IT Security Specialist
Jobright.ai · Pontiac, MI · 2 days ago
HybridFull-time
Why Join Us
This role is part of the Jobright Direct Hiring Network, where top companies like Cresta AI, Plaud, Mercor, OpenArt, and 1,500+ others hire top talent directly through our platform. This is not a mass job posting. Only select, high-signal candidates are invited and recommended directly to hiring teams.
Role Responsibilities
- Evaluate the adequacy and effectiveness of internal data controls, business and technical processes, and the performance of the organization's technology platforms
- Perform security and integrity reviews of the organization's data or IT systems
Qualifications Required
- 2+ years hands-on experience in at least one of the following areas: SOC Analyst, Threat hunting, Detection engineering, or Network Security engineering
- 2+ years experience in active troubleshooting of technical systems including creation of documentation
- Experience in client facing environments including active correspondence via email, instant message, voice/video calls with screen sharing
- Strong desire to learn, grow, and stay connected to the changing threat landscape
- Ability to discuss the fundamentals of information security in at least THREE of the following areas:
- Governance, Risk, and Compliance (GRC)
- Cloud and hosted applications
- Containerization
- Application security
- Network security and Zero Trust Architecture (ZTNA/NetSec)
- Endpoint security and OS hardening
- Security tooling and reporting automation (leveraging PowerShell/Python/Bash etc.)
- Malware analysis/forensic system analysis
- Incident response and remediation
- Penetration testing of Apps, endpoints, or devices
- Cyber Threat Intelligence (CTI) including automation of feeds and processing of incoming alerts/vulnerabilities
- Vulnerability Management
- Data Protection
Preferred
- Experience with CrowdStrike
- Hands-on experience with SOAR and other automations
- Hands-on experience using common AI models for automation, reporting, or research
- Familiar with various NIST frameworks such as CSF 2.0, 800-207, and 800-53
- Familiar with MITRE ATT&CK framework
- Familiar with OWASP and web application penetration testing
- Connections to the larger infosec community
- ISACA CRISC certification
- ISC2 SSCP certification
- CompTIA Security+ certification
- Experience with Government (State, local, or federal) IT systems (StateRamp/FedRamp)
- GRC experience extending to CJIS, HIPAA, PCI etc