Cybersecurity Administrator
NewBe an early applicantSummary
In-house cybersecurity administrator at a multifamily real estate company who owns day-to-day security across cloud and on-premises environments — monitoring alerts, managing Entra ID/Conditional Access and MFA, running vulnerability and patch management, leading incident response, and supporting SOC 2 compliance, all centered on the Microsoft 365/Azure stack.
- Monitor security alerts, logs, and endpoint protection tools; investigate incidents and lead post-incident reviews.
- Manage Entra ID (Azure AD), Conditional Access, MFA, and access controls using least-privilege principles.
- Conduct vulnerability scans, prioritize remediation, and coordinate patching across endpoints, servers, and cloud environments.
- Administer and optimize firewalls, endpoint security, email security, and DLP solutions.
- Support cyber insurance, SOC 2, vendor risk assessments, audits, and security documentation.
- Lead phishing simulations, security awareness training, and user risk remediation efforts.
- Monitor and reduce internal and external attack surface exposure through ongoing hardening initiatives.
- Validate backups and support business continuity and disaster recovery testing.
- Evaluate vendor and SaaS security posture and support risk reviews for contracts and renewals.
- Maintain security runbooks, dashboards, metrics, and reporting on organizational risk posture.
- Act as a technical escalation point for the help desk and provide advanced troubleshooting support.
- Administer and maintain the Microsoft 365 environment, including Exchange, SharePoint, Teams, OneDrive, Power Platform, Entra ID, Defender XDR, Purview, and Azure.
- Other duties and projects as directed and assigned.
- Degree: B.S. in Cybersecurity, Information Systems, Computer Science, or a related field (or equivalent professional experience).
- 2-4+ years of experience in a cybersecurity, systems administration, or IT security role with strong troubleshooting skills.
- Working knowledge of Microsoft 365/Azure security tooling (Entra ID, Conditional Access, Defender, DLP) or equivalent platforms.
- Familiarity with security frameworks such as NIST CSF, CIS Controls, or SOC 2, and common compliance/audit processes.
- Experience with attack surface management or external attack surface monitoring tools (e.g., asset discovery, shadow IT detection, exposure scoring).
- Experience managing user risk programs, such as risk-based Conditional Access, insider risk management, or user behavior analytics.
- Relevant certifications preferred: Security+, CySA+, SSCP, CISSP, or similar.
- Ability to participate in an on-call rotation for security incidents and critical operational emergencies.
- A strategic thinker. You evaluate options thoughtfully, weigh tradeoffs, and choose solutions that align with long-term goals.
- A learner by nature. You stay curious, adapt quickly, and grow your skills as the business evolves.
- A calm problem solver. You stay steady under pressure, assess situations clearly, and move toward practical solutions.
- A grind-with-purpose performer. You work hard because you care—not because someone is watching. Your motivation comes from ownership and outcomes.
