FORGE Your Path logo
FORGE Your Path
Posted 62 days agoVerified live 2d ago

IT Security Analyst

Brief overview

Remote
$66k–$76k/yrStated range
2+ yrsMinimum
Microsoft 365 administrationWindows endpoint fundamentalsVulnerability scanningCVSS scoreEDR platformsIncident responsePhishing simulation campaignsVendor risk managementSecurity ticket triageRisk assessment support

About the company

FORGE Your Path logo
FORGE Your Pathforgeyourpath.org

FORGE is building the future workforce by connecting students to meaningful careers in construction and the skilled trades.

Job description

Summary

ForgePath Security is a cybersecurity and IT services consultancy founded in 2023. They are seeking an IT Security Analyst to support their help desk and work as a hands-on security analyst, focusing on vulnerability management, vendor risk reviews, and incident response, while providing opportunities for growth in the security field.

Responsibilities

  • Tier 1 / Tier 2 end-user support: workstations, accounts, productivity software, common application issues
  • Microsoft 365 administration (Exchange Online, Teams, SharePoint, Entra ID basics)
  • Remote endpoint provisioning and support workflows, coordinating with the client's on-site staff for physical hardware tasks
  • Own and triage the ticket queue
  • Vulnerability management — own the operational program end to end: scan operations, finding triage, prioritization, remediation tracking with IT and end users, and reporting
  • Third-party / vendor risk reviews: send, track, and coordinate vendor review questionnaires; perform first-pass analysis against established criteria; draft initial vendor review reports for senior review
  • Risk assessment support: evidence gathering, control verification, asset and system documentation, and interview coordination under vCISO direction
  • Phishing simulation campaigns: planning, deployment, reporting, follow-up training
  • Security ticket triage and investigation (EDR alerts, email security, identity)
  • Incident response support under ForgePath senior leadership
  • Routine hygiene: access reviews, configuration checks, hardening tasks

Skills

  • 2–4+ years across IT support / help desk / junior SOC or security analyst work (any combination)
  • Strong Microsoft 365 and Windows endpoint fundamentals
  • Familiarity with vulnerability scanning — you don't need to be an expert, but you should know what a CVSS score is and how to drive a fix
  • Strong written communication — you'll be drafting vendor review reports and remediation summaries that leadership reads
  • Solid customer-service instincts: patient, professional, and willing to help
  • Organized and self-directed enough to run recurring programs (scans, questionnaires, campaigns) without daily oversight
  • Security+, Network+, or equivalent certifications
  • Experience with EDR platforms (Microsoft Defender, CrowdStrike, SentinelOne)
  • Exposure to third-party / vendor risk management or GRC work (questionnaires, SOC 2 report review, risk registers)
  • Exposure to phishing-simulation tools (KnowBe4, Hoxhunt, etc.)
  • Curiosity about offensive security — there's real room to grow toward pentest and red-team-adjacent work over time
  • A genuine interest in security research and the wider community, such as digging into new vulnerabilities and security news and writing them up. We love people who would want to publish blog posts or research to benefit the security world

Qualifications

Must Haves

  • 2–4+ years across IT support / help desk / junior SOC or security analyst work (any combination)
  • Strong Microsoft 365 and Windows endpoint fundamentals
  • Familiarity with vulnerability scanning — you don't need to be an expert, but you should know what a CVSS score is and how to drive a fix
  • Strong written communication — you'll be drafting vendor review reports and remediation summaries that leadership reads
  • Solid customer-service instincts: patient, professional, and willing to help
  • Organized and self-directed enough to run recurring programs (scans, questionnaires, campaigns) without daily oversight

Nice to Haves

  • Security+, Network+, or equivalent certifications
  • Experience with EDR platforms (Microsoft Defender, CrowdStrike, SentinelOne)
  • Exposure to third-party / vendor risk management or GRC work (questionnaires, SOC 2 report review, risk registers)
  • Exposure to phishing-simulation tools (KnowBe4, Hoxhunt, etc.)
  • Curiosity about offensive security — there's real room to grow toward pentest and red-team-adjacent work over time
  • A genuine interest in security research and the wider community, such as digging into new vulnerabilities and security news and writing them up. We love people who would want to publish blog posts or research to benefit the security world

Benefits

  • Full benefits: medical, dental, vision, and 401(k) with employer match
  • Paid time off and ForgePath-supported professional development
  • Mentorship from ForgePath's security team and a real path to grow into deeper security work

More jobs like this