About this role
OVERVIEW
Support the day-to-day operation of Santikos cybersecurity program by monitoring security events, investigating alerts, managing vulnerabilities, supporting identity and access controls, and helping protect systems and data across corporate and theater environments. Play a hands-on role in protecting a multi-location organization while building broad cybersecurity experience across cloud, identity, endpoints, networks, business applications, incident response, vulnerability management, and enterprise security governance. Work closely with the CIO, IT Infrastructure & Operations Manager, Cloud/POS team, support staff, and external security partners to identify risk, coordinate remediation, support security incidents, and maintain evidence for security and compliance requirements.
ROLES & RESPONSIBILITIES
- Monitor security alerts, logs, and telemetry from endpoint, identity, cloud, email, network, and other security platforms; investigate suspicious activity and escalate incidents as appropriate
- Perform initial triage and analysis of potential security incidents, document findings, preserve relevant evidence, and support containment, remediation, recovery, and post-incident follow-up activities
- Coordinate vulnerability management activities, including reviewing scan results, validating findings, prioritizing risk, assigning remediation actions, tracking progress, and verifying closure
- Take ownership of assigned security findings from initial validation through remediation and closure, coordinating with system owners and vendors as needed rather than functioning solely as an alert-monitoring or escalation resource
- Perform recurring reviews of user access, privileged accounts, administrative roles, service accounts, MFA, conditional access, and other identity controls in Microsoft 365, Entra ID, Azure, and related systems
- Support privileged-access governance by helping ensure administrative access is appropriately assigned, reviewed, documented, and removed when no longer required
- Assist with security configuration reviews and hardening efforts across endpoints, servers, cloud services, Microsoft 365, network devices, and business applications
- Support phishing prevention and response, including investigation of suspicious messages, malicious links or attachments, compromised accounts, credential exposure, and user-reported security concerns
- Assist with security awareness and training activities, including phishing simulations, employee communications, targeted education, and follow-up for identified risks
- Maintain and improve security documentation, including incident records, procedures, standards, control evidence, risk items, remediation trackers, and technical security configurations
- Support PCI DSS and other applicable security or compliance activities by gathering evidence, coordinating control-owner responses, tracking remediation items, and maintaining support documentation
- Work with the IT Infrastructure & Operations Manager, Cloud/POS team, and support staff to ensure identified vulnerabilities, insecure configurations, and security findings are remediated within appropriate timeframes
- Support endpoint, email, identity, cloud, network, and web-security technologies used by Santikos and coordinate technical escalations with vendors when specialized support is required
- Assist with implementation and ongoing improvement of security controls, including endpoint protection, email security, web filtering, logging, monitoring, MFA, conditional access, privileged identity management, and related safeguards
- Review security advisories, threat intelligence, vendor notices, and emerging vulnerabilities to determine potential impact to Santikos systems and recommend practical response actions
- Support onboarding, role changes, and employee separations by validating access-control requirements and assisting with rapid revocation of privileged or sensitive access when needed
- Assist with periodic testing and validation of security controls, including account reviews, vulnerability scans, recovery evidence, logging, alerting, and other operational security checks
- Own the internal remediation lifecycle for findings identified through independent security assessments, vulnerability scans, audits, penetration testing, and other security reviews; coordinate responsible system owners, establish target dates, track remediation through completion, maintain closure evidence, and escalate overdue or unresolved risks to the CIO
- Serve as the primary Santikos operational liaison for the independent cybersecurity assurance program and other external security assessments; provide requested evidence, respond to technical questions, coordinate internal owners, and support validation activities while preserving the independence of the assessor
- Support cyber-insurance, audit, and risk-management requests by helping maintain accurate technical evidence and status information
- Participate in security-related projects and technology initiatives to ensure appropriate controls are considered during planning, implementation, and change activities
- Identify opportunities to automate security monitoring, evidence collection, reporting, and repetitive administrative tasks
- Communicate security findings, risks, and recommended actions clearly to technical staff, business stakeholders, and leadership
- Maintain confidentiality and use elevated or sensitive system access only for authorized business purposes and in accordance with Santikos policies
- Perform other cybersecurity and technology-risk duties as assigned
Qualifications
EDUCATION & EXPERIENCE REQUIREMENTS:
- Bachelors degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related field preferred; equivalent combination of relevant education, technical training, certifications, and experience will be considered
- Minimum of 3 years of progressive experience in cybersecurity, information security, systems administration, network security, security operations, or a closely related technical role
- Relevant certifications, such as CompTIA Security+, CySA+, Microsoft Security certifications, GIAC, or equivalent industry certifications are preferred
- Demonstrated hands-on experience investigating security alerts, suspicious activity, account compromise, malware, phishing, or other security events is required
- Experience supporting a multi-site or distributed environment is preferred
SKILLS, KNOWLEDGE & ABILITIES:
- Knowledge of and experience with vulnerability scanning, vulnerability remediation, patching, configuration review, or related exposure-management processes
- Demonstrated knowledge of and experience with Microsoft 365, Entra ID, Azure security controls, MFA, privileged-access concepts, Windows environments, identity and access management, and multi-factor authentication concepts
- Ability to support security controls, audits, PCI DSS, NIST, CIS Controls, or other cybersecurity frameworks or compliance requirements is preferred
- Strong understanding of cybersecurity fundamentals including threats, vulnerabilities, risk, authentication, authorization, encryption, logging, and incident response
- Ability to analyze security alerts and technical evidence across endpoint, identity, cloud, email, network, and application environments
- Knowledge of and experience with vulnerability-management tools and the ability to interpret scan findings, assess practical risk, and coordinate remediation
- Familiarity with endpoint detection and response, email-security platforms, web filtering, firewall technologies, security logging, and monitoring tools
- Understanding of common attack techniques including phishing, credential theft, malware, privileged escalation, lateral movement, data exfiltration, and social engineering
- Ability to document investigations, security configurations, remediation actions, and control evidence clearly and accurately
- Familiarity with scripting, automation, or data-analysis tools such as PowerShell, Python, APIs, or similar technology is preferred
- Strong analytical and problem-solving abilities with a methodical approach to investigation and troubleshooting
- High degree of integrity, discretion, and judgment when handling confidential information, security events, employee data, and privileged system access
- Strong written and verbal communication skills with the ability to explain security concerns and recommended actions to both technical and non-technical audiences
- Ability to remain calm, organized, and responsive during security incidents or other time-sensitive events
- Detail-oriented with strong documentation, follow-through, and evidence-management habits
- Ability to work independently while collaborating effectively with infrastructure, cloud/POS, support, development, business teams, and external security partners
- Ability to prioritize competing vulnerabilities, alerts, projects, and compliance requirements based on business risk
- Curiosity and commitment to continuous learning as technologies, attack methods, and security practices evolve