Information Security Administrator

Welch Equipment
Denver, CO, United States
1 day ago
Apply on recruiting.adp.com
Prepare application

Role details

Contract type
Internship / Graduate position
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$70,720.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Microsoft Azure Cloud Computing Cloud Computing Security Configuration Management CompTIA Security+ Cyber Security Information Systems Information Leak Prevention Data Security Disaster Recovery Multi-Factor Authentication
+13 more
Identity and Access Management Information Lifecycle Management Microsoft Security Essentials Microsoft Office Phishing Zero Trust Network Access Systems Integration Software Vulnerability Management EndPointSecurity Data Processing Data Classification Information Technology CIS Benchmarks

Job description

Develop and maintain the organization’s cybersecurity program, including governance, compliance, risk assessments, audits, incident response, security monitoring, and awareness. Administer Microsoft Defender, Purview, Secureworks Taegis, Sophos, and KnowBe4 platforms; manage security policies, access controls, data protection, alerts, playbooks, and vendor reviews. Maintain risk registers, coordinate remediation and investigations, report security metrics, support business continuity, and advise leadership on cybersecurity priorities, budgeting, and investments., The Information Security Administrator is responsible for developing, implementing, and maintaining the organization’s cybersecurity program. This role serves as the primary resource for information security governance, compliance, risk management, security monitoring, security awareness, and incident response activities.

The position works collaboratively with IT, business leaders, vendors, and external partners to protect company systems and data while supporting contractual, regulatory, and industry requirements. The Information Security Administrator administers security technologies, maintains policies and standards, conducts risk assessments, supports audits, and drives continuous improvement of the organization’s security posture.

This role serves as the organization’s security champion and trusted advisor, providing management with practical recommendations regarding cybersecurity risks, compliance obligations, priorities, and investments., * Develop, maintain, communicate, and support enforcement of cybersecurity policies, standards, procedures, and guidelines.

  • Lead and support compliance and requirements initiatives
  • Conduct security risk assessments, document findings, assign remediation actions, and track corrective work through completion.
  • Coordinate internal and external security audits and maintain organized evidence, control documentation, and compliance records and suggest improvements based on findings
  • Lead the migration of non-compliant systems, processes, and environments toward approved compliant configurations.
  • Coordinate third-party and vendor security reviews and support business continuity, disaster recovery, and cybersecurity planning activities.
  • Review, triage, investigate, and coordinate response to security alerts, suspicious activity, and cybersecurity incidents.
  • Coordinate containment, eradication, recovery, evidence preservation, and post-incident review activities in accordance with the incident response plan.
  • Research emerging threats, vulnerabilities, attack techniques, and defensive practices and translate findings into actionable recommendations.
  • Develop and maintain security response playbooks, escalation procedures, detection use cases, and operational documentation.
  • Administer and optimize Microsoft Defender security solutions, including Defender for Endpoint, Defender for Office 365, Defender for Identity, and Microsoft Defender XDR.
  • Administer Microsoft Purview capabilities, including Data Loss Prevention, Information Protection, retention, data lifecycle controls, eDiscovery support, and other deployed compliance features.
  • Manage Secureworks Taegis XDR and Sophos MDR/XDR platforms, integrations, alert workflows, asset coverage, policy configuration, and operational escalations.
  • Serve as the primary liaison with managed security service providers, security operations centers, cybersecurity consultants, and incident response partners.
  • Monitor security dashboards and metrics to identify trends, recurring threats, coverage gaps, and opportunities for improvement.
  • Tune alerts, detections, policies, exclusions, and escalation paths to improve visibility and response effectiveness while managing unnecessary noise.
  • Manage endpoint security policies, security baselines, threat protection configurations, and security tool deployment coverage across corporate systems.
  • Manage email security platforms, phishing reporting processes, threat analysis workflows, and integrations among KnowBe4, PhishER, Microsoft Defender, and related tools.
  • Administer KnowBe4 security awareness training, phishing simulations, reporting workflows, user groups, campaigns, and related program communications.
  • Monitor training participation and phishing simulation results and use program trends to target additional education and risk reduction activities.
  • Develop practical employee security communications and promote a culture of cybersecurity awareness throughout the organization.
  • Provide role-appropriate guidance on phishing, account security, data handling, safe computing, and emerging threats.
  • Support identity and access management controls, including multi-factor authentication, Conditional Access, privileged access, periodic access reviews, and Zero Trust initiatives.
  • Review user access, administrative privileges, and system permissions for alignment with least-privilege and business-need principles.
  • Partner with system owners to implement data classification, retention, loss prevention, and appropriate data protection controls.
  • Support investigations involving potential data exposure, unauthorized activity, policy violations, or misuse of company information assets.
  • Maintain the cybersecurity risk register and document risk owners, treatment decisions, remediation plans, target dates, and status.
  • Perform security assessments of systems, technologies, vendors, and business processes before and after implementation.
  • Develop meaningful security metrics and provide management with clear reporting on risk, compliance, vulnerabilities, incidents, awareness, and control effectiveness.
  • Assist leadership with cybersecurity roadmap development, prioritization, budgeting, and investment recommendations.
  • Ability to work in a constant state of alertness and safe manner
  • Additional duties as assigned

Requirements

  • Bachelor’s degree in Information Technology, Information Systems, Cybersecurity, Computer Science, or a related field. Equivalent professional experience may be considered.
  • 7+ years of related experience in cybersecurity, information security, governance, risk, compliance, security operations, or IT infrastructure.
  • Experience developing and maintaining information security policies, standards, procedures, and compliance documentation.
  • Experience supporting audits, security assessments, vulnerability management, incident response, and remediation programs.
  • Experience administering enterprise security technologies. Direct experience with Microsoft Defender, Microsoft Purview, KnowBe4, Secureworks Taegis, or Sophos MDR/XDR is strongly preferred.
  • Working knowledge of recognized security frameworks and control practices, including ISO 27001, NIST Cybersecurity Framework, CIS Controls, and Zero Trust principles.
  • Strong analytical, investigative, documentation, project coordination, and problem-solving skills.
  • Ability to explain technical risk, compliance requirements, and recommended actions to technical and non-technical audiences.
  • Ability to work independently, collaborate across departments, manage competing priorities, and respond effectively during security incidents.
  • CISSP, CISA, SSCP, CEH, CompTIA Security+, CISM, or CRISC preferred
  • Microsoft security, identity, compliance, or Azure certifications applicable to the deployed environment preferred
  • Other relevant audit, privacy, risk management, cloud security, or incident response certifications preferred

Benefits & conditions

  • Low-cost Medical, Dental, Vision insurance
  • STD, LTD, and Life insurance
  • Paid Sick Leave and PTO
  • 401(k) match
  • Compensation Range: $107,000 - $117,500 annually depending on experience, Remote or Hybrid United States 107K-160K Annually Mid level 107K-160K Annually Mid level Cloud * Fintech * Software * Business Intelligence * Consulting * Financial Services The role involves managing outsourced accounting for nonprofits, leading teams, preparing financial reports, and improving operational efficiencies. Top Skills: Bill.ComIntaactMicrosoft Office SuiteNetSuiteQuickbooks Online Wipfli

Audit Internship - Spring 2028

13 Minutes Ago Hybrid Denver, CO, USA 34-34 Hourly Internship 34-34 Hourly Internship Cloud * Fintech * Software * Business Intelligence * Consulting * Financial Services Audit interns support client engagements by performing audit, review, and compliance testing; preparing financial statements, footnotes, reports, and engagement outputs; gathering client information; analyzing data; identifying process improvements; and communicating with engagement leaders. Interns develop practical audit, accounting, GAAP, software, administrative, communication, and teamwork skills while working with clients across various industries., Wipfli, Designs and implements scalable AI, machine learning, automation, and generative AI solutions for clients. Responsibilities include assessing AI readiness, developing strategies, leading discovery and solution delivery, integrating AI with enterprise systems, advising on governance and responsible AI, managing client engagements, contributing to reusable AI offerings, and supporting business development. The role requires strong technical, consulting, communication, and stakeholder management skills. Top Skills: Api FrameworksAutomationGenerative AiLarge Language ModelsMachine LearningAzurePythonSQL

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

About the company

Welch Equipment Company is the premier provider of material handling solutions and represents equipment from the world’s #1 manufacturers. Our culture of continuous improvement, or Kaizen, is embedded throughout the organization and is only one of the many “tools” to our success in supporting our employees.

Our core values are:

  • Customer Commitment
  • Integrity & Accountability
  • Teamwork
  • Respect
  • Act with Urgency

Our goal is to provide our employees with the tools needed to build a successful career, not just a job. We provide top notch support for our technicians in the form of manufacturer training, tech support, field service supervisors, on the job training in a controlled environment, cutting-edge technology and leaders trained to support.

We are seeking employees who are ready to join a culture of continuous improvement, positive attitude, and servant leadership. If that’s you come build your career with us at Welch Equipment Company and let’s continue to set the standard!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on recruiting.adp.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · World Congress 2024

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

41 sec

Massive client data loss and bio-digital storage

Chris Heilmann +1 · LIVE

Videos

See all

Related articles

See all