security-analyst](https://www.wearedevelopers.com/jobs/ext/197919-systems-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Systems Security Analyst - **Company:** Ntracts, LLC - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cyber Security, Identity and Access Management, Microsoft Security Essentials, Windows PowerShell, Proprietary Software, Azure Active Directory, User Provisioning Software, Software Vulnerability Management, EndPointSecurity, Microsoft InTune, Microsoft Sentinel, CIS Benchmarks - **Published:** May 31, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=7ad91dabeb9b4ece ## About the Role Do you have experience in UEM?, * 3-6 years of experience in security operations, endpoint security, or systems administration * Hands-on experience with Microsoft Intune, Defender XDR, Sentinel, and Entra * Experience operating in regulated environments (SOC 2, HIPAA preferred) * Strong understanding of identity governance and least privilege principles * Hands-on expertise in PowerShell development and Microsoft Sentinel automation, including workflow and response automation * Strong documentation and organizational skills * Ability to communicate technical findings clearly to non-technical stakeholders * Ability to operate independently while aligning with leadership direction ## Description The Systems Security Analyst is a hands-on security professional responsible for operating, improving, and scaling the organization's security posture across endpoints, identity, monitoring, and incident response. This role works deeply within the Microsoft security ecosystem (Intune, Defender XDR, Sentinel, Entra) and owns critical operational domains including device lifecycle management, vulnerability remediation, identity governance, and security monitoring. The analyst will lead initial incident investigations and containment efforts while escalating significant events to leadership as appropriate. This is a security-focused role, not a traditional helpdesk position, though it will support secure device onboarding/offboarding and assist with internal software and technical support where necessary. This role is suited for a security professional who thrives in a growing organization and enjoys building scalable, sustainable systems. Areas of Responsibility * Security Operations and Monitoring * Perform daily monitoring and analysis using Microsoft Defender XDR and Sentinel * Investigate, triage, and prioritize security alerts, suspicious activity, and anomalies based on risk and impact * Maintain structured, well-documented investigation records * Continuously tune alerts to reduce noise and improve signal quality 2. Incident Response * Lead investigation and containment of low- to medium-severity security incidents and support high-severity events under executive direction * Coordinate response actions across affected systems and stakeholders * Escalate high-severity or business-impacting incidents to executive leadership * Document incident timelines, root cause analysis, and remediation actions * Contribute to post-incident reviews and control improvements * Provide as-needed support during active security incidents outside standard business hours 3. Endpoint and Device Security * Own device onboarding and offboarding workflows using Intune and automation tooling * Enforce and maintain endpoint security baselines and configuration policies * Own endpoint patching and vulnerability remediation to meet defined SLAs * Monitor device compliance and drive corrective actions when standards are not met 4. Identity and Access Management * Manage identity lifecycle processes in Microsoft Entra * Enforce least-privilege access using role-based access controls * Conduct periodic access reviews and remediate excessive privileges * Support user provisioning and deprovisioning 5. Security Program Maturity and Automation * Improve operational efficiency through scripting and automation (PowerShell and related tools) * Use AI-driven workflows to enhance monitoring, reporting, and remediation * Identify process inefficiencies and propose scalable improvements to strengthen the security program 6. Documentation, Compliance and GRC Alignment * Maintain thorough documentation of security procedures and controls * Gather and organize audit-ready evidence for SOC 2 and HIPAA * Align operational practices with policy and risk management expectations * Partner with internal GRC leadership to ensure execution matches documented controls 7. Security-Aligned Technical Support * Assist with internal software and technical support where security or device management intersects * Serve as a security escalation point for technical issues * Collaborate cross-functionally to resolve issues without owning general IT support, * Independently runs daily security monitoring * Owns device lifecycle and vulnerability management * Leads initial incident investigations confidently * Produces audit-ready documentation * Improves at least one operational process through automation ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)