Cyber Security Analyst

Type One Energy
Madison, WI, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Experience required
1 year minimum
Working hours
Regular working hours
Job source

Tech stack

Software as a Service CompTIA Security+ Cyber Security Identity and Access Management Intrusion Detection and Prevention Python (Programming Language) Windows PowerShell Azure Active Directory Security Information and Event Management Software Asset Management Technical Data Management Systems Software Vulnerability Management
+4 more
Data Classification IT General Controls (ITGC) Microsoft InTune CIS Benchmarks

Job description

The Security Analyst will help operate and mature Type One Energy’s information security program as the second internal security practitioner, working alongside the Senior Cybersecurity Engineer. This is a foundational role with a clear trajectory. In the first year you will lead the buildout of automated hardware and software inventory and support the standup of a new SIEM, establishing the asset visibility and detection foundations on which the broader security program and the company’s IT general controls depend. As those foundations stabilize, the role grows into deeper security operations, detection engineering, and incident response. It suits an early-career security professional who is technically curious, process-disciplined, and motivated to build reliable, automated systems from the ground up. You will contribute to:

  • Build and automate hardware and software inventory using existing security and endpoint telemetry, replacing manual reconciliation with reliable, repeatable pipelines
  • Support the implementation and tuning of a new SIEM, including data source onboarding, alert triage, and detection use-case development
  • Maintain the authoritative system inventory and produce audit-ready evidence of its completeness and accuracy in support of IT general controls (ITGC)
  • Monitor, triage, and escalate security events in coordination with the managed SOC provider, developing into an internal point of continuity for security operations
  • Identify, track, and coordinate remediation of vulnerabilities across the endpoint and identity estate
  • Support access management, change management, and asset-completeness evidence in preparation for external audit
  • Contribute to incident response readiness, runbook development, and post-incident documentation
  • Maintain security documentation and control records in alignment with the information security document suite
  • Support oversight of managed service providers and vendors, validating that outsourced controls are performed and evidenced
  • Collaborate with IT, engineering, legal, and finance teams where security intersects their work, Type One Energy applies proven advanced manufacturing methods, modern computational physics and high-field superconducting magnets to develop its optimized stellarator fusion energy system. Our FusionDirect development program pursues the lowest-risk, shortest-schedule path to a fusion power plant over the coming decade, using a partner-intensive and capital-efficient strategy.

Type One Energy is committed to community engagement in the development and deployment of its clean energy technology. For more information, visit www.typeoneenergy.com or follow us on LinkedIn.

Export Control Compliance Notice

This position may require access to technology, technical data, software, or other information that is subject to U.S. export control laws and regulations. Any offer of employment will be contingent upon the Company’s ability to comply with applicable U.S. Export Control Laws, including obtaining any required government authorizations.

Type One Energy is a Global, U.S.-based company that develops and utilizes technologies subject to U.S. export control and trade compliance regulations. Certain positions may require access to controlled technologies, technical data, software, or other information regulated by U.S. Export Control Laws.

For positions involving access to export-controlled technology or information, the Company may be required to determine whether any government authorization or license is needed before such access can be provided. Any offer of employment for such positions may be contingent upon the Company’s ability to comply with applicable U.S. Export Control Laws and obtain any required government authorizations.

U.S. Employment Eligibility Verification

For positions based in the United States, Type One Energy participates in E-Verify and verifies the identity and employment authorization of newly hired employees in accordance with applicable federal law. Employees hired to work in the United States will be required to complete the Form I-9 employment eligibility verification process upon hire.

Requirements

  • One to three years of experience in IT, security operations, or a closely related technical role; equivalent education plus relevant hands-on experience will be considered
  • Working familiarity with core security operations concepts, including SIEM, endpoint detection and response, alerting, and vulnerability management
  • Demonstrated scripting and automation ability (e.g., PowerShell, Python), with a bias toward automating repetitive work rather than performing it manually
  • Understanding of endpoint and identity management platforms (e.g., Microsoft Entra ID, Intune, or equivalents)
  • Strong attention to detail and disciplined documentation habits; comfort owning data quality and reconciliation
  • Ability to work effectively with managed service providers and external vendors
  • Strong analytical, troubleshooting, and problem-solving skills
  • CompTIA Security+ or an equivalent certification, or active progress toward one, preferred
  • Exposure to compliance frameworks such as CIS Controls, NIST CSF, SOC 2, or SOX ITGC, preferred
  • Hands-on exposure to SIEM content or detection engineering, and to asset or SaaS discovery tooling, preferred
  • Experience in a regulated, manufacturing, or critical-infrastructure environment, preferred
  • Familiarity with data classification and DLP concepts such as Microsoft Purview sensitivity labeling, preferred

Benefits & conditions

In addition to a basic salary and yearly bonus, you will also get…

  • A hybrid work policy
  • Stock options
  • Relocation allowance
  • Insurance plans
  • Retirement options
  • And many more great voluntary benefits

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all