FMI · 23 hours ago
IT Security Analyst
FMI is a leading consulting and investment banking firm dedicated to the built environment. They are seeking an IT Security Analyst to focus on daily security monitoring, incident response, identity and access management, and vulnerability management, contributing to FMI’s cybersecurity maturity efforts.
Management Consulting
Responsibilities
Monitor and investigate alerts from Microsoft 365 Defender, Cisco Secure Endpoint, and SIEM systems
Monitor failed MFA attempts, risky sign-ins, and conditional access events
Assist with phishing simulations, user awareness campaigns, and education follow-ups
Respond to security incidents with triage, containment, documentation, and root-cause analysis
Assist in migrating email security policies from Cisco ESA to Microsoft Defender and ETD platforms
Maintain Entra ID configuration, MFA enforcement, and risk-based sign-in policies
Manage privileged access, break-glass accounts, and role-based access reviews
Conduct quarterly user and group access reviews for business applications
Support onboarding/offboarding automation and SSO integrations
Maintain asset and application inventories to support patching and lifecycle tracking
Conduct vulnerability scans, validate findings, and monitor remediation efforts
Collaborate with IT to coordinate monthly patching and report compliance metrics
Support SIEM operations including log ingestion, correlation, and dashboard maintenance
Onboard new data sources into SIEM and ensure log health and completeness
Maintain detection use cases, triage playbooks, and summary reporting
Maintain accurate security documentation, diagrams, and compliance records
Collaborate with internal teams to embed security best practices across processes and applications
Prepare monthly and quarterly summaries of incidents, trends, vulnerabilities, MFA adoption, and risk items for leadership
Use PowerShell or Python to assist with evidence collection, alert enrichment, and automation
Develop automation and AI-driven workflows for alert triage, summaries, and reporting
Evaluate and implement safe, value-adding automation in partnership with the Director of IT and Security
Lead cross-functional security projects and influence stakeholders
Tune SIEM rules, build new detections, and onboard log sources
Translate technical risks into actionable business insights
Recommend improvements to identity lifecycle and access control processes
Support tabletop exercises and user awareness initiatives
Gain exposure to compliance tools such as Vanta or Drata
Qualification
Required
Bachelor's degree in information security, computer science, or related field (or equivalent experience)
3–5 years of experience in information security, IT operations, or system administration
Experience managing Microsoft 365 Defender, Cisco Secure Endpoint, and SIEM systems
Familiarity with NIST or ISO 27001 frameworks, incident response processes, and vulnerability management
Exposure to compliance programs such as NIST CSF, ISO 27001, or SOC 2
Scripting or automation experience (PowerShell or Python)
Ability to work both independently and collaboratively in a small team environment
Strong documentation, reporting, and communication skills
Ability to travel up to 10% to regional offices (Raleigh, Denver, Houston, Tampa)
Ability to perform computer-based work for extended periods and occasionally lift up to 10 lbs
Must be able to commute to the office three or more days per week
Preferred
Relevant certifications: CompTIA Security+, Microsoft SC-200, or CySA+ preferred (required within 6 months of hire)
CISSP or similar certifications are a plus
Benefits
Paid employee medical insurance
Life insurance
Long-term disability
A strong 401(k) plan
PTO
Parental leave
Optional benefit elections
Company
FMI
FMI serves the industry as a trusted advisor.
Funding
Current Stage
Growth StageLeadership Team
Recent News
2024-02-25
Company data provided by crunchbase