Security Operations Analyst

SubwayShelton, CT

About The Position

The Security Operations Analyst operates the identity security and access-governance layer of Subway's Cybersecurity program. Sitting within the Identity & Access Management team, this role is the operational bridge between IAM and the Detect & Respond function — identity-first in day-to-day work, but grounded in general security operations center (SOC) practice. The Analyst runs access-governance controls that keep the enterprise least-privileged and audit-ready, operates identity threat detection and response using CrowdStrike Falcon Identity Protection, and investigates access anomalies in Falcon Next-Gen SIEM. This role is designed as a genuine growth seat and launchpad into the broader Cybersecurity program, with development paths toward senior identity security, threat detection engineering, security engineering, or IAM engineering.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field — or equivalent work experience.
  • 1–3 years in security operations, identity operations, a security operations center (SOC), or IT operations with significant identity or security scope.
  • Working knowledge of IAM fundamentals: authentication and MFA, SSO concepts, directory services, joiner/mover/leaver lifecycle, and least-privilege access.
  • Hands-on exposure to Okta or a comparable identity provider: user and group administration, MFA management, and basic application assignment; Okta strongly preferred.
  • Familiarity with SOC practices: alert triage, severity assessment, escalation paths, evidence handling, and incident documentation.
  • Exposure to a SIEM or security analytics platform — querying logs, investigating events, and reading detections; CrowdStrike Falcon Next-Gen SIEM a plus; willingness to develop CQL proficiency required.
  • Active Directory fundamentals (users, groups, OUs) and familiarity with Microsoft Entra ID and Microsoft 365 administration concepts.
  • Experience with an ITSM platform (ServiceNow preferred) in a ticket-driven operations environment.
  • Strong written documentation habits — investigations, evidence, and runbooks that others can follow and auditors can rely on.
  • Comfort using LLM and generative AI tools in day-to-day technical and analytical work.

Nice To Haves

  • Direct experience with identity threat detection and response tooling (CrowdStrike Falcon Identity Protection or similar ITDR platform).
  • Exposure to Okta Identity Governance or another IGA/access-certification platform (SailPoint, Saviynt, Omada).
  • Familiarity with identity-focused attack techniques — credential stuffing, MFA fatigue, token theft, Kerberos abuse, lateral movement — and the MITRE ATT&CK framework.
  • Basic scripting in PowerShell or Python for reporting, reconciliation, and evidence gathering.
  • Awareness of non-human identity concepts: service accounts, credential scoping, and access patterns for LLM and agentic AI integrations.
  • Exposure to attack surface/asset management (CAASM) tooling.
  • Relevant certification: CompTIA Security+, Okta Certified Professional, Microsoft SC-300, or GIAC entry-level certification.

Responsibilities

  • Operate identity threat detection and response with CrowdStrike Falcon Identity Protection: monitor and triage identity-based detections, assess risk and severity, apply risk-based policy actions within defined guardrails, and escalate confirmed threats to the Detect & Respond team; investigate access anomalies end to end using identity telemetry in CrowdStrike Falcon Next-Gen SIEM — authentication events, MFA activity, privileged-account usage, and provisioning changes.
  • Support tuning of identity detections, dashboards, and alert quality with the Detect & Respond team; participate in incident response for identity-related incidents including account compromise, credential abuse, and unauthorized access — executing containment actions such as session revocation, credential reset, and access suspension under team runbooks; monitor privileged and service-account activity for anomalous behavior and policy violations.
  • Run Okta Identity Governance access certification campaigns end to end: campaign setup and scoping, reviewer coordination and follow-up, revocation execution, exception tracking, and production of audit-ready evidence for PCI-DSS 4.0 and cyber-insurance programs; support access request workflow operations including approval-path exceptions and escalations outside self-service.
  • Apply least-privilege principles in daily work: flag over-broad group and role assignments, validate time-bound privileged access, and drive cleanup of dormant, orphaned, or over-privileged accounts; produce and maintain access evidence for internal and external audits and compliance programs.
  • Work down the standing identity-risk case backlog: investigate, prioritize, remediate, and close findings such as dormant accounts, stale privileged access, weak authentication paths, and unowned service accounts; track remediation against service-level targets and report progress and systemic patterns to Cybersecurity leadership.
  • Handle Tier-2/3 identity escalations remaining after automation — complex access requests, provisioning exceptions, and onboarding/offboarding edge cases; manage assigned tickets in ServiceNow meeting SLA targets; support access-related requests from investigations, legal holds, and HR partners with appropriate discretion and documentation; participate in the team's shared on-call rotation.
  • Author and maintain runbooks, triage guides, and knowledge-base articles for identity security operations and certification processes; track and report on identity-risk backlog burn-down, certification completion rates, and detection quality metrics; propose governance, detection, and automation improvements from observed patterns.

Benefits

  • Insurance Plans (Medical, Life)
  • Pension/401K/RSP (country specific)
  • Competitive Bonus
  • Mobility Allowance
  • Tuition Reimbursement
  • Company Holidays
  • Volunteering time
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service