Ready to be part of our team? We are looking for an IT Securities Analyst II for our Deland, FL office!This is a full time, onsite, in-person position Sponsorship is not available for this opportunitySummary: The IT Security Analyst II is the senior hands-on technical practitioner on the Kingspan Americas security team and the primary responder for security incidents across the organization. This role leads incident response, drives vulnerability assessment and remediation validation, and builds out the threat-hunting capability, leveraging deep expertise in CrowdStrike and the broader security stack to detect and stop malicious activity before it becomes a breach.
The Analyst II operates with a high degree of autonomy. The analyst manages day-to-day security operations with minimal direction and is expected to prioritize their work, drive investigations to closure, and recognize when a finding requires escalation to, or reporting through, the IT Security Manager.
Essential Duties:Incident Response (Primary)
- Incident Leadership: Serve as primary responder and technical lead for security incidents: detection, triage, containment, eradication, and recovery. Act as subject matter expert where exploitation is suspected.
- IR Program: Maintain and improve incident response playbooks and runbooks. Document root cause analysis and lessons learned and drive corrective actions to completion.
- Readiness: Support tabletop exercises and IR readiness activities across business units.
- Phishing & User Reports: Oversee analysis of user-reported phishing and suspicious emails. Analyze headers, links, and attachments; initiate remediation such as blocking senders and purging inboxes through the FreshService ticketing system.
Threat Hunting & Detection Engineering
- Proactive Hunting: Build and mature the threat hunting practice: form hypotheses grounded in MITRE ATT&CK, hunt across endpoint, network, and identity telemetry, and translate findings into new detections and monitoring coverage.
- CrowdStrike Expertise: Serve as the resident CrowdStrike expert. Advanced use of Falcon for detection, investigation, real-time response, and custom IOA/IOC development. Tune detections to reduce noise and close visibility gaps.
Vulnerability & Patch Management
- Assessment & Validation: Run vulnerability scanning (Qualys, Tanium), prioritize findings by exploitability and business risk, and validate patch cycle effectiveness through scan data and reporting. Identify systemic gaps and escalate.
- Remediation Guidance: Issue clear remediation guidance to system administrators, who execute the patch cycles, and track findings through to closure.
- Emerging Threats: Rapidly assess emerging high-severity CVEs and zero-day exploits, determine exposure across divisions, and drive time-sensitive remediation with administrators.
Security Operations & Tool Management
- Tool Ownership: Manage, tune, and maintain enterprise security tooling (CrowdStrike, Cisco Umbrella, Meraki, Qualys, Tanium) and translate security requirements into technical controls and configuration standards. Partner with platform and service owners to close control gaps.
- Endpoint Policy Governance: Review, standardize, and maintain security policies within Microsoft Intune (compliance policies, configuration profiles, and security baselines). Partner with endpoint administrators and the service desk, who retain platform ownership, to move policy management from one-off changes to a documented review cadence.
- Reporting: Develop and present security metrics, incident summaries, and program status to IT leadership in clear, business-relevant terms.
Security Training & Awareness
- Awareness Program: Implement and maintain security training and awareness campaigns, including phishing simulations, that educate staff on cyber hygiene and best practices. Track completion and results and report findings to the IT Security Manager.
General
- Support audit and compliance activities by providing security evidence, logs, and control documentation as requested.
- Verify the security posture of third-party vendors and requested software in support of onboarding and procurement.
- Follow the Group Code of Conduct and Group Compliance.
- Follow Compliance requirements per "KNA-SOP-1705 Compliance Roles and Responsibilities."
- Perform all other duties as assigned.
Education/Experience:- Experience: Minimum 4 years of hands-on experience in cybersecurity, SOC operations, incident response, or threat hunting.
- CrowdStrike: Demonstrated hands-on experience with CrowdStrike Falcon (detection, investigation, real-time response). CrowdStrike certifications (CCFA, CCFR, CCFH) are a strong plus.
- Autonomy: Runs investigations and technical projects end-to-end with minimal supervision.
- Education: Bachelor's degree in Computer Science, Information Security, or equivalent professional experience.
- Certifications: Preferred certifications include Security+, CySA+, GCIH, GCFA, GCIA, CISSP, or other industry-relevant security certifications.
- Industry: Experience in medium to large-scale multinational manufacturing, retail, or similar industry is advantageous.
- Communication: Ability to explain security risks, incident findings, and remediation needs clearly to technical and non-technical audiences.
- Language: Bilingual proficiency (English/Spanish) is preferred.
Technical Skills:- Networking: Deep understanding of standard network protocols (TCP/IP, ARP, ICMP, DHCP, DNS, HTTP, SNMP) and proficiency with packet analysis tools.
- Tool Proficiency: CrowdStrike, Cisco Umbrella, Meraki, Qualys, Microsoft Intune (security policy administration), Power BI, Lansweeper, Tanium.
- IT Service Management: Experience using ticketing systems such as FreshService, ServiceNow, or Jira to manage security workflows.
- Frameworks: Working knowledge of NIST, CIS, and ISO 27001 standards.
Personal AttributesThe successful candidate will exhibit the following attributes:
Curious Investigative Judgment- Critical Thinking: Exceptional analytical skills and willingness to challenge the status quo and investigate quiet signals others might miss.
- Thinks clearly when security issues are urgent, unclear, or incomplete.
- Maintains sound judgment without becoming reactive or alarmist under pressure.
Ownership Mindset- Takes full responsibility for outcomes, not just tasks. Drives work to completion without close supervision and keeps the IT Security Manager informed without needing to be asked.
- Remains steady, organized, and focused when managing complex investigations, risks, or unresolved issues over time.
- Shows mature judgment in knowing when to continue independently and when to raise concerns for support or visibility.
Practical Security Instinct- Balances risk awareness with a realistic understanding of how business and manufacturing environments operate.
- Looks for security approaches that are credible, workable, and grounded in the situation.
Service-Minded Security Partner- Service Orientation: A strong desire to help users work securely rather than acting as a blocker. Understands that security in a manufacturing environment has to enable production, sales, and plant operations, and finds controls that fit how the business actually works. Experience in non-regulated industries, MSP environments, or other settings where security had to earn cooperation rather than mandate it is highly valued.
Careful Discretion- Handles sensitive information with maturity, restraint, and respect for confidentiality.
- Is trusted to remain measured when dealing with incidents, access concerns, or potentially disruptive findings.
AI-Aware Security Judgment- Stays intellectually alert as attacker behavior, security risks, and technology-enabled threats continue to evolve.
- Brings healthy skepticism, curiosity, and disciplined judgment to unfamiliar signals, patterns, and emerging risks.
- Is comfortable balancing new technology with human analysis, careful questioning, and practical security instincts.
Physical Demands:The physical demands described here are representative of those that may be encountered while performing the essential functions of this position. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- Office-Based Work: This role is primarily performed in an onsite office setting and may involve extended periods working at a desk or workstation while monitoring security tools, reviewing alerts, documenting investigations, and using business and security systems.
- Computer and Equipment Use: Work may include frequent use of a computer, keyboard, mouse, phone, collaboration tools, ticketing systems, and enterprise security platforms such as endpoint, vulnerability, network, and identity monitoring tools.
- Information Review: The position may involve reviewing digital logs, alerts, reports, dashboards, technical documentation, incident records, and system-generated information with attention to accuracy, urgency, and detail.
- Movement Within Facility: The role may occasionally involve standing, walking, or moving within the office or facility to attend meetings, collaborate with internal teams, access equipment, or support security-related activities.
- Communication and Interaction: Regular communication may occur with IT teams, business stakeholders, leadership, vendors, and users through in-person discussions, phone calls, emails, tickets, reports, and virtual meetings.
- Lifting and Handling: The role may occasionally involve exerting up to 50 lbs. of force and/or up to 20 lbs. of force more frequently when lifting, carrying, pushing, pulling, or otherwise handling materials, equipment, or office-related items.
- Work Environment and Travel: The work environment generally includes a professional office setting with typical lighting, temperature, and noise levels. Occasional travel may be involved as needed for business meetings, security support, or related activities.
- Strength & Mobility: This position primarily involves seated work, with occasional standing or walking as needed. Must be able to exert up to 50 lbs. of force occasionally, up to 20 lbs. frequently, and a negligible amount constantly to lift, carry, push, or pull objects.
- Dexterity & Coordination: Frequent use of hands and fingers for typing, handling documents, operating office equipment, and interacting with digital tools.
- Visual & Auditory Requirements: Requires specific vision abilities, including close vision, distance vision, peripheral vision, depth perception, and the ability to adjust focus for reading, computer work, and document review.
- Cognitive & Communication Demands: Requires sustained mental focus, problem-solving, and analytical skills. Effective verbal and written communication, including collaborating with others, phone calls, emails, and in-person discussions.
- Work Environment: Typical office setting with controlled lighting, temperature, and noise levels.
We offer a comprehensive benefits package including 401k with company match, Medical, Dental, Vision, Identity Theft Protection, Critical Illness, Accident, Hospital Indemnity, Pregnancy and Parental Leave, Fitness Reimbursement, Educational Assistance, Life, AD&D, Short- and Long-Term Disability, and Life Assistance Program.