IAM and Security Systems Analyst
Year Up UnitedAbout the role
About the Role:
We are seeking a highly skilled IAM and Security Systems Analyst to support the design, implementation, and operation of critical security controls across our infrastructure, cloud, and application environments. While the title reflects an analyst level, the role requires a hands-on engineering mindset with deep technical experience in identity management, security tooling, and threat detection.
This individual will play a key role in securing our systems, applications, and data by evaluating, implementing, and managing tools and processes across the security stack, from access governance to application security, SIEM operations, and incident response.
Key Responsibilities
Identity & Access Management (IAM)
- Manage and support identity platforms including Active Directory, Azure AD, and Okta.
- Implement RBAC, least privilege principles, and automated provisioning/deprovisioning.
- Conduct periodic access reviews and support access certification processes.
- Integrate IAM controls into application and cloud environments.
Security Engineering & Tooling
- Administer and optimize Mimecast, OKTA, Microsoft Defender, Intune, and other endpoint/cloud security tools.
- Manage SIEM tools including rule tuning, log ingestion, and correlation.
- Implement and automate application code reviews using security scanning tools (e.g., SAST, DAST).
- Perform application security testing and contribute to threat modeling and risk evaluations.
- Lead cloud control monitoring, data protection measures, and compliance reporting.
Threat Detection & Incident Response
- Conduct analysis of security alerts and lead incident response efforts.
- Leverage threat intelligence to update detection mechanisms and enhance response playbooks.
- Perform root cause analysis and evidence handling following incidents.
- Support red team/blue team exercises and penetration testing activities.
Architecture, Process & SDLC Integration
- Review and evaluate system and application security architectures.
- Support integration of security controls across the SDLC and DevSecOps pipelines.
- Design and continuously improve security processes and documentation.
- Participate in security metrics and reporting efforts to track control effectiveness.
- Support SOC design discussions and contribute to its operational maturity.
Collaboration & Compliance
- Partner with IT Operations teams, Infrastructure, HR, and Compliance to support security initiatives.
- Assist with internal and external audits, control documentation, and evidence collection.
- Maintain awareness of frameworks such as SOC 2, NIST, and ISO 27001.
- Help run awareness training, phishing simulations, and risk assessments.
This is a hybrid role that will require regular in-person work in office for work tasks and/or activities for coaching and support of our students. You must live within a commutable distance to either Boston, MA, New York City, NY, or Washington DC.
Salary Range: $90,000-$110,000/annually
Required Qualifications
- 3–5 years of experience in a security engineering or analyst role
- Strong experience with IAM platforms (Active Directory, Azure AD, Okta)
- Proficient in SIEM platforms, incident response, and Microsoft security tools
- Experience with automated security testing tools (SAST, DAST)
- Familiarity with cloud security (Microsoft 365, Azure) and application security principles
- Hands-on experience in scripting/automation (PowerShell, Python, or Terraform a plus)
- Strong understanding of network protocols, system hardening, and endpoint defense
- Excellent problem-solving and communication skills
Preferred Qualifications
- Familiarity with red teaming, penetration testing, and threat modeling
- Exposure to compliance frameworks such as SOC 2, HIPAA, or ISO 27001
- Participation in SOC design or operations
- Experience with security metrics/reporting and risk assessments
Why Join Us:
You’ll be part of a mission-driven team focused on protecting a modern IT and cloud-first organization. This is an opportunity to shape and grow a scalable security program, drive impact across critical systems, and mature key security domains.
#LI-Hybrid
COMPENSATION & BENEFITS:
Year Up United has established salary ranges for each of our sites, which allows us to pay employees competitively, equitably and consistently in different geographic markets. For roles in which the location is listed as flexible, the range dis
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s