Crexi
Senior Security Operations Analyst
Playa Vista, CA · Senior
Sponsorship not specified$148k-$201kDetected 16 days ago
AWSAzureCloud PlatformsMachine LearningCybersecuritySIEMSOARSOC OperationsDetection EngineeringIncident ResponseComplianceCadenceLeadershipCommunicationCollaboration
About the role
- The Senior Security Operations Analyst is Crexi's primary internal security practitioner, responsible for day-to-day security operations, threat detection and response, and maintaining a strong security posture across the organization.
- Reporting to the Director, Information Technology, this role serves as the internal first line of defense for security events, protecting company systems, endpoints, identities, and data against evolving threats.
Responsibilities
- Monitor and triage security alerts, serve as the first internal escalation point for managed SOC vendors, investigate flagged incidents, and maintain accurate, timely incident logs.
- Manage endpoint security tooling, administer EDR and MDM platforms, enforce policy compliance across employee devices, and remediate vulnerabilities identified through scans or alerts
- Owns identity and access management (IAM) policy, access review design and audit reporting.
- Run the phishing simulation and security awareness program, schedule and manage campaigns, track completion rates, report results to leadership, and follow up with repeat offenders or high-risk user groups.
- Support SOC 2 evidence collection, pull logs, screenshots, and control artifacts on a recurring cadence to support corporate-side controls for audit and compliance readiness.
- Maintain security documentation, keep runbooks, incident response procedures, and access control policies current, accurate, and accessible.
- Partner with IT and engineering on security architecture reviews, vulnerability management, and secure configuration standards to reduce attack surface.
- Performs other duties as assigned.
Requirements
- 5- 8 years of experience in a security operations, IT security, or similar hands-on role.
- familiarity with control evidence collection and audit preparation.
- Experience working in cloud environments (AWS, Azure) with an understanding of cloud security fundamentals.
- Strong working knowledge of security operations concepts: threat detection, incident response, vulnerability management, and identity and access control.
- Hands-on experience with EDR platforms (e.g., CrowdStrike), MDM tools, and SIEM or log management platforms.
- Working knowledge of IAM principles and tools (e.g., Azure AD / Entra ID), including SSO, SCIM, and privileged access management.
- Hands-on experience supporting compliance frameworks, particularly SOC 2
- Why Crexi?
- Rapidly growing startup with a dynamic work environment
- Flexible team structure with the ability to progress in career
- Health, Dental, and Vision insurance
- Collaborative culture and numerous team activities
- The California base pay range for this position is $148,000-$201,000 per year with eligibility for generous bonus, equity, and healthcare insurance. The total compensation package offered to a successful candidate will depend on several factors, which may include, but are not limited to, the type and length of experience applicable to the role and within the industry, job-related skills, job level, and geographic location. Commercial Real Estate Exchange, Inc ("Crexi") is a multi-state employer, and this salary range may not reflect positions that work in other states.
Nice to have
- Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field preferred
- equivalent professional experience considered.
- Security certifications preferred, e.g., CompTIA Security+, GCIA, GCIH, SSCP, or equivalent.
- Experience with AI-powered security tools, SOAR platforms, or automated threat detection workflows is a plus.
Compensation
- The California base pay range for this position is $148,000-$201,000 per year with eligibility for generous bonus, equity, and healthcare insurance.
Benefits
- Track and report key security metrics, alert volumes, mean time to respond, endpoint coverage, phishing click rates, and open vulnerabilities, on a recurring basis to the Director, IT.
This listing is sourced directly from Crexi's careers page and normalized into a canonical job model.