Role Summary The IT Security Analyst supports the Firm’s day-to-day security operations, phishing response, vulnerability management, endpoint protection, cloud security review, physical security administration, incident response support, evidence collection, and security reporting activities. This role performs first-level security analysis, documents findings, coordinates remediation with IT Operations, and escalates high-risk issues to the Firm’s managed service provider IT Security team and internal IT/Security leadership as appropriate. This position is intended for an entry- to mid-level security professional who can follow defined procedures, perform structured analysis, maintain audit-ready evidence, and support recurring operational security tasks. Benefits & Perks At ALAW, we’re committed to supporting the well-being and success of our team. We offer a comprehensive benefits package that includes: Medical, dental, and vision Insurance 401(k) plan with company match Company-paid life insurance, short-term and long-term disability coverage Generous PTO and paid holidays Professional development opportunities Employee recognition programs Wellness resources and employee assistance program (EAP) Employee referral program with bonus incentives Key Responsibilities Monitor and triage security alerts involving suspicious sign-ins, malware, phishing, endpoint activity, email threats, administrative changes, and unusual network or cloud activity. Investigate user-reported phishing messages, analyze relevant indicators, identify similar messages, and coordinate quarantine or removal when appropriate. Support identity and access reviews, including inactive, vendor, and privileged accounts; MFA enrollment; Conditional Access coverage; suspicious sign-ins; and mailbox forwarding or inbox rules. Monitor endpoint security coverage and compliance, identify devices with missing or outdated security tools, and coordinate remediation with IT Operations. Review vulnerability and patch-compliance reports, prioritize findings based on risk, create remediation tickets, and validate completion through rescans or supporting evidence. Review Microsoft 365, Azure, and AWS security findings, including external sharing, guest access, configuration exceptions, logging, encryption, and least-privilege controls. Assist with security awareness training, phishing simulations, employee follow-up, and reporting on participation and phishing trends. Support incident response by collecting evidence, documenting timelines, assisting with approved containment activities, and tracking action items through closure. Maintain organized security records and assist with evidence collection for audits, client questionnaires, compliance reviews, and governance reporting. Support physical security administration and periodic access reviews for systems such as Brivo and ADT. Prepare concise security updates, alert summaries, incident documentation, and compliance reports for leadership review. Preferred Qualifications Experience with Microsoft Sentinel, Microsoft Defender, Entra ID, Intune, Proofpoint, SentinelOne, Nessus, Fortinet, DNSFilter, Brivo, ADT, or comparable technologies. Familiarity with security frameworks or regulatory standards such as NIST CSF, CIS Controls, SOC 2, or the GLBA Safeguards Rule. Experience supporting phishing investigations, vulnerability remediation, access reviews, endpoint security, cloud security, or physical access administration. Security+, CySA+, SC-200, AZ-900, MS-900, or a comparable certification is preferred but not required. Requirements One to three years of experience in cybersecurity, IT support, security operations, infrastructure support, audit support, or a related technical role. Working knowledge of Windows endpoints, Microsoft 365, phishing analysis, vulnerability management, security alerts, and ticketing workflows. Ability to review logs and technical findings, follow established procedures, document conclusions, and escalate concerns appropriately. Strong attention to detail and organizational skills, particularly when maintaining evidence for audit, compliance, and governance purposes. Effective written and verbal communication skills. Scope of Authority The IT Security Analyst performs initial analysis, documents findings, coordinates routine remediation, and escalates high-risk or business-impacting matters to senior security leadership. Material security changes, risk acceptance decisions, production-system containment, policy modifications, and final legal or breach determinations require appropriate senior authorization. Job Type: Full time Work Location: Tampa/Remote About ALAW Founded in 1997, Albertelli Law (ALAW) has grown from a modest legal practice to a comprehensive, nationwide law firm providing efficient and effective legal representation to the nation’s largest financial institutions. Headquartered in Tampa, FL, and led by a team of seasoned industry veterans across an 18-state footprint, we are strategically positioned to cater to the diverse needs of our clients, including mortgage servicers, banks, investors, and other financial institutions. Our expansive practice covers a full range of services, including appellate advocacy, attorney closing services, bankruptcy solutions, consumer collections, creditors' rights matters, foreclosure proceedings, eviction services, litigation support, regulatory compliance, REO (Real Estate Owned) services, replevin actions, and an array of other specialized legal services tailored to meet our clients' unique needs. At ALAW, our dedication extends beyond our professional services. We believe in the power of community engagement and positive outreach. Our team passionately contributes to charitable initiatives, offers pro bono legal assistance, and actively volunteers in the communities where we operate. We take pride in fostering a culture that champions involvement, ensuring that our impact is felt in the heart of the community.
IT App Security Analyst
Kate
IT Security Analyst II
Centauri
IT Security Analyst
Epicorsoftware
Summer 2027 IT Cybersecurity Internship – Security Analyst
Sou1052Sppi
IT Cybersecurity Analyst - Vulnerability Management Cyber Security Engineer
Wecenergygroup
IT Cybersecurity Analyst - Cloud Security Engineer
Wecenergygroup