At Midrex, you will do work that matters alongside people who believe you matter. The work won’t be easy, but it will be worth it. You’ll be part of a great team—with plenty of autonomy—to bring out your best. And you’ll be well compensated and have a best-in-class benefits package. Take a look:
-
Competitive benefits effective from Day 1
-
Dollar-for-dollar 401(k) matching (up to 6%)
-
Profit sharing with 401(k) kicker
-
Generous overtime for qualified positions
-
Raffles for professional sports tickets
-
Flexible home/office work practices
-
Employee recognition awards
Since 1987, Midrex has been the world leader in direct reduction technology, offering the best proven method for decarbonization in the iron and steel industry available today. Our rapid growth is transforming the steel industry and our planet. And none of it would be possible without our people, who bring vision, compassion, and extraordinary expertise to this work every day. So, if you’re looking to do big work in a small-team environment, Midrex is just the place for you.
The Security Analyst is responsible for monitoring, detecting, investigating, and responding to cybersecurity threats across the organization's global technology environment. This role supports the protection of company systems, networks, cloud services, applications, and data through continuous security monitoring, vulnerability management, security awareness initiatives, compliance activities, and implementation of security controls. The role increasingly leverages AI-enabled security tooling to accelerate threat detection, triage, and response, and supports the secure adoption of AI technologies across the organization.
The Security Analyst serves as a key member of the cybersecurity team and works closely with IT infrastructure, cloud, networking, application, and business teams to improve the organization's security posture. This position requires strong analytical abilities, attention to detail, problem-solving skills, and a commitment to continuous improvement.
Essential Duties and Responsibilities
Security Operations
Monitor security alerts, events, and incidents generated by security platforms including SIEM, endpoint protection, email security, cloud security, and network security systems.
Investigate suspicious activity and coordinate incident response activities through resolution.
Perform threat hunting and security investigations to identify potential risks and unauthorized activities.
Document security incidents, findings, lessons learned, and remediation activities.
Participate in on-call rotation and security incident escalations as required.
Vulnerability and Risk Management
Conduct vulnerability assessments and coordinate remediation efforts with system owners.
Track and report remediation progress and risk reduction metrics.
Support annual penetration testing activities and validation of remediation actions.
Assist in risk assessments and implementation of corrective actions.
Identify opportunities to reduce organizational cyber risk through technology, process, and control improvements.
Security Engineering and Administration
Assist with implementation, administration, and optimization of security technologies.
Manage security policies and configurations across Microsoft 365, Azure, endpoint management, email security, and network security platforms.
Support identity and access management controls including role-based access control, least privilege, and privileged account management.
Assist with implementation and maintenance of Zero Trust security architecture initiatives.
Manage SSL/TLS certificate lifecycle processes including acquisition, renewal, deployment, and documentation.
Security Awareness and Training
Coordinate and administer the corporate Security Awareness Program.
Develop and deliver security awareness communications, training campaigns, and phishing simulations.
Analyze user participation metrics and identify improvement opportunities.
Conduct coaching sessions with employees requiring additional phishing awareness training.
Compliance and Governance
Assist with maintaining compliance with ISO 27001, NIST Cybersecurity Framework, and corporate security policies.
Support internal and external audits by collecting evidence and documenting security controls.
Participate in policy development, standards creation, and security procedure improvements.
Maintain accurate security documentation, inventories, and records.
Business Continuity and Disaster Recovery
Support backup, recovery, and disaster recovery processes.
Participate in periodic testing of business continuity and disaster recovery plans.
Assist in maintaining resilience and recoverability of critical technology services.
AI Security
Leverage AI-assisted security tools (e.g., Microsoft Security Copilot, CrowdStrike Charlotte AI) to accelerate alert triage, incident summarization, and threat investigations.
Support monitoring and governance of enterprise AI usage, including detection of unauthorized (“shadow AI”) applications and enforcement of AI acceptable use policies.
Assist with securing generative AI deployments, including Microsoft 365 Copilot data protection and Purview-based data governance and DLP controls for AI services.
Help identify and analyze AI-enabled threats such as AI-generated phishing, deepfake, and social engineering campaigns, and incorporate these risks into security awareness content.
Support AI risk assessments and contribute to AI governance activities aligned with emerging frameworks and standards.
Required Qualifications
Education
Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field; or equivalent professional experience.
Experience
Three to five years of cybersecurity, information security, or IT infrastructure experience.
Experience supporting enterprise security technologies in a Microsoft-centric environment.
Experience investigating security events and coordinating remediation activities.
Required Technical Knowledge
Security Operations Center (SOC) processes and methodologies
Incident response and breach investigation
Vulnerability management and remediation
Microsoft 365 and Azure security fundamentals
Endpoint Detection and Response (EDR/XDR) platforms
Security Information and Event Management (SIEM)
Email security technologies and phishing protection
Networking fundamentals including TCP/IP, DNS, DHCP, HTTP/S, TLS, VPN, and wireless security
Artificial Intelligence (AI) security fundamentals, including generative AI and large language model (LLM) risk concepts
Common AI threat vectors such as prompt injection, data leakage, model manipulation, and AI-generated phishing (e.g., OWASP Top 10 for LLM Applications)
Familiarity with AI-assisted security operations tools for alert triage, investigation, and reporting
Awareness of AI governance and risk frameworks such as the NIST AI Risk Management Framework (AI RMF)
Identity and Access Management (IAM)
Encryption, certificate management, and key management principles
Windows security administration and endpoint hardening
Preferred Qualifications
Technical Experience
CrowdStrike Falcon / Next-Gen SIEM
Microsoft Defender Security Suite
Microsoft Intune
Cisco Umbrella / Secure Access
Palo Alto, Cisco, and Meraki security platforms
KnowBe4 Security Awareness platform
Abnormal Email Security platform
Microsoft Entra ID
Security automation and scripting with PowerShell or Python
Microsoft Security Copilot or similar AI-assisted security operations tools
AI-powered threat detection and email security platforms (e.g., behavioral AI phishing detection)
Applying DLP and data governance controls to generative AI services (e.g., Microsoft Purview for Copilot)
Cloud security tools and monitoring platforms
Data Loss Prevention (DLP)
Microsoft Purview
Security compliance frameworks including ISO 27001 and NIST
Certifications
One or more of the following:
CompTIA Security+
Microsoft Security Certifications
SC-200
SC-300
SC-900
AI-900 (Microsoft Azure AI Fundamentals)
SSCP
GSEC
CEH
CISSP (preferred but not required)
Core Competencies
Analytical thinking
Problem solving
Attention to detail
Technical troubleshooting
Communication and presentation skills
Collaboration and teamwork
Customer service orientation
Initiative and ownership
Continuous learning mindset
Physical Requirements
Ability to sit and work at a computer for extended periods.
Ability to occasionally lift and move equipment up to 50 pounds.
Ability to travel domestically and internationally when required.
Travel Requirements
Midrex is an equal opportunity employer and is committed to providing employment opportunities to all qualified individuals without regard to race, color, religion, sex, national origin, age, disability, or any other protected status in accordance with all applicable laws. In compliance with the Americans with Disabilities Act, Midrex will provide reasonable accommodations to qualified individuals with disabilities and encourages both prospective and current employees to discuss potential accommodations with the People and Culture department.