Job Description
Job Title:  IT - Cybersecurity Analyst
Posting Start Date:  9/9/26
Division:  Corporate
Posting Area:  IT + Information Systems
Job Location:  Cebu City, Philippines, Meridian, ID

Job Title: IT Cybersecurity Analyst

Location: Meridian, ID

Starting Salary: $75,000 - $95,000 (depending on experience)

Employment Type: Full-Time, Salary

Work Environment: Hybrid (4 days in-office, 1 day remote)

 

Summary of Company Benefits:

  • Health, Dental, and Vision Insurance
  • Health Savings Account (HSA)
  • Flexible Spending Account (FSA)
  • 401(k) with an Employer Match
  • Group Term Life Insurance and AD&D
  • Employer Paid Long-Term & Short-Term Disability
  • Voluntary Supplemental Hospital and Accident Plans
  • Employee Assistance Program
  • 8 Company Paid Holidays & 1 Floating Holiday
  • Progressive Paid Time Off (PTO) Accruals
  • Annual Salary Incentive Bonus

 

About Woodgrain:
Woodgrain is one of the top millwork operations in the world, with locations throughout the United States and Chile. With 70 years of quality manufacturing craftsmanship and service, Woodgrain is a top producer of mouldings, doors, and windows, as well as a premier distributor of specialty building products. Woodgrain Inc. is headquartered in Fruitland, Idaho with six divisions and over 45 manufacturing and warehouse facilities in the United States and South America. Since 1954, Woodgrain is proud to be family owned and operated. 

Job Summary:
The Cybersecurity Analyst is responsible for proactively monitoring, detecting, and responding to cybersecurity threats to safeguard the organization’s data, systems, and business operations. This role plays a key part in identifying vulnerabilities, mitigating risks, and ensuring the integrity and confidentiality of critical information assets. The analyst will work collaboratively across teams to detect and investigate suspicious activity, respond to both intentional and unintentional security incidents, and support recovery efforts that address root causes. This position requires a strong understanding of threat landscapes, incident response protocols, and cybersecurity best practices to protect the organization’s infrastructure and personnel from evolving cyber threats.



Duties & Responsibilities:

  • Administer, maintain, and optimize enterprise security tools and technologies, including:
    • Endpoint Detection and Response (EDR)
    • Cloud security monitoring and reporting
    • Security Information and Event Management (SIEM)
    • Firewall and network traffic analysis
    • Vulnerability management and security assessment tools
    • Identity and Access Management (IAM) technologies
  • Implement, review, and maintain secure configurations across endpoints, servers, cloud platforms, identity systems, and other enterprise technologies using established security standards and industry best practices.
  • Support the implementation and ongoing administration of cloud identity and access management solutions, with an emphasis on Microsoft Entra ID and Microsoft 365.
  • Assist with the design, implementation, and maintenance of identity security controls, including:
    • Multi-Factor Authentication (MFA)
    • Conditional Access
    • Single Sign-On (SSO)
    • Self-Service Password Reset (SSPR)
    • Role-Based Access Control (RBAC)
    • Privileged access controls
    • Identity lifecycle and access review processes
  • Analyze identity and access environments to identify excessive permissions, anomalous access, stale accounts, and other conditions that may introduce security risk.
  • Work with Infrastructure, Application, ERP, and other technical teams to implement secure identity integrations and authentication methods across on-premises and cloud environments.
  • Evaluate and optimize configurations of internal and external security technologies in collaboration with cross-functional teams.
  • Ensure security technologies remain reliable, appropriately configured, and aligned with organizational risk management strategies.
  • Implement and maintain Center for Internet Security (CIS) Controls, CIS Benchmarks, and other recognized secure configuration standards.
  • Identify configuration weaknesses, security control gaps, and opportunities to reduce attack surface across enterprise systems.
  • Conduct vulnerability assessments and risk analyses using industry-standard scanning and assessment tools.
  • Research emerging threats, technologies, and security capabilities and recommend practical improvements to strengthen the organization’s security posture.
  • Monitor the evolving threat landscape and assist in developing technical controls and defensive strategies to mitigate identified risks.
  • Lead and support the security incident response lifecycle, including detection, investigation, containment, eradication, recovery, and post-incident review.
  • Analyze security alerts and events to identify suspicious activity, compromised accounts, endpoint threats, or other indicators of compromise.
  • Contribute to incident reporting and provide technical guidance on appropriate response and remediation activities.
  • Perform internal security assessments and support external audits to identify control gaps and opportunities for improvement.
  • Assist with security questionnaires, audit requests, risk assessments, and security architecture reviews.
  • Develop and maintain security policies, procedures, technical standards, and operational documentation.
  • Support security awareness and role-based security training initiatives.
  • Monitor and manage the IT Security ticket queue, ensuring security incidents, requests, and investigations are addressed appropriately and in a timely manner.
  • Act as a liaison between Security, Infrastructure, Application, and business teams to help ensure security requirements are understood and incorporated into technical solutions.


Requirements:

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline. Equivalent professional experience may be considered in lieu of a degree.
  • At least 2 years of experience in Cybersecurity, IT Infrastructure, Networking, Systems Administration, Identity and Access Management, or a comparable technical field.
  • Hands-on experience implementing, administering, troubleshooting, or assessing security technologies in an enterprise environment.
  • Experience with Microsoft identity and cloud technologies, preferably including Microsoft Entra ID, Microsoft 365, Azure, Active Directory, or hybrid identity environments.
  • Working knowledge of identity and access management concepts, including authentication, authorization, MFA, SSO, RBAC, least privilege, and privileged access.
  • Experience implementing or maintaining secure system configurations and applying recognized security standards or configuration baselines.
  • Demonstrated experience investigating security events, alerts, or cyber incidents.
  • Preference will be given to candidates holding one or more industry-recognized certifications such as Security+, CySA+, SC-300, AZ-500, PenTest+, PNPT, CISA, CISSP, or equivalent certifications.
  • Working knowledge across at least three (3) cybersecurity domains, including:
    • Identity and Access Management (IAM)
    • Cloud Security
    • Infrastructure Security
    • Endpoint Detection and Response (EDR)
    • Detection Engineering
    • Network Security
    • Vulnerability Management
    • Digital Forensics & Incident Response
    • Application Security
    • Risk Management
    • Threat Intelligence
    • Security Configuration Management
    • Red Team/Adversarial Security

 

Additional Skills:

  • Strong ability to communicate technical security concepts clearly to both technical and non-technical audiences.
  • Ability to analyze incomplete or ambiguous information and make informed, risk-based decisions.
  • Adaptable and effective in a dynamic enterprise technology environment.
  • Strong troubleshooting skills with the ability to investigate issues across identity, endpoint, network, cloud, and application environments.
  • Understanding of secure configuration principles, system hardening, least privilege, and defense-in-depth strategies.
  • Familiarity with Microsoft Entra ID capabilities such as Conditional Access, MFA, Enterprise Applications, App Registrations, authentication methods, identity protection, and access reviews.
  • General understanding of Active Directory and hybrid identity architectures.
  • Familiarity with scripting and automation technologies such as PowerShell, Python, Bash, or JavaScript for security administration, auditing, data analysis, and automation.
  • Working knowledge of the MITRE ATT&CK Framework and common attacker tactics, techniques, and procedures (TTPs).
  • Understanding of networking concepts, protocols, firewall technologies, and network security methodologies.
  • Experience with Microsoft technologies including Windows Server, Windows operating systems, Azure, Microsoft 365, and Active Directory.
  • Experience working with SIEM, EDR, vulnerability management, or other enterprise security platforms.
  • Familiarity with cybersecurity frameworks, regulatory requirements, and security standards such as CIS Controls, CIS Benchmarks, NIST Cybersecurity Framework, or similar frameworks.
  • Ability to effectively communicate in English, both verbally and in writing. Additional languages are preferred.


Physical Demands: 

The physical demands and work environment are representative of a typical office environment. While performing the duties of this job, the employee is occasionally required to stand; walk; sit; use hands to finger, handle, or feel objects, tools or controls; reach with hands and arms; climb stairs; balance; stoop, kneel, crouch or crawl; talk and hear. The employee must occasionally lift or move up to 25 pounds. 

Travel: This position does not require travel to other Woodgrain locations. 

 

Applications will be accepted until the position has been filled

 

____________________________________________________________

Woodgrain is an Equal Employment Opportunity Employer. We are committed to providing an environment of mutual respect where equal employment opportunities are available to all applicants and employees without regard to race, color, religion, sex, pregnancy, national origin, age, physical and mental disability, marital status, sexual orientation, gender identity, gender expression, genetic information, military and veteran status, and any other characteristic protected by applicable law. Woodgrain is a drug, alcohol, and tobacco-free workplace. All offers of employment are contingent upon pre-employment background and drug screening, and some positions require a fitness for duty test.