Senior Security Administrator
Role details
Job location
Tech stack
Job description
AOS is seeking a hands-on Senior Security Administrator to support and strengthen the company's cybersecurity program. This role will help operate, monitor, and improve security controls across endpoints, networks, identity and access, email security, vulnerability management, logging, incident response, and audit readiness. The position works closely with IT Infrastructure, Automation, business application teams, and external security vendors to reduce cyber risk and support continuous improvement aligned with the NIST Cybersecurity Framework., * Monitor and triage security alerts from SIEM/log management, endpoint protection, EDR, firewall, DNS security, WAF, DLP, vulnerability scanning, and security rating tools.
- Administer and support AOS security technologies, including Cisco FirePower, McAfee Endpoint/DLP, SecureWorks Redcloak, IMAP/ITAP SIEM, OpenDNS/Cisco Umbrella, Imperva WAF/DDoS, ManageEngine PAM, Nessus, Microsoft Entra ID/MFA, and Proofpoint or equivalent email security tools.
- Operate vulnerability management processes, including scanning, risk prioritization, remediation tracking, exception documentation, and reporting.
- Support identity and access management activities, including MFA enforcement, VPN access control, privileged access review, user access review, and account provisioning/deprovisioning validation.
- Assist with phishing investigations, endpoint security events, email quarantine review, DLP alerts, and malware response.
- Participate in incident response activities, including investigation, containment, remediation, documentation, and lessons learned.
- Prepare and maintain audit evidence, control documentation, security procedures, diagrams, access review records, vulnerability reports, and incident records.
- Support customer security questionnaires, ITGC audits, supplier security reviews, cybersecurity insurance requests, and board/audit reporting as needed.
- Coordinate with internal teams and vendors to improve security operations, control maturity, and response readiness.
Requirements
- 5+ years of experience in IT security, security administration, infrastructure security, or cybersecurity operations.
- Hands-on experience with endpoint security, firewalls, vulnerability management, SIEM/log monitoring, MFA, Active Directory, Microsoft Entra ID, VPN, and email security.
- Ability to investigate alerts, review logs, document findings, and coordinate remediation with technical teams.
- Working knowledge of NIST CSF, CIS Controls, ISO 27001, or similar cybersecurity frameworks.
- Experience supporting audits, access reviews, security evidence collection, and remediation tracking.
- Strong communication, documentation, troubleshooting, and cross-functional coordination skills., * Experience in semiconductor, manufacturing, high-tech, or global enterprise environments.
- Experience with Cisco FirePower, McAfee Endpoint/DLP, SecureWorks Redcloak, Imperva, Nessus, ManageEngine PAM, Proofpoint, Cisco Umbrella/OpenDNS, or similar tools.
- Experience with ITGC/SOX audits, customer security assessments, third-party risk reviews, or cybersecurity insurance support.
- Security certifications such as Security+, CySA+, CISSP, CISM, GCIH, GCIA, Microsoft Security, or equivalent practical experience.
Benefits & conditions
2.82.8 out of 5 stars Sunnyvale, CA 94085 $100,000 - $140,000 a year - Full-time