{"id":1459057,"url":"https://alion.io/job/twoconnect-it-security-analyst-work-from-home-day-shift","title":"IT Security Analyst - Work From Home | Day Shift","company":{"id":719418,"name":"Twoconnect","domain":"twoconnect.com.au","url":"https://alion.io/company/twoconnect-2","size_band":null,"is_staffing_agency":false,"employer_type":"staffing","is_intermediary":false,"listed_via":null,"ats_vendor":"Workable","truth_index":null},"role":"Security","role_family":"Security","seniority":null,"employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Philippines"],"countries":["PH"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":17000,"max_usd":48000,"period":"year","method":null,"sample_n":3655},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"ITIL","optional":false},{"name":"ITSM","optional":false},{"name":"Least Privilege","optional":false},{"name":"Microsoft Defender","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"Service Desk","optional":false},{"name":"SIEM","optional":false},{"name":"DNS","optional":true},{"name":"PowerShell","optional":true},{"name":"TCP/IP","optional":true},{"name":"Windows","optional":true},{"name":"Windows Server","optional":true}],"status":"live","first_seen_at":"2026-09-29T11:17:06Z","employer_posted_date":"2026-09-29","last_verified_at":"2026-10-06T01:01:38Z","board_verified":true,"closed_at":null,"days_open":6,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":6},"description":"The IT Security Analyst will support the protection of a Microsoft-based environment across global operations through security monitoring, incident response, identity and access management, vulnerability management, and continuous improvement of cyber security controls. The role will work closely with internal IT teams and external security providers to investigate threats, coordinate remediation, and support the organisation’s Essential Eight and IT service management processes.\nTriage and investigate Microsoft Defender alerts and Arctic Wolf SOC escalations, including phishing, malware, suspicious sign-ins and endpoint activity.\nCoordinate containment, eradication and recovery activities with Arctic Wolf and internal IT teams, maintaining incident evidence and escalating major incidents where required.\nSupport Microsoft Defender endpoint protection, Microsoft 365 security posture, security hardening and endpoint detection and response.\nPrioritise vulnerabilities based on exploitability, exposure and business criticality, and track remediation through to closure.\nSupport security baselines and patch compliance using Microsoft management tools and NinjaOne where applicable.\nReview and strengthen Active Directory and Microsoft Entra ID security, including MFA, Conditional Access, least-privilege access and periodic access reviews.\nReview privileged accounts, role-based access, service accounts and application permissions, and support identity-related threat response.\nSupport improvement of Essential Eight controls, maintain evidence and remediation actions, and work with control owners to verify implementation.\nSupport security risk assessments, policy reviews and audits, translating identified control gaps into prioritised actions.\nRecord and manage security incidents, requests, problems and changes in Freshservice in line with agreed ITSM processes.\nPerform root cause analysis, maintain response playbooks and knowledge articles, and support continuous improvement of recurring security issues.\nReport on incident response, remediation ageing, Defender coverage, identity risks and Essential Eight progress.\nCollaborate with service desk, infrastructure, application and business teams to resolve security issues while supporting operational continuity.\nProvide practical security guidance and contribute to phishing awareness and user education.\nSupport incident handovers across time zones and participate in agreed after-hours incident response arrangements when required.\nOther position-level duties as they arise.\nRequirements\nAt least 3 years’ relevant experience in cyber security operations, incident response, or an IT role with substantial hands-on security responsibilities is essential.\nPractical experience securing Microsoft enterprise environments and investigating threats using Microsoft Defender for Endpoint or equivalent EDR tooling is essential.\nHands-on experience with Active Directory, Microsoft Entra ID, MFA, Conditional Access and access reviews is essential.\nExperience working with a SIEM and managed SOC or MDR provider is essential; Arctic Wolf experience is highly regarded.\nWorking knowledge of Essential Eight implementation or assessment and ITIL-aligned IT service management processes is essential; Freshservice experience is desirable.\nStrong knowledge of Microsoft 365 and Windows security, including Exchange Online, Windows endpoints and Windows Server, is essential.\nExperience with log analysis and threat investigation, including common attack techniques, phishing and ransomware, is essential.\nSound understanding of networking fundamentals, including TCP/IP, DNS, firewalls and VPNs, is essential.\nPowerShell or Kusto Query Language (KQL) experience for investigation and automation is desirable.\nExposure to Intune, Defender for Office 365 and Defender for Identity is desirable.\nExperience within global or multi-site operations is desirable.\nRelevant qualifications in cyber security, information technology or a related discipline, or equivalent practical experience, are essential.\nRelevant Microsoft security or identity certifications, CompTIA Security+, ITIL Foundation certification or Essential Eight assessment training are desirable.\nStrong analytical judgement, problem-solving ability and clear written and verbal communication skills are essential.\nAbility to prioritise competing incidents and handle sensitive information with discretion and accountability is essential.\nBenefits\nWhy Join Twoconnect?\nWe offer more than just a job - we offer a supportive and rewarding career experience. Here’s what you can expect from this opportunity:\nWork from home\nMon - Fri: 9:00 AM - 6:00 PM AEST/AEDT (adjustments will be made for daylight saving time)\nHMO with 2 free dependents and medical reimbursements\nGovernment-mandated benefits\nOpportunities to work with leading companies in Australia and beyond\nTraining programmes for career development\nEngaging company outings, team activities and wellness sessions\nSupportive, inclusive culture\nDedicated managers focused on your growth and success\nTwoconnect connects highly skilled Filipino professionals with established companies in Australia, New Zealand, the United States, the United Kingdom and Europe, providing direct access to global careers and long-term opportunities.\nWe offer competitive pay and benefits, additional entitlements and structured career development programs that make employment both financially rewarding and professionally sustainable.\nOur industry-leading retention rate demonstrates our commitment to a people-first culture that prioritizes stability, growth and genuine care for every employee.\nTwoconnect is an equal opportunity employer. We value cultural diversity and foster an inclusive workplace where every employee is respected and supported as part of a growing global team.","description_format":"text","description_chars":5853,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"Philippines","iso":"PH","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Professional Services","Incident Response","Human Resources","Recruiting & Staffing"],"lifecycle":[{"event":"open","at":"2026-09-29T11:17:06Z"}],"visa":[],"liveness":{"score":82,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.822,"p_room":1,"age_days":5,"expected_fill_days":25,"reasons":["conf:1","win:early"],"computed_at":"2026-10-05T05:45:15Z"},"pay":null,"html_url":"https://alion.io/job/twoconnect-it-security-analyst-work-from-home-day-shift","json_url":"https://alion.io/job/twoconnect-it-security-analyst-work-from-home-day-shift.json","meta":{"generated_at":"2026-10-06T02:39:38Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4019,"day_limit":5000,"remaining_today":981,"minute_limit":60,"resets_at":"2026-10-07T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":719418},"rest":"https://alion.io/mcp/rest/get_company?id=719418"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Ftwoconnect-it-security-analyst-work-from-home-day-shift"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Ftwoconnect-it-security-analyst-work-from-home-day-shift"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Ftwoconnect-it-security-analyst-work-from-home-day-shift"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/twoconnect-it-security-analyst-work-from-home-day-shift\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Ftwoconnect-it-security-analyst-work-from-home-day-shift"}]}