Information Technology - Security Administrator

Charles River AssociatesBoston, MA
$125,000 - $140,000Hybrid

About The Position

The Information Technology (ITS) department at Charles River Associates is currently a team of more than 40 professionals dedicated to enhancing, maintaining, and developing the firm's technology infrastructure and security. The team is comprised of four functions: Service Delivery & Telecom, Enterprise Application Solutions, Infrastructure, Networking and Cloud Solutions, Information Security. Information Technology staff are based in the Boston, Chicago, London, Munich, New York, Oakland, San Francisco, College Station and Washington, DC offices. Mainly a Microsoft house, CRA is looking to maximize the performance of our on-premise systems and hybrid infrastructure, meaning experience with cloud technologies is essential for this role. The Security Administrator supports CRA’s information security and compliance objectives by administering and monitoring identity and access controls, privileged access, security configuration standards, and recurring security tasks. This role partners closely with Infrastructure, Service Delivery, Enterprise Applications, and Information Security to ensure that access is provisioned appropriately, administrative privileges are controlled, security baselines are maintained, and evidence is available for audits and compliance reviews. The Security Administrator also helps reduce operational risk by improving repeatability (documentation, runbooks, automation where feasible) and by supporting incident response and remediation activities.

Requirements

  • Bachelor's degree in a relevant discipline, Master's desirable;
  • Demonstrated hands-on experience administering identity and access controls in Microsoft-centric environments (e.g., Active Directory and cloud identity platforms);
  • Familiarity with Windows Server administration concepts;
  • Working knowledge of privileged access concepts and controls (least privilege, separation of duties, delegated administration, privileged group governance);
  • Experience producing audit evidence and supporting compliance workflows (access reviews, approval capture, evidence retention);
  • Familiarity with common security operations processes (incident, change, problem), and comfort working in a ticket-driven operating model;
  • Scripting/automation exposure (PowerShell preferred) to reduce manual administrative overhead is a plus;
  • Familiarity with vulnerability management and remediation coordination processes/tools is a plus.
  • Ability to follow and improve documented procedures, with strong attention to detail and consistency;
  • Strong communication and collaboration skills; able to coordinate with multiple IT teams and stakeholders.

Responsibilities

  • Administer and support identity and access controls across core platforms (e.g., Active Directory and cloud identity services), including account lifecycle activities, group management, and delegated administrative models.
  • Support the administration and enforcement of privileged access standards, including separate admin accounts, least privilege, and controls around membership in privileged groups (e.g., Domain Admins, Enterprise Admins, Schema Admins, Administrators, SQL Admins, workstation/desktop support admin groups).
  • Execute recurring access reviews and produce audit-ready evidence (e.g., administrator account reviews, privileged group membership exports/screenshots with timestamps, approval tracking), coordinating required approvals and retaining records per process.
  • Implement and maintain security configuration standards for Windows/identity-related services, including baseline security settings, policy alignment, and ongoing verification activities.
  • Partner with infrastructure and endpoint teams to support vulnerability management workflows (triage, prioritization, tracking, and validation of remediation), with focus on identity/security-related findings and configuration weaknesses.
  • Participate in off-hours and weekend server patching processes as required, including change coordination, access enablement, validation, and post-maintenance checks.
  • Handle and triage security administration requests through the ticketing system (e.g., access changes, group/permissions adjustments, privileged access requests), ensuring proper approvals and adherence to standard processes.
  • Support investigation and response activities by gathering logs, access history, and system context when security events require identity/permissions analysis; coordinate escalation to Information Security / SOC as needed.
  • Maintain and improve documentation (runbooks, procedures, approval flows) for security administration tasks; identify opportunities to streamline repetitive access tasks through standardization and automation.
  • Work closely with Infrastructure, Service Delivery, Enterprise Applications, and Information Security stakeholders to ensure security administration work is prioritized effectively and executed consistently; communicate clearly with technical and non-technical audiences.
  • Ability to support off-hours maintenance windows (evenings/weekends) as required, including clear communication, careful execution, and post-change validation.

Benefits

  • medical, dental, and vision insurance
  • 401(k) retirement plan with employer match
  • life and disability insurance
  • paid time off (vacation, sick leave, holidays)
  • paid parental leave
  • wellness programs and employee assistance resources
  • commuter benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service