> Markdown version of [/jobs/ext/2692156-information-security-administrator](https://www.wearedevelopers.com/jobs/ext/2692156-information-security-administrator). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Administrator - **Company:** Welch Equipment - **Location:** Denver, CO, United States - **Experience:** Expert - **Salary:** $70,720.0 - **Contract:** Internship / Graduate position - **Skills:** Artificial Intelligence, Microsoft Azure, Cloud Computing, Cloud Computing Security, Configuration Management, CompTIA Security+, Cyber Security, Information Systems, Information Leak Prevention, Data Security, Disaster Recovery, Multi-Factor Authentication, Identity and Access Management, Information Lifecycle Management, Microsoft Security Essentials, Microsoft Office, Phishing, Zero Trust Network Access, Systems Integration, Software Vulnerability Management, EndPointSecurity, Data Processing, Data Classification, Information Technology, CIS Benchmarks - **Published:** September 3, 2026 - **Apply:** https://recruiting.adp.com/srccsh/public/RTI.home?r=5001222741206&c=1127807&d=WelchCareerCenter ## About the Role * Bachelor's degree in Information Technology, Information Systems, Cybersecurity, Computer Science, or a related field. Equivalent professional experience may be considered. * 7+ years of related experience in cybersecurity, information security, governance, risk, compliance, security operations, or IT infrastructure. * Experience developing and maintaining information security policies, standards, procedures, and compliance documentation. * Experience supporting audits, security assessments, vulnerability management, incident response, and remediation programs. * Experience administering enterprise security technologies. Direct experience with Microsoft Defender, Microsoft Purview, KnowBe4, Secureworks Taegis, or Sophos MDR/XDR is strongly preferred. * Working knowledge of recognized security frameworks and control practices, including ISO 27001, NIST Cybersecurity Framework, CIS Controls, and Zero Trust principles. * Strong analytical, investigative, documentation, project coordination, and problem-solving skills. * Ability to explain technical risk, compliance requirements, and recommended actions to technical and non-technical audiences. * Ability to work independently, collaborate across departments, manage competing priorities, and respond effectively during security incidents. * CISSP, CISA, SSCP, CEH, CompTIA Security+, CISM, or CRISC preferred * Microsoft security, identity, compliance, or Azure certifications applicable to the deployed environment preferred * Other relevant audit, privacy, risk management, cloud security, or incident response certifications preferred ## Description Develop and maintain the organization's cybersecurity program, including governance, compliance, risk assessments, audits, incident response, security monitoring, and awareness. Administer Microsoft Defender, Purview, Secureworks Taegis, Sophos, and KnowBe4 platforms; manage security policies, access controls, data protection, alerts, playbooks, and vendor reviews. Maintain risk registers, coordinate remediation and investigations, report security metrics, support business continuity, and advise leadership on cybersecurity priorities, budgeting, and investments., The Information Security Administrator is responsible for developing, implementing, and maintaining the organization's cybersecurity program. This role serves as the primary resource for information security governance, compliance, risk management, security monitoring, security awareness, and incident response activities. The position works collaboratively with IT, business leaders, vendors, and external partners to protect company systems and data while supporting contractual, regulatory, and industry requirements. The Information Security Administrator administers security technologies, maintains policies and standards, conducts risk assessments, supports audits, and drives continuous improvement of the organization's security posture. This role serves as the organization's security champion and trusted advisor, providing management with practical recommendations regarding cybersecurity risks, compliance obligations, priorities, and investments., * Develop, maintain, communicate, and support enforcement of cybersecurity policies, standards, procedures, and guidelines. * Lead and support compliance and requirements initiatives * Conduct security risk assessments, document findings, assign remediation actions, and track corrective work through completion. * Coordinate internal and external security audits and maintain organized evidence, control documentation, and compliance records and suggest improvements based on findings * Lead the migration of non-compliant systems, processes, and environments toward approved compliant configurations. * Coordinate third-party and vendor security reviews and support business continuity, disaster recovery, and cybersecurity planning activities. * Review, triage, investigate, and coordinate response to security alerts, suspicious activity, and cybersecurity incidents. * Coordinate containment, eradication, recovery, evidence preservation, and post-incident review activities in accordance with the incident response plan. * Research emerging threats, vulnerabilities, attack techniques, and defensive practices and translate findings into actionable recommendations. * Develop and maintain security response playbooks, escalation procedures, detection use cases, and operational documentation. * Administer and optimize Microsoft Defender security solutions, including Defender for Endpoint, Defender for Office 365, Defender for Identity, and Microsoft Defender XDR. * Administer Microsoft Purview capabilities, including Data Loss Prevention, Information Protection, retention, data lifecycle controls, eDiscovery support, and other deployed compliance features. * Manage Secureworks Taegis XDR and Sophos MDR/XDR platforms, integrations, alert workflows, asset coverage, policy configuration, and operational escalations. * Serve as the primary liaison with managed security service providers, security operations centers, cybersecurity consultants, and incident response partners. * Monitor security dashboards and metrics to identify trends, recurring threats, coverage gaps, and opportunities for improvement. * Tune alerts, detections, policies, exclusions, and escalation paths to improve visibility and response effectiveness while managing unnecessary noise. * Manage endpoint security policies, security baselines, threat protection configurations, and security tool deployment coverage across corporate systems. * Manage email security platforms, phishing reporting processes, threat analysis workflows, and integrations among KnowBe4, PhishER, Microsoft Defender, and related tools. * Administer KnowBe4 security awareness training, phishing simulations, reporting workflows, user groups, campaigns, and related program communications. * Monitor training participation and phishing simulation results and use program trends to target additional education and risk reduction activities. * Develop practical employee security communications and promote a culture of cybersecurity awareness throughout the organization. * Provide role-appropriate guidance on phishing, account security, data handling, safe computing, and emerging threats. * Support identity and access management controls, including multi-factor authentication, Conditional Access, privileged access, periodic access reviews, and Zero Trust initiatives. * Review user access, administrative privileges, and system permissions for alignment with least-privilege and business-need principles. * Partner with system owners to implement data classification, retention, loss prevention, and appropriate data protection controls. * Support investigations involving potential data exposure, unauthorized activity, policy violations, or misuse of company information assets. * Maintain the cybersecurity risk register and document risk owners, treatment decisions, remediation plans, target dates, and status. * Perform security assessments of systems, technologies, vendors, and business processes before and after implementation. * Develop meaningful security metrics and provide management with clear reporting on risk, compliance, vulnerabilities, incidents, awareness, and control effectiveness. * Assist leadership with cybersecurity roadmap development, prioritization, budgeting, and investment recommendations. * Ability to work in a constant state of alertness and safe manner * Additional duties as assigned ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)