Summary
mSupply is a North American distributor of OEM repair parts and equipment serving the appliance, HVAC, and plumbing industries. The IT Security Analyst supports daily cybersecurity monitoring and operations by reviewing alerts, assisting with investigations and incident response, administering security tools, tracking vulnerability remediation, and maintaining security documentation and reports.
Responsibilities
- Monitor security alerts and activity using security tools such as SIEM, EDR/XDR, identity, email, cloud, and other cybersecurity platforms
- Perform initial review and triage of security alerts, gather relevant information, document findings, and escalate issues as appropriate
- Assist with security investigations and incident response activities, including information gathering, remediation tracking, and follow-up
- Work with managed SOC/MDR providers and internal IT teams to investigate and resolve assigned security alerts and issues
- Maintain security incident documentation, procedures, and assigned response documentation
- Support the day-to-day administration, monitoring, and routine configuration of assigned cybersecurity tools
- Assist with reviewing security tool alerts, dashboards, logs, and system health
- Help troubleshoot security tool issues, integrations, and configuration concerns
- Assist with testing security-control changes and maintaining related documentation and records
- Review vulnerability and security assessment findings and assist with tracking remediation activities
- Work with technology owners to follow up on assigned vulnerabilities and overdue remediation items
- Assist with validating that identified security issues have been addressed through rescans, configuration checks, or other documented methods
- Support security assessments, audits, control testing, and evidence collection as needed
- Assist with tracking security risks and maintaining accurate records of remediation activities
- Maintain security reports, dashboards, metrics, and documentation for assigned areas
- Assist with recurring security reviews and other cybersecurity activities
- Use basic scripting, queries, or automation tools to improve routine security tasks when appropriate
- Participate in cybersecurity projects, tabletop exercises, security awareness activities, and technology evaluations as assigned
- Communicate status, issues, and potential risks to the appropriate team members
Skills
- Bachelor's degree in cybersecurity, information technology, computer science, or a related field, or an equivalent combination of education and relevant professional background
- 2–3+ years in information technology or cybersecurity, including security operations, security administration, IT support, systems administration, network administration, or a related technical function
- Familiarity with cybersecurity tools such as SIEM, EDR/XDR, vulnerability management, identity security, email security, or similar platforms
- Basic understanding of Windows and/or Linux systems, networking, identity and access management, cloud services, and common enterprise technologies
- Ability to review security alerts, troubleshoot technical issues, document findings, and escalate concerns appropriately
- Understanding of cybersecurity concepts, vulnerability management, security controls, and incident response
- Strong organizational, written, and verbal communication skills
- Ability to manage multiple priorities, work collaboratively with technical teams, and follow established procedures
- CompTIA Security+
- CompTIA CySA+
- Microsoft Security Operations Analyst (SC-200)
- This position primarily works in an office or remote work environment and requires regular use of computers and other technology
- Occasional travel may be required based on business needs
- Familiarity with security frameworks or practices such as NIST CSF or CIS Controls is preferred
- Background supporting security operations within a corporate IT environment
- Familiarity with SIEM, EDR/XDR, vulnerability management, identity, Microsoft 365, or other security technologies
- Exposure to security investigations, incident response, vulnerability remediation, or security assessments
- Basic proficiency with PowerShell, Python, security queries, APIs, or other scripting tools
- Familiarity working with managed security providers or SOC/MDR teams
- Background in a distributed, supply-chain, distribution, e-commerce, or multi-site environment
- Other relevant cybersecurity certification is a plus but not required
Qualifications
Must Haves
- Bachelor's degree in cybersecurity, information technology, computer science, or a related field, or an equivalent combination of education and relevant professional background
- 2–3+ years in information technology or cybersecurity, including security operations, security administration, IT support, systems administration, network administration, or a related technical function
- Familiarity with cybersecurity tools such as SIEM, EDR/XDR, vulnerability management, identity security, email security, or similar platforms
- Basic understanding of Windows and/or Linux systems, networking, identity and access management, cloud services, and common enterprise technologies
- Ability to review security alerts, troubleshoot technical issues, document findings, and escalate concerns appropriately
- Understanding of cybersecurity concepts, vulnerability management, security controls, and incident response
- Strong organizational, written, and verbal communication skills
- Ability to manage multiple priorities, work collaboratively with technical teams, and follow established procedures
- CompTIA Security+
- CompTIA CySA+
- Microsoft Security Operations Analyst (SC-200)
- This position primarily works in an office or remote work environment and requires regular use of computers and other technology
- Occasional travel may be required based on business needs
Nice to Haves
- Familiarity with security frameworks or practices such as NIST CSF or CIS Controls is preferred
- Background supporting security operations within a corporate IT environment
- Familiarity with SIEM, EDR/XDR, vulnerability management, identity, Microsoft 365, or other security technologies
- Exposure to security investigations, incident response, vulnerability remediation, or security assessments
- Basic proficiency with PowerShell, Python, security queries, APIs, or other scripting tools
- Familiarity working with managed security providers or SOC/MDR teams
- Background in a distributed, supply-chain, distribution, e-commerce, or multi-site environment
- Other relevant cybersecurity certification is a plus but not required
Benefits
- Medical, dental, vision, and prescription coverage effective immediately
- 401(k) plan with company contributions
- Life insurance and short-term disability coverage
- HSA/FSA options and an Employee Assistance Program (EAP)
- Paid time off, including vacation, holidays, and personal days
- Weekly pay
- Employee discounts
- Primarily works in an office or remote work environment