Exposure Intelligence Analyst – Endpoint & Identity (EDR / AD-Entra / PAM / MFA)
Allstate · United States · 3 wk ago
RemoteRemoteInformation TechnologyFull-time
Key Responsibilities (Core + Domain)
- Convert endpoint/identity signals into exploitability-aware exposure intelligence.
- Identify chained attack paths (endpoint compromise → credential theft → privilege escalation → lateral movement).
- Produce clear remediation plans; support validation and closure tracking.
Endpoint & Identity (Domain)
- Own SME coverage for identity controls and endpoint posture: MFA gaps, privilege pathways, stale accounts, insecure configs, weak conditional access, device compliance gaps.
- Identify systemic identity risks: excessive privileges, weak auth flows, misconfigured policies, high-risk admin surfaces.
- Partner with IAM/endpoint teams to implement durable corrective actions.
Required Qualifications
- 3+ years in identity security, endpoint security, security operations, or exposure management.
- Working knowledge of AD/Entra fundamentals, MFA/PAM concepts, and endpoint control posture.
- Ability to describe attacker identity tradecraft and prioritize based on exploitability.
Preferred Qualifications
- Deep experience in endpoint platforms (Windows 10/11, macOS), Identity systems (Active Directory, Entra ID) and endpoint and identity security controls (EDR, Intune, PAM, MFA).
- Experience with identity telemetry, privilege analysis, and identity attack path concepts.
- Experience with endpoint detection/security telemetry.
- Automation skills (PowerShell, KQL, Python) for evidence gathering/validation.
Skills
- Automation
- Endpoint Security
- Identity Access Management (IAM)
- Identity Management (IdM)
- Scripting
Pay
Compensation offered for this role is $100,000.00 - $170,500.00 annually and is based on experience and qualifications.
Schedule
N/A
Benefits
N/A
Benefits
N/A