IT Infrastructure & Security Analyst
About the Role
The InfraSec Analyst helps with the support, maintenance, and operation of a diverse set of infrastructure and information security systems. They perform detailed work necessary to aid the needs of business and organizational requirements. The analyst must be knowledgeable of current security issues and compliance-related information and possess the ability to escalate security issues as needed.
A Day in the Life
- Supports Infrastructure & Cloud Security initiatives per the IT strategy.
- Implements and refines procedures to govern infrastructure security for our business.
- Promotes a broad range of vertical infrastructure security objectives such as risk and identity management, up-to-date devices (i.e., OS and software patching), data management, and information protection.
- Assists with hardware and software implementation as needed for new corporate initiatives.
- Run automated scanning tools to find unpatched software or weak configurations.
- Performs monitoring and analysis of daily events on a variety of systems to detect infrastructure security risks and threats.
- Partners with the SIEM team in monitoring system logs and traffic for suspicious activity using
- Run security scans, patch software, and fix weaknesses in servers, firewalls, and cloud configurations.
- Provides support including network, application, and desktop (remote and on-site) troubleshooting for incidents.
- Logs, triages, and routes infrastructure security issues to the appropriate IT teams
- Helps manage user permissions, firewalls, network segmentation, and privileged access management.
- Supports incident response process by documenting all actions taken during investigations.
- Collaborates with business and technology leaders to ensure the successful remediation of discovered infrastructure security weaknesses.
- Assists with reporting on gaps, project progress, and technology posture.
- Works closely with cross-functional teams to ensure technology implementations follow the policies and procedures defined by this role.
- Collaborates, as needed, with external auditors to ensure maturity and risk management assessments are completed and compliance certifications are achieved annually.
- Acts as on-call contact for Security escalations.
- Completes projects and daily tasks; as assigned.
What Sets You Apart
- Adopts EWC values in personal work behaviors, decision making, contributions and interpersonal interactions.
- Helps shape a positive work environment by demonstrating and influencing others to reward performance and value "can do" people, accountability, diversity and inclusion, flexibility, continuous improvement, collaboration, creativity, and fun.
- Experience with commercial infrastructure, cloud, and security solution platforms (e.g., Azure and AWS consoles, O365, GoTo, CrowdStrike, Osano, Lokker, BitSight, Logz.io, etc.)
- Ability to manage a broad range of deliverables, with ambiguous task symptomatology, while consistently achieving collaborative success with others to accomplish goals.
- Works well in a team environment and takes pride in participating in projects that employ the skills of all team members.
- Ability to learn quickly in a dynamic environment and to troubleshoot issues.
- Business savvy communications skills and concise written communication skills.
- Ability to be self-sufficient and self-driven in a small team.
- Understanding of the current threat and vulnerability landscape.
- Excellent organization and presentation skills.
- Hands-on experience with security information and event monitoring (SIEM) platforms and/or log management systems that perform log collection, analysis, correlation, and alerting.
- Basic security standards and frameworks (i.e., ISO 27001, SOC2, NIST CSF, etc.) familiarity.
Education and Experience
- Bachelor’s degree in computer science, cybersecurity, information technology or coursework/certification (including, but not limited to: CompTIA Security+, Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), etc.) or equivalent practical experience.
- 2+ years in Security and security technology roles.
- 4+ years in Microsoft technology administration; strong knowledge of O365 environment administration, including Azure, Azure AD, SharePoint, Office, One Drive, and Teams.
- Technical knowledge of endpoint security technologies including NGAV, EDR, and MDM.
- Email security administration and implementation experience.
- Exposure to web app firewall management.
- Excellent knowledge of Security Awareness Training Delivery, Policy and Procedural documentation, Identity Management, Privileged Access, and other security methodologies.
- Experience with Governance, Risk Management, and/or GRC, or solutions.
- Conceptual knowledge of federation between sites and federated identity.
- Knowledge of security assessments and vendor risk management.
*This role is not eligible for Visa Sponsorship*
European Wax Center is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability status, protected veteran status, or any other characteristic protected by law.
This job description is a general description of essential job functions. It is not intended to describe all duties someone in this position may perform. All employees of EWC and operating subsidiaries are expected to perform tasks as assigned by supervisory/management personnel, regardless of job title or routine job duties.