CYBER SECURITY ANALYST l

American Pacific MortgageRoseville, CA
$84,000 - $85,000Onsite

About The Position

The Security Analyst I is an entry-level cybersecurity position responsible for supporting the day-to-day operation of the company's information security program. Working under the direction of senior cybersecurity staff, this position assists with security alert monitoring, vulnerability and patch management oversight, software security reviews, security configuration monitoring, audit support, and security reporting. This role is designed for an individual who has a foundational understanding of information technology and cybersecurity and is interested in developing a career in security operations. The Security Analyst I is not expected to independently design or engineer security solutions. The position works closely with senior security personnel, Information Systems teams, our Managed Service Provider (MSP), Managed Security Service Provider (MSSP), and other technology partners to ensure security activities are completed and appropriately documented.

Requirements

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field or equivalent education, training, certifications, or relevant technical experience.
  • Approximately 0–2 years of experience in cybersecurity, information technology, help desk, systems administration, network support, or another related technical field.
  • Foundational understanding of cybersecurity concepts, including: Endpoint security, Malware and phishing, Authentication and access controls, Vulnerability and patch management, Basic networking concepts, Security monitoring and incident escalation
  • Basic familiarity with Windows environments and Microsoft technologies.
  • Ability to review technical information, identify potential issues, and follow established escalation procedures.
  • Strong attention to detail and organizational skills.
  • Ability to maintain accurate documentation and track multiple security activities through completion.
  • Strong written and verbal communication skills.
  • Ability and willingness to learn new cybersecurity technologies, processes, and concepts.
  • Ability to work collaboratively with senior technical staff, internal technology teams, and third-party service providers.

Nice To Haves

  • CompTIA Security+, Network+, or similar entry-level technology/security certification.
  • Internship, coursework, lab, or professional experience involving cybersecurity or IT operations.
  • Familiarity with SIEM, endpoint detection and response (EDR), vulnerability management, or security monitoring technologies.
  • Familiarity with Microsoft Azure, Microsoft 365, Entra ID, or Microsoft Intune.
  • Exposure to Proofpoint or other email security technologies.
  • Exposure to SentinelOne or other endpoint detection and response platforms.
  • Basic understanding of the NIST Cybersecurity Framework (NIST CSF), CIS Controls, or similar cybersecurity frameworks.
  • Basic familiarity with PowerShell, Python, or other scripting/automation technologies.
  • Experience working with an MSP, MSSP, SOC, help desk, or other technology service provider.

Responsibilities

  • Review and triage security alerts generated by security monitoring platforms, endpoint security tools, email security systems, and other security technologies.
  • Perform initial investigation and gather relevant information related to security events.
  • Follow established procedures for documenting, escalating, and tracking potential security incidents.
  • Work with senior cybersecurity staff and security service providers to support incident investigation and response activities.
  • Maintain appropriate documentation and evidence related to security events and incidents.
  • Assist with the company's vulnerability and patch management program.
  • Review vulnerability and patching reports and track identified vulnerabilities through remediation.
  • Coordinate with the MSP and internal technology teams to ensure required patches and security updates are completed within established timelines.
  • Follow up on outstanding or failed patching activities and escalate exceptions when necessary.
  • Assist with validating and documenting remediation activities.
  • Prepare regular vulnerability and patch compliance reporting for senior security staff.
  • Assist with the security review of new software, applications, browser extensions, and other technologies requested for use within the company.
  • Gather required security and vendor information using established review processes and checklists.
  • Review basic security considerations such as data access, authentication, permissions, software source, and requested system privileges.
  • Identify requests requiring additional technical or security review and escalate them to senior cybersecurity staff.
  • Maintain documentation of software reviews, approvals, exceptions, and security requirements.
  • Assist with monitoring security configurations across company-managed endpoints, systems, and security platforms.
  • Review security dashboards and reports to identify devices or systems that are missing required security controls or are not meeting established security standards.
  • Coordinate remediation activities with the appropriate internal team or service provider.
  • Assist with tracking security configuration exceptions and corrective actions.
  • Support senior security personnel with security configuration reviews and compliance reporting.
  • Perform routine administrative activities within approved security tools and platforms under established procedures.
  • Assist with maintaining security policies, procedures, standards, operational documentation, and security records.
  • Generate routine security metrics, dashboards, and management reports.
  • Assist with tracking security findings, remediation activities, exceptions, and open action items.
  • Support the continuous improvement of cybersecurity processes and procedures.
  • Assist with periodic user access and security reviews.
  • Support reviews of privileged accounts, inactive accounts, access exceptions, and other identity-related security controls.
  • Assist with gathering documentation and evidence related to identity and access management controls.
  • Escalate identified access concerns or exceptions to senior cybersecurity personnel.
  • Assist with cybersecurity awareness and training initiatives.
  • Support phishing simulation and security awareness activities.
  • Help develop and distribute security communications and educational materials.
  • Assist employees with basic security questions and reinforce established security practices and policies.
  • Assist with maintaining cybersecurity-related Disaster Recovery (DR) and Business Continuity Planning (BCP) documentation.
  • Support preparation and coordination of DR and BCP exercises.
  • Document testing results, identified issues, and follow-up activities.
  • Assist with tracking remediation items resulting from exercises and tests.
  • Assist the cybersecurity team with responses to regulatory, state, investor, customer, and internal audit requests.
  • Gather documentation, reports, screenshots, logs, and other evidence required to demonstrate security controls.
  • Maintain organized records of audit evidence and security documentation.
  • Assist with tracking security findings and remediation activities through completion.
  • Support compliance activities associated with the company's cybersecurity framework and regulatory obligations.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service