Trek

Trek

IT Security Engineer

Waterloo, Wisconsin

Sponsorship not specifiedDetected 1 day ago
PythonPowerShellAzureCybersecurityNetwork SecuritySIEMMicrosoft SentinelSOC OperationsDetection EngineeringIncident ResponseComplianceTCP/IPDNSCommunicationCISSPCompTIA

About the role

  • When you're on our team, you're taken care of, encouraged to learn and grow, and given lots of opportunities to do so.
  • Give us your best, and we'll give it right back.
  • Job Description Location: Trek Waterloo HQ (Hybrid) Role Summary Help us secure the Awesome Bus!

Responsibilities

  • Own the IAM program lifecycle: identity governance, role-based access control (RBAC), access certification, joiner-mover-leaver (JML) processes, and policy enforcement
  • Design and maintain a least-privilege access model across SaaS, cloud, and on-premises systems, including privileged access management (PAM)
  • Drive access certification campaigns: scope, execute, and report on periodic entitlement reviews across all systems
  • Develop and enforce IAM policies, standards, and procedures - including third-party and service account governance
  • Partner with HR, IT, and application teams to ensure processes are accurate, automated where possible, and consistently enforced
  • Support audit and compliance activities with identity evidence and access control documentation
  • Own the incident response lifecycle for security events - from initial detection through containment, eradication, recovery, and post-incident review
  • Develop, tune, and maintain detection rules and correlation logic across SIEM and EDR platforms to reduce noise and surface high-confidence detections
  • Build and maintain incident response playbooks, investigation runbooks, and post-incident documentation
  • Perform other duties as assigned

Requirements

  • 5+ years' experience in IT or information security, with demonstrable hands-on ownership across both IAM and security operations functions
  • Deep hands-on experience with Microsoft Entra ID (Azure AD) including SSO, MFA, Conditional Access, and directory operations
  • Strong understanding of IAM concepts: RBAC, least privilege, PAM, JML processes, access certification, and federated identity
  • Strong understanding of Windows and *nix systems, network architecture and protocols (TCP/IP, DNS, HTTPS), and cloud technologies
  • Demonstrated ability to incorporate AI tools into security workflows - not just awareness of them

Nice to have

  • Experience with privileged access management platforms (CyberArk, BeyondTrust, Admin by Request, or similar)
  • Scripting experience - PowerShell or Python - for automating identity workflows, detection pipelines, and security integrations
  • Experience with physical security systems (access control, CCTV) as a secondary function
  • Experience supporting compliance frameworks - PCI DSS, ISO 27001, SOC 2, or similar - with technical evidence and control documentation
  • Experience with threat hunting methodologies and hypothesis-driven investigation
  • Bachelor's degree in Computer Science, Information Security, MIS, or equivalent experience
  • Employee discounts on all product

Compensation

  • This policy applies to all aspects of employment, including hiring, promotion, demotion, compensation, training, working conditions, transfer, job assignments, benefits, layoff, and termination.

Benefits

  • Flexible and fun company culture
  • Competitive health care
  • PPO & HDHP medical plan options, Dental insurance, Vision insurance
  • Flexible Spending Accounts (FSA)
  • Free life insurance & optional term life insurance
  • Competitive vacation package
  • 401(k) with match and Employee Stock Ownership Plans (ESOP)
  • 12 weeks of maternity leave with 100% pay
  • Flexible holiday schedule - 10 company holidays
  • Tuition Reimbursement up to $15,000! (Undergraduate & Masters programs)
  • This policy applies to all aspects of employment, including hiring, promotion, demotion, compensation, training, working conditions, transfer, job assignments, benefits, layoff, and termination.
  • Administer and optimize Microsoft Entra ID (Azure AD) including SSO, MFA, Conditional Access policies, and directory health

Company info

  • At Trek we view artificial intelligence as a competitive advantage and a personnel multiplier, not a replacement for human expertise or judgment.
  • We are an E-Verify employer.

Equal opportunity

  • We are an Equal Employment Opportunity ("EEO") Employer.

This listing is sourced directly from Trek's careers page and normalized into a canonical job model.