Goodwill Kentucky · 9 hours ago
Security Analyst
Goodwill Kentucky is dedicated to safeguarding its information systems and digital assets. The Security Analyst will play a crucial role in monitoring and improving the organization's security posture while collaborating with IT leadership and external security partners.
Telecom & CommunicationsConsumer GoodsConsumerEmail
Responsibilities
Partner with the Managed Security Service Provider (MSSP) to monitor security alerts, incidents, and threats across networks, systems, endpoints, and cloud environments
Triage, investigate, and respond to security incidents reported by MSSP, escalating appropriately and coordinating remediation efforts
Review MSSP reports and dashboards, translating findings into actionable insights for the CIO and IT leadership
Assist in identifying, assessing, and documenting cybersecurity risks and vulnerabilities
Support the development, maintenance, and enforcement of security policies, standards, and procedures
Participate in risk assessments, audits, tabletop exercises, and compliance activities (e.g. PCI, or other applicable regulations)
Collaborate with IT teams to implement security best practices, controls, and remediation plans
Help manage vulnerability scanning, patching coordination, and configuration reviews
Recommend tools, processes, and improvements to strengthen Goodwill Kentucky’s overall security posture
Serve as a trusted security partner to IT, leadership, and business teams
Support security awareness initiatives and promote a culture of cybersecurity across the organization
Communicate security risks and incidents clearly to both technical and non-technical stakeholders
Lead cybersecurity awareness training as needed and work closely with the Learning & Development team on cybersecurity training initiatives
Maintain incident reports, risk registers, policies, and security documentation
Provide regular updates and metrics to the CIO and leadership on security posture, trends, and areas of concern
Qualification
Required
Bachelor's degree in Information Security, Computer Science, Information Technology, or related field preferred (or equivalent experience)
2–5 years of experience in cybersecurity, security operations, or IT with a strong security focus
Familiarity with working alongside a Managed Security Service Provider (MSSP) or third-party security vendors
Understanding of common security tools and concepts (SIEM, EDR, firewalls, vulnerability management)
Strong analytical, problem-solving, and communication skills
Incident response and log analysis
Endpoint and network security (EDR, firewalls, VPNs)
Vulnerability scanning and remediation
Identity and access management (MFA, least privilege)
Microsoft 365 / cloud security fundamentals, Microsoft Purview, Microsoft Defender
Security frameworks and risk assessment
Security documentation and reporting
Preferred
Security certifications such as Security+, CISSP, CEH, or similar
Experience in nonprofit, healthcare, retail, or multi-site environments
Knowledge of compliance frameworks and regulations relevant to nonprofits or regulated data
Experience translating technical security issues into business-level risk discussions
Work with MSSP to make sure Security incidents are identified and addressed quickly and effectively with root cause communicated
Leadership has clear visibility into risks and security posture
Strong, collaborative relationships with the MSSP, VP of IT, and internal IT teams
Continuous improvement in security maturity without slowing down Goodwill Kentucky's mission
This job may have physical requirements that are considered sedentary work. Sedentary work involves sitting for long periods of time; occasional bending, squatting, kneeling, stooping; good finger dexterity and feeling; frequent repetitive motions; talking, hearing, and visual acuity and occasional lifting up to 15 pounds
Travel to other locations beyond the assigned work location is occasionally required
Company
Goodwill Kentucky
Goodwill Kentucky is a 101-year-old nonprofit organization that operates in 103 of Kentucky’s 120 counties.
Funding
Current Stage
Late StageTotal Funding
$4.5MKey Investors
Charter CommunicationsU.S. Department of LaborJewish Heritage Fund
2024-09-18Grant
2023-06-28Grant· $4M
2023-03-09Grant· $0.5M
Recent News
24-7 Press Release Newswire
2025-06-27
2025-05-08
Lane Report | Kentucky Business & Economic News
2025-04-17
Company data provided by crunchbase