Security Analyst
At Midrex, you’ll do work that matters alongside people who believe you matter. The work won’t be easy, but it will be worth it. You’ll be part of a great team—with plenty of autonomy—to bring out your best.
Benefits
- Competitive benefits effective from Day 1
- Dollar-for-dollar 401(k) matching (up to 6%)
- Profit sharing with 401(k) kicker
- Generous overtime for qualified positions
- 4 weeks of paid vacation
- Tuition reimbursement
- Raffles for professional sports tickets
- Half-day Fridays
- Flexible home/office work practices
- Paid time to volunteer
- Employee recognition awards
Since 1987, Midrex has been the world leader in direct reduction technology, offering the best proven method for decarbonization in the iron and steel industry available today. Our rapid growth is transforming the steel industry and our planet. And none of it would be possible without our people, who bring vision, compassion, and extraordinary expertise to this work every day.
About the role
The Security Analyst is a great role for someone who is in the early stages of their cybersecurity career. We won’t expect you to know everything, but you should love cybersecurity, have a working knowledge of the industry and domain, and possess a growth mindset and be ready to learn. Day-to-day, this role will assist with the administration and continual improvement of our IT security, supporting 200 employees (and growing) across 7 locations and 3 continents globally.
Responsibilities
- Reports to the Manager – IT Operations.
- Works with and takes direction from the Senior Security Administrator (SSA). Will provide additional redundancy and support implementing, managing, and administering core security components with the assistance of the SSA.
- Work as an “ideal team player” with all company departments and employees in all assignments. Work toward building consensus on all assignments by finding solutions that meet the best interests of all parties involved.
- Exemplify Midrex’s purpose to Love and Serve others.
- Overall workload by percentage:
- 75% workload = Security projects and tasks; security administration and implementation.
- 25% workload = Tier 2-3 service desk support on security related tickets.
- Proactively looks for ways to improve security and add various layers of security for end points and servers (virtual and physical).
- Investigating network traffic for suspicious behavior.
- Automate security notifications and create dashboards and reports for the IT Dept and Executive team.
- Installing, administering, and troubleshooting network security solutions.
- Updating software with the latest security patches and ensuring the proper defenses are present for each network resource.
- Assist in maintaining and monitoring the SIEM platform.
- Consulting with staff, managers, and executives about the best security practices and providing technical advice.
- Develop and manage cybersecurity awareness campaigns, including digital signage, signs posted in common areas, etc.
- Plan and execute monthly security training and phishing campaigns.
- Monitor production systems, respond to and troubleshoot incidents.
- Maintain knowledge in cybersecurity information technology field and keep the Senior Security Administrator and Manager – IT Operations aware of information technology changes and innovations.
- Stay current with IT Security and systems, both hardware and software.
- Assist in maintaining backup and replication systems to ensure integrity of the disaster recovery site.
- Assist in analyzing and remediating security audit logs and vulnerability scans.
- Complete special projects and other responsibilities as assigned.
- Participate in periodic on-call duties.
Requirements
Soft Skills
- MUST Possess: Ideal Team Player attributes of Humble, Hungry and People Smarts.
- Willingness to learn and not stop learning (growth mindset).
- Good customer service skills (people-first mindset).
- Stress management in a high operational tempo environment.
- Detail oriented and knows how to manage time, prioritize and focus on various tickets and tasks.
- Must have an excellent work ethic and be able to handle stress very well.
- Ability to work in a fast-paced environment – Should be able to multi-task with proven follow-through and adherence to changing priorities and deadlines.
- Ability to organize multiple work assignments and meet budget and time requirements.
- Clear Communication and Documentation:
- Ability to clearly communicate technical issues to both technical and non-technical stakeholders.
- Ability to clearly document processes, configurations, or end-user instructions.
- Strong desire to learn and grow.
- Takes initiative.
- Asks good questions.
- Not afraid to ask for help when unsure or stuck.
- Proactively looks for solutions, improvements, and emerging technology to leverage.
Hard Skills
Required:
- Microsoft Security Suite (Defender and Intune).
- KnowBe4 (training/PhishER/PhishRIP).
- Understanding of Cloud-based security issues.
- Understanding of application and network security best practices.
- Understanding of endpoint and server best practices.
- Understanding of hybrid cloud/on-prem networks.
Preferred:
- Microsoft Security Suite (Entra, Priva, Purview, Sentinel).
- CCIE Security.
- NIST security standards.
- Rubrik.
- Microsoft Intune and SCCM.
- Application Deployments.
- Intune Device Policies.
- Device Compliance.
- Windows Updates for Business or equivalent Windows OS update/patch management.
- Active Directory:
- AD Management.
- GPOs.
- Domain Controller administration and deployment.
- Understanding of Sites and Services, AD Trusts, Hybrid User and Computer objects.
- Azure Active Directory:
- AD Connect.
- Conditional Access.
- Dynamic Groups.
- Single-sign on.
- Service Principles.
- Switch, Firewall, and Wireless management and administration:
- Cisco/Meraki Firewall.
- Meraki Wi-Fi.
- Cisco Umbrella.
- SSL Certificate management and renewal processes.
- DMARC, DKIM and SPF best practices.
- PowerShell.
- Working knowledge of security principles and best practices:
- Role-based Access Control.
- Principles of least privilege.
- Zero Trust.
- Disaster Recovery and failover.
- Strong Troubleshooting skills:
- Workstations.
- Servers.
- Applications.
- Networking.
- Understanding of TCP/IP and associated networking programs and protocols (DNS, DHCP, SSL, TLS, SNMP, HTTP, etc.).
Qualifications
- Bachelor's degree in technology or related experience required.
- Certifications in A+ and/or Security+.
- Minimum of 3-5 years in a fast-paced environment providing cybersecurity support and execution.
Travel Requirement
0% - 10% International and Domestic based on project demands.
Physical Requirements
- Prolonged periods of sitting at a desk and working on a computer.
- Ability to move around a project site.
- Lifting up to 50 lbs, setting up workstations, etc.