IT / Information Security Analyst II
IT / Information Security Analyst II
About the role
Bloom Credit is hiring an IT / Information Security Analyst II to own day-to-day IT operations and hands-on security work across a fully remote Mac fleet. This is a combined role: roughly 50/50 IT and IS in theory, with the mix shifting by project and business need.
You will work with strong support from the Head of IT/IS and partner across the entire organization—engineering, compliance, product, people ops, and other functions—as identity, devices, access, and security touch every team. You operate with high autonomy in a remote environment.
We maintain SOC 2 and PCI DSS (self-attested) obligations. Experience supporting audits and evidence collection is valued.
What you'll own (Analyst II)
IT operations
- Endpoint lifecycle for a remote Mac fleet (provisioning, configuration, support, offboarding)
- Identity and access: JumpCloud directory / IdP / MDM, SSO app lifecycle, joiner–mover–leaver flows
- Google Workspace administration (mail, groups, Drive, Meet) and related automation where useful
- Helpdesk / end-user support: clear triage, resolution, and documentation
- Asset lifecycle coordination (procurement, shipping, disposition) with existing tooling
- Prefer native integrations and scripted automation over repetitive console click-ops; keep manual break-glass and validation paths documented
Information security
- CrowdStrike EDR health, detections, containment, and response coordination
- DLP controls and data-handling practices in daily ops, including policy tuning and exception handling
- SIEM / security signal work in Datadog (alerting, investigation support, tuning with stakeholders)
- Security hygiene: least privilege, access reviews, device posture, exception handling
- Support SOC 2 and PCI evidence gathering with Compliance; keep controls operational, not theoretical
- Zero Trust mindset preferred (identity-centric access, device trust, least privilege)—not required if you learn fast in this model
What you'll own (Analyst II)
IT operations
- Endpoint lifecycle for a remote Mac fleet (provisioning, configuration, support, offboarding)
- Identity and access: JumpCloud directory / IdP / MDM, SSO app lifecycle, joiner–mover–leaver flows
- Google Workspace administration (mail, groups, Drive, Meet) and related automation where useful
- Helpdesk / end-user support: clear triage, resolution, and documentation
- Asset lifecycle coordination (procurement, shipping, disposition) with existing tooling
- Prefer native integrations and scripted automation over repetitive console click-ops; keep manual break-glass and validation paths documented
Information security
- CrowdStrike EDR health, detections, containment, and response coordination
- DLP controls and data-handling practices in daily ops, including policy tuning and exception handling
- SIEM / security signal work in Datadog (alerting, investigation support, tuning with stakeholders)
- Security hygiene: least privilege, access reviews, device posture, exception handling
- Support SOC 2 and PCI evidence gathering with Compliance; keep controls operational, not theoretical
- Zero Trust mindset preferred (identity-centric access, device trust, least privilege)—not required if you learn fast in this model
Education and credentials
No single path is required. Degrees, certifications, and on-the-job experience are weighed equally.
- College - Associate's or bachelor's in IT, cybersecurity, CS, or related—or equivalent practical experience
- Certifications - 1–2 relevant certs (e.g. Security+, Google Workspace Admin, JumpCloud, CrowdStrike, CySA+, GSEC) or equivalent demonstrated depth
- On-the-job - ~4–6 years with ownership beyond ticket-only work; can run identity/endpoint/security ops with light oversight
How we work
- Fully remote; no traditional office network—access is identity- and device-centric
- Prefer native vendor integrations, then maintained scripts/automation, then console click-ops when that is the right business case
- High-impact actions require clear scope, blast radius, and rollback thinking; Head of IT/IS approves before execution
- Head of IT/IS available for support, escalation, and prioritization—not day-to-day micromanagement
Soft skills that matter here
- Clear, concise written communication across the org
- Calm triage under interruption (helpdesk + security signals)
- Ownership of outcomes without waiting to be told
- Collaborative posture—enable teams, don't gatekeep for its own sake
Apply for this job
*
indicates a required field