Security Analyst Athens Administrators - 3.7 Concord, CA Job Details Full-time $120,000 - $160,000 a year 22 hours ago Benefits Health savings account AD&D insurance Disability insurance Health insurance Dental insurance 401(k) Flexible spending account On-the-job training Vision insurance Qualifications Security audits
AWS IAM SFTP
Cloud identity and access management (IAM) Qualys Okta Vulnerability scanning implementation Customer service CISSP Zoom CCPA Public Cloud Windows Microsoft Office Endpoint Detection and Response (EDR) Driver's License Computer hardware Security Event Management (security operations) Log analysis tools Azure AD MFA Vulnerability management Cloud compliance Typing Access control management Data Loss Prevention Regulatory compliance analysis PowerShell Vuls Intune Full Job Description
ATHENS POSITION DETAILS
Position Title:
Security Analyst Department:
Information Technology Reports To:
Senior IT Manager FLSA Status:
Exempt Job Grade:
16 ATHENS
ADMINISTRATORS
Explore the Athens Administrators difference: We have been dynamic, innovative leaders in claims administration since our founding in 1976. We foster an environment where employees not only thrive but consistently recognize Athens as a "Best Place to Work." Immerse yourself in our engaging, supportive, and inclusive culture, offering opportunities for continuous professional growth. Join our nationwide family-owned company in Workers' Compensation, Property & Casualty, Program Business, and Managed Care. Embrace a change and come make an impact with the Athens Administrators family today!
POSITION SUMMARY
Athens Administrators is seeking a full-time Security Analyst to join our IT department and support enterprise-wide security initiatives. This position may be remote, provided the employee meets technical requirements and resides in one of our operating states: AZ, CA, FL, ID, IL, MA, NV, NJ, NY, NC, OR, TX, or VA. Employees living within 26 miles of one of our office locations—Concord, CA; Orange, CA; Lake Mary, FL; or San Antonio, TX—are required to work onsite once per week, on a day designated by their supervisor between Tuesday and Thursday. Athens offices operate Monday through Friday, 7:30 a.m. to 5:30 p.m. local time. The standard schedule for this role is Monday through Friday, 37.5 hours per week, with a start time no later than 9:00 a.m. local time. The Security Analyst will be primarily responsible for safeguarding the integrity, confidentiality, and availability of enterprise systems, data, and user access. This position will be responsible for daily security monitoring, incident investigation, compliance support, and vulnerability lifecycle management. The Security Analyst works closely with the System Administrator team, Help Desk leadership, and the Senior IT Manager to identify and mitigate risks in real-time while supporting Athens' regulatory frameworks such as SOC 1 Type 2, SOC 2 Type 2, HIPAA, NIST, CPRA, CCPA and
GPDR. PRIMARY RESPONSIBILITIES
Our new hire should have the skills, ability, and judgment to perform the following essential job duties and responsibilities with or without reasonable accommodation.
Additional duties may be assigned:
Threat Monitoring & Incident Response Monitor and investigate alerts from DataDog SEIM, CrowdStrike EDR, Duo, Mimecast, and other security systems. Analyze unusual login activity, access anomalies, or endpoint behaviors and escalate as appropriate. Manage incident response playbooks and assist in root cause analysis (RCA) documentation. Coordinate with system administrators to isolate, triage, and remediate threats. Vulnerability Management & Remediation Operate and analyze results from Qualys vulnerability scans across servers, endpoints, cloud resources, and network devices. Work with System Administrators to validate patch deployment and remediation timelines. Participate in annual and ad-hoc penetration testing remediation efforts. Take point to work with the team to remediate any items raised in the penetration test. Security Operations & Policy Enforcement Support the configuration, policy tuning, and operational use of CrowdStrike, Duo MFA, Cloudflare Zero Trust, OKTA/Entra ID, and Mimecast. Conduct geo-blocking, conditional access rule reviews, and file transfer audits via Secure FTP. Review and maintain Athens security policies and procedures, ensuring compliance with industry standards and regulations. Ensure all Athens team members are educated, have acknowledged and are following the Athens Policies and Procedures based on their role. Compliance, Logging & Audit Support Act as the primary point of contact for the SOC 1 and SOC 2 auditors Act as the primary point person within Athens as we strive to achieve TX Ramp status Prepare and maintain system logs, evidence, and control testing documentation to support SOC 1 and SOC 2 audits. Monitor Data Loss Prevention (DLP) violations across M365, Secure FTP, and
SIMS/CXP
claims platforms. Enforce access controls and support system onboarding/offboarding with audit-ready tracking. Security Awareness & Governance Assist with staff security awareness training campaigns and phishing simulations. Maintain and enhance internal documentation related to policy, incident response, and tool configuration. Contribute to Athens' security roadmap, proposing improvements in detection, prevention, or automation. Schedule and take point for our Disaster recovery testing annually Answer all security questionnaires from prospects, customers, carriers, our insurance company, etc.
ESSENTIAL POSITION REQUIREMENTS
The requirements listed below are representative of the knowledge, skill, and/or ability required. While it does not encompass all job requirements, it is meant to give you a solid understanding of expectations. Bachelor's degree in information technology, computer science, or a related field, or equivalent practical experience required CISSP Certification required Relevant certifications such as CompTIA Security+, CompTIA Project+, Microsoft
SC-200, AWS
Certified Security are highly desirable, willingness to pursue further certifications encouraged. Significant knowledge of relevant software (including Microsoft Windows 10 and 11, Office 365 and hardware (including PCs., laptops, monitors, printers, etc.) 3-5 years in IT security operations, SOC monitoring, or vulnerability management roles.
Working knowledge of:
DataDog, CrowdStrike, Duo, OKTA, Mimecast, and Cloudflare. Hands-on experience with Qualys, BitLocker, InTune, Secure FTP. Familiarity with Microsoft 365 DLP, Zoom security configuration, and AWS IAM policies. Experience supporting audit frameworks such as SOC 1/2, HIPAA, or
ISO 27001.
Experience with privacy regulations such as
CCPA, CPRA, GPDR.
Experience with TX Ramp and/or State Ramp is a huge bonus. Proficient with log analysis tools such as DataDog and scripting in PowerShell or Python. Strong customer service and interpersonal skills Effectively work individually, and in a team environment, with clients and employees Ability to assess problems and situations independently quickly and critically, but also to know when to seek additional expertise. Ability to meet employer's attendance, time zone requirement, and hybrid remote work policy. Ability to type quickly, accurately and for prolonged periods, sit for prolonged periods, and lift up to 20 lbs. Valid driver's license and ability to local travel required, occasionally to one of our other offices. Reasoning ability, including problem-solving and analytical skills, i.e., proven ability to research and analyze facts, identify issues, and make appropriate recommendations and solutions for resolution Ability to be trustworthy, dependable, and team-oriented for fellow employees and the organization Seeks to include innovative strategies and methods to provide a high level of commitment to service and results Ability to demonstrate care and concern for fellow team members and clients in a professional and friendly manner Acts with integrity in difficult or challenging situations and is a trustworthy, dependable contributor Athens' operations involve handling confidential, proprietary, and highly sensitive information, such as health records, client financials, and other personal data. Therefore, maintaining honesty and integrity is essential for all roles within the company.
APPLY WITH US
We look forward to learning about YOU! If you believe in our core values of honesty and integrity, a commitment to service and results, and a caring family culture, we invite you to apply with us. Please submit your resume and application directly through our website at http://www.athensadmin.com/careers/job-openings Feel free to include a cover letter if you'd like to share any other details. All applications received are reviewed by our in-house Corporate Recruitment team. The Company will consider qualified applicants with arrest or conviction records in accordance with the Los Angeles Fair Chance Ordinance for Employers and the California Fair Chance Act. Applicants can learn more about the Los Angeles County Fair Chance Act, including their rights, by clicking on the following link: https://dcba.lacounty.gov/wp-content/uploads/2024/08/FCOE-Official-Notice-Eng-Final-8.30.2024.pdf. This description portrays in general terms the type and levels of work performed and is not intended to be all-inclusive or represent specific duties of any one incumbent. The knowledge, skills, and abilities may be acquired through a combination of formal schooling, self-education, prior experience, or on-the-job training. Athens Administrators is an Equal Opportunity/ Affirmative Action employer. We provide equal employment opportunities to all qualified employees and applicants for employment without regard to race, religion, sex, age, marital status, national origin, sexual orientation, citizenship status, veteran status, disability, or any other legally protected status. We prohibit discrimination in decisions concerning recruitment, hiring, compensation, benefits, training, termination, promotions, or any other condition of employment or career development.
THANK YOU!
We look forward to reviewing your information. We understand that applying for jobs may not be the most enjoyable task, so we genuinely appreciate the time you've dedicated. Don't forget to check out our website at www.athensadmin.com as well as our LinkedIn, Glassdoor, and Facebook pages! Athens Administrators is dedicated to fair and equitable compensation for our employees that is both competitive and reflective of the market. The estimated rate of pay can vary depending on skills, knowledge, abilities, location, labor market trends, experience, education including applicable licenses & certifications, etc. Our ranges may be modified at any time. In addition, eligible employees may be considered annually for discretionary salary adjustments and/or incentive payments. We offer a variety of benefit plans including Medical, Vision, Dental, Life and AD&D, Long Term Care, Critical Care, Accidental, Hospital Indemnity, HSA & FSA options, 401k (and Roth), Company-Paid STD & LTD and more! Further information about our comprehensive benefits package may be found on our website at https://www.athensadmin.com/careers/why-work-here