Information Security Administrator
Welch Equipment CompanyAbout Welch Equipment
Welch Equipment Company is the premier provider of material handling solutions and represents equipment from the world's #1 manufacturers. Our culture of continuous improvement, or Kaizen, is embedded throughout the organization and is only one of the many “tools” to our success in supporting our employees.
Our core values are:
- Customer Commitment
- Integrity & Accountability
- Teamwork
- Respect
- Act with Urgency
Our goal is to provide our employees with the tools needed to build a successful career, not just a job. We provide top notch support for our technicians in the form of manufacturer training, tech support, field service supervisors, on the job training in a controlled environment, cutting-edge technology and leaders trained to support.
We are seeking employees who are ready to join a culture of continuous improvement, positive attitude, and servant leadership. If that’s you come build your career with us at Welch Equipment Company and let’s continue to set the standard!
Benefits
- Low-cost Medical, Dental, Vision insurance
- STD, LTD, and Life insurance
- Paid Sick Leave and PTO
- 401(k) match
- Compensation Range: $107,000 - $117,500 annually depending on experience
Position Description
The Information Security Administrator is responsible for developing, implementing, and maintaining the organization’s cybersecurity program. This role serves as the primary resource for information security governance, compliance, risk management, security monitoring, security awareness, and incident response activities.
The position works collaboratively with IT, business leaders, vendors, and external partners to protect company systems and data while supporting contractual, regulatory, and industry requirements. The Information Security Administrator administers security technologies, maintains policies and standards, conducts risk assessments, supports audits, and drives continuous improvement of the organization’s security posture.
This role serves as the organization’s security champion and trusted advisor, providing management with practical recommendations regarding cybersecurity risks, compliance obligations, priorities, and investments.
Responsibilities:
- Develop, maintain, communicate, and support enforcement of cybersecurity policies, standards, procedures, and guidelines.
- Lead and support compliance and requirements initiatives
- Conduct security risk assessments, document findings, assign remediation actions, and track corrective work through completion.
- Coordinate internal and external security audits and maintain organized evidence, control documentation, and compliance records and suggest improvements based on findings
- Lead the migration of non-compliant systems, processes, and environments toward approved compliant configurations.
- Coordinate third-party and vendor security reviews and support business continuity, disaster recovery, and cybersecurity planning activities.
- Review, triage, investigate, and coordinate response to security alerts, suspicious activity, and cybersecurity incidents.
- Coordinate containment, eradication, recovery, evidence preservation, and post-incident review activities in accordance with the incident response plan.
- Research emerging threats, vulnerabilities, attack techniques, and defensive practices and translate findings into actionable recommendations.
- Develop and maintain security response playbooks, escalation procedures, detection use cases, and operational documentation.
- Administer and optimize Microsoft Defender security solutions, including Defender for Endpoint, Defender for Office 365, Defender for Identity, and Microsoft Defender XDR.
- Administer Microsoft Purview capabilities, including Data Loss Prevention, Information Protection, retention, data lifecycle controls, eDiscovery support, and other deployed compliance features.
- Manage Secureworks Taegis XDR and Sophos MDR/XDR platforms, integrations, alert workflows, asset coverage, policy configuration, and operational escalations.
- Serve as the primary liaison with managed security service providers, security operations centers, cybersecurity consultants, and incident response partners.
- Monitor security dashboards and metrics to identify trends, recurring threats, coverage gaps, and opportunities for improvement.
- Tune alerts, detections, policies, exclusions, and escalation paths to improve visibility and response effectiveness while managing unnecessary noise.
- Manage endpoint security policies, security baselines, threat protection configurations, and security tool deployment coverage across corporate systems.
- Manage email security platforms, phishing reporting processes, threat analysis workflows, and integrations among KnowBe4, PhishER, Microsoft Defender, and related tools.
- Administer KnowBe4 security awareness training, phishing simulations, reporting workflows, user groups, campaigns, and related program communications.
- Monitor training participation and phishing simulation results and use program trends to target additional education and risk reduction activities.
- Develop practical employee security communications and promote a culture of cybersecurity awareness throughout the organization.
- Provide role-appropriate guidance on phishing, account security, data handling, safe computing, and emerging threats.
- Support identity and access management controls, including multi-factor authentication, Conditional Access, privileged access, periodic access reviews, and Zero Trust initiatives.
- Review user access, administrative privileges, and system permissions for alignment with least-privilege and business-need principles.
- Partner with system owners to implement data classification, retention, loss prevention, and appropriate data protection controls.
- Support investigations involving potential data exposure, unauthorized activity, policy violations, or misuse of company information assets.
- Maintain the cybersecurity risk register and document risk owners, treatment decisions, remediation plans, target dates, and status.
- Perform security assessments of systems, technologies, vendors, and business processes before and after implementation.
- Develop meaningful security metrics and provide management with clear reporting on risk, compliance, vulnerabilities, incidents, awareness, and control effectiveness.
- Assist leadership with cybersecurity roadmap development, prioritization, budgeting, and investment recommendations.
- Ability to work in a constant state of alertness and safe manner
- Additional duties as assigned
Education and Experience
- Bachelor’s degree in Information Technology, Information Systems, Cybersecurity, Computer Science, or a related field. Equivalent professional experience may be considered.
- 7+ years of related experience in cybersecurity, information security, governance, risk, compliance, security operations, or IT infrastructure.
- Experience developing and maintaining information security policies, standards, procedures, and compliance documentation.
- Experience supporting audits, security assessments, vulnerability management, incident response, and remediation programs.
- Experience administering enterprise security technologies. Direct experience with Microsoft Defender, Microsoft Purview, KnowBe4, Secureworks Taegis, or Sophos MDR/XDR is strongly preferred.
- Working knowledge of recognized security frameworks and control practices, including ISO 27001, NIST Cybersecurity Framework, CIS Controls, and Zero Trust principles.
- Strong analytical, investigative, documentation, project coordination, and problem-solving skills.
- Ability to explain technical risk, compliance requirements, and recommended actions to technical and non-technical audiences.
- Ability to work independently, collaborate across departments, manage competing priorities, and respond effectively during security incidents.
- CISSP, CISA, SSCP, CEH, CompTIA Security+, CISM, or CRISC preferred
- Microsoft security, identity, compliance, or Azure certifications applicable to the deployed environment preferred
- Other relevant audit, privacy, risk management, cloud security, or incident response certifications preferred