Home › Companies › Metrosys › Security Operations Administrator
Security Operations Administrator
Metrosys · (Multiple States) · Active · JazzHR / ApplyToJob
Job facts
| Field | Value |
|---|---|
| Company | Metrosys |
| Title | Security Operations Administrator |
| Normalized title | - |
| Department / team | - |
| Location | (Multiple States) |
| Work model | - |
| Employment type | Contract |
| Salary | USD |
| Status | active |
| ATS provider | JazzHR / ApplyToJob |
| Posted / first seen | 2026-05-20 / 2026-05-30 |
| Changed / last seen | 2026-05-30 / 2026-06-06 |
Related slices
| Page | What it contains | Open |
|---|---|---|
| Company jobs | Active postings from Metrosys. | Open |
| Company breakdowns | Role, location, ATS, and work model facets for this company. | Open |
| ATS provider jobs | Active postings observed through JazzHR / ApplyToJob. | Open |
| Provider filtered search | The same provider as a filtered job collection. | Open |
| Lifecycle events | Open, update, close, and reopen events for this posting. | Open |
| Original posting | Canonical source or apply URL captured from the ATS. | Open |
Linked records
| Company | Metrosys |
| Source | 5504ef2f-a663-44cb-a4a8-da8c60abaa7e |
| ATS provider | JazzHR / ApplyToJob |
Description
Position Overview MetroSys is seeking a dependable and detail-oriented Security Operations Administrator for a short-term contract engagement supporting a client’s security monitoring and response operations. This role is responsible for reviewing, triaging, documenting, and responding to alerts generated across the client’s security platforms and infrastructure environment.
The ideal candidate has hands-on experience with endpoint security, email security, identity-related alerts, and incident response workflows, and can work independently while coordinating with help desk and infrastructure teams as needed.
This role is structured around a daily operational review window (~2 hours per day) while supporting a 24/7 alerting environment.
Key Responsibilities Review and respond to security alerts and tickets generated from the client’s monitoring and security platforms Investigate and triage alerts related to: Endpoint security events Email threats and phishing activity Suspicious authentication attempts Firewall and network security events Perform incident response activities including: Documentation Initial remediation actions Escalation and coordination Post-mortem reporting Validate email and phishing-related incidents using: Mimecast KnowBe4 / PhishER / PhishRip workflows Monitor and respond to endpoint alerts within: Sophos EDR/XDR Sophos Intercept X Advanced Investigate identity and authentication alerts from Microsoft environments, including: Sign-in risk events Suspicious token or authorization activity IP/location anomalies Support security investigations involving: Sophos firewall alerts Fortinet networking environments MFA and authentication platforms (including YubiKey environments) Coordinate with client help desk and infrastructure teams for remediation support and escalation handling Maintain accurate documentation of incidents, actions taken, and recommendations Required Qualifications 3+ years of experience in security administration, SOC operations, or security incident response Hands-on experience with: Mimecast KnowBe4 / phishing remediation workflows Sophos EDR/XDR and Intercept X Microsoft 365 security and sign-in risk analysis Understanding of: Security incident response workflows Endpoint and network security concepts Identity and access management fundamentals Experience reviewing and analyzing security alerts and event data Strong documentation and communication skills Ability to work independently and manage daily operational responsibilities efficiently
Full job record
| Job ID | 27117e06afe95182a5ec42485bdb8a06bd93f81c |
| Org ID | 75d9d64e-050e-4014-bff2-cbe0dad5e57e |
| Source ID | 5504ef2f-a663-44cb-a4a8-da8c60abaa7e |
| Board ID | 5504ef2f-a663-44cb-a4a8-da8c60abaa7e |
| Provider | jazzhr |
| Provider Job Key | e1QjyoTJck |
| Title | Security Operations Administrator |
| Normalized Title | — |
| Status | active |
| Active | yes |
| Location Text | (Multiple States) |
| Department | — |
| Team | — |
| Employment Type | contract |
| Workplace Type | — |
| Remote Policy | — |
| Country | (Multiple States) |
| Region | — |
| City | — |
| Salary Raw | USD |
| Salary Min | — |
| Salary Max | — |
| Salary Currency | — |
| Salary Period | — |
| Source URL | https://metrosys.applytojob.com/apply/e1QjyoTJck/Security-Operations-Administrator |
| Apply URL | https://metrosys.applytojob.com/apply/e1QjyoTJck/Security-Operations-Administrator |
| First Seen At | 2026-05-30 05:49:21Z |
| Last Seen At | 2026-06-06 20:19:12Z |
| Last Checked At | 2026-06-06 20:19:12Z |
| Last Changed At | 2026-05-30 05:49:21Z |
| Inactive At | — |
| Source Posted At | 2026-05-20 00:00:00Z |
| Source Updated At | — |
| Raw Payload Uri | s3://job-postings-prod-raw-590183727216/raw/provider=jazzhr/board=metrosys/date=2026-06-06/2026-06-06T20-19-10-358Z-f233037de224ddd860fec0f66aa8991287af655724539a9f79bfefba7cbe227b.json |
Event Fields
{
"content_hash": "35c3d72f6156c646f2909030ce947ad5adc06c0730f075346f5179b131df341d",
"source_hash": "03d4d5e2532bc93fffb9302738f93ecc43919de38dc4d77b82508eb5db6798bf",
"last_changed_at": "2026-05-30T05:49:21.475Z",
"active_status": "active"
}Parsed Structured
{
"language": "en",
"location": {
"raw": "(Multiple States)",
"city": null,
"region": null,
"country": "(Multiple States)",
"is_remote": false,
"confidence": 0.8
},
"salary_max": null,
"salary_min": null,
"inferred_at": "2026-06-06T20:19:12.655Z",
"launch_scope": {
"reason": "jazzhr_production_catalog",
"included": true,
"location": {
"raw": "(Multiple States)",
"city": null,
"region": null,
"country": "(Multiple States)",
"is_remote": false,
"confidence": 0.8
},
"countries": [
"(Multiple States)"
]
},
"remote_policy": null,
"salary_period": null,
"workplace_type": null,
"salary_currency": null
}Extensions
{}Native Structured
{
"detail": {
"url": "https://metrosys.applytojob.com/apply/jobs/details/e1QjyoTJck?&",
"heading": "Security Operations Administrator",
"html_title": "JazzHR » Job Listings",
"canonical_url": "https://metrosys.applytojob.com/apply/e1QjyoTJck/Security-Operations-Administrator",
"description_html": "<h3><strong>Position Overview</strong></h3><p>MetroSys is seeking a dependable and detail-oriented <strong>Security Operations Administrator</strong> for a short-term contract engagement supporting a client’s security monitoring and response operations. This role is responsible for reviewing, triaging, documenting, and responding to alerts generated across the client’s security platforms and infrastructure environment.</p><p>The ideal candidate has hands-on experience with endpoint security, email security, identity-related alerts, and incident response workflows, and can work independently while coordinating with help desk and infrastructure teams as needed.</p><p>This role is structured around a <strong>daily operational review window (~2 hours per day)</strong> while supporting a 24/7 alerting environment.</p><hr><h3><strong>Key Responsibilities</strong></h3><ul><li>Review and respond to security alerts and tickets generated from the client’s monitoring and security platforms</li><li>Investigate and triage alerts related to:<ul><li>Endpoint security events</li><li>Email threats and phishing activity</li><li>Suspicious authentication attempts</li><li>Firewall and network security events</li></ul></li><li>Perform incident response activities including:<ul><li>Documentation</li><li>Initial remediation actions</li><li>Escalation and coordination</li><li>Post-mortem reporting</li></ul></li><li>Validate email and phishing-related incidents using:<ul><li><strong>Mimecast</strong></li><li><strong>KnowBe4 / PhishER / PhishRip</strong> workflows</li></ul></li><li>Monitor and respond to endpoint alerts within:<ul><li><strong>Sophos EDR/XDR</strong></li><li><strong>Sophos Intercept X Advanced</strong></li></ul></li><li>Investigate identity and authentication alerts from Microsoft environments, including:<ul><li>Sign-in risk events</li><li>Suspicious token or authorization activity</li><li>IP/location anomalies</li></ul></li><li>Support security investigations involving:<ul><li>Sophos firewall alerts</li><li>Fortinet networking environments</li><li>MFA and authentication platforms (including YubiKey environments)</li></ul></li><li>Coordinate with client help desk and infrastructure teams for remediation support and escalation handling</li><li>Maintain accurate documentation of incidents, actions taken, and recommendations</li></ul><hr><h3><strong>Required Qualifications</strong></h3><ul><li><strong>3+ years</strong> of experience in security administration, SOC operations, or security incident response</li><li>Hands-on experience with:<ul><li>Mimecast</li><li>KnowBe4 / phishing remediation workflows</li><li>Sophos EDR/XDR and Intercept X</li><li>Microsoft 365 security and sign-in risk analysis</li></ul></li><li>Understanding of:<ul><li>Security incident response workflows</li><li>Endpoint and network security concepts</li><li>Identity and access management fundamentals</li></ul></li><li>Experience reviewing and analyzing security alerts and event data</li><li>Strong documentation and communication skills</li><li>Ability to work independently and manage daily operational responsibilities efficiently</li></ul>",
"description_text": "Position Overview\n MetroSys is seeking a dependable and detail-oriented Security Operations Administrator for a short-term contract engagement supporting a client’s security monitoring and response operations. This role is responsible for reviewing, triaging, documenting, and responding to alerts generated across the client’s security platforms and infrastructure environment.\n The ideal candidate has hands-on experience with endpoint security, email security, identity-related alerts, and incident response workflows, and can work independently while coordinating with help desk and infrastructure teams as needed.\n This role is structured around a daily operational review window (~2 hours per day) while supporting a 24/7 alerting environment.\n Key Responsibilities\n Review and respond to security alerts and tickets generated from the client’s monitoring and security platforms\n Investigate and triage alerts related to: Endpoint security events\n Email threats and phishing activity\n Suspicious authentication attempts\n Firewall and network security events\n Perform incident response activities including: Documentation\n Initial remediation actions\n Escalation and coordination\n Post-mortem reporting\n Validate email and phishing-related incidents using: Mimecast\n KnowBe4 / PhishER / PhishRip workflows\n Monitor and respond to endpoint alerts within: Sophos EDR/XDR\n Sophos Intercept X Advanced\n Investigate identity and authentication alerts from Microsoft environments, including: Sign-in risk events\n Suspicious token or authorization activity\n IP/location anomalies\n Support security investigations involving: Sophos firewall alerts\n Fortinet networking environments\n MFA and authentication platforms (including YubiKey environments)\n Coordinate with client help desk and infrastructure teams for remediation support and escalation handling\n Maintain accurate documentation of incidents, actions taken, and recommendations\n Required Qualifications\n 3+ years of experience in security administration, SOC operations, or security incident response\n Hands-on experience with: Mimecast\n KnowBe4 / phishing remediation workflows\n Sophos EDR/XDR and Intercept X\n Microsoft 365 security and sign-in risk analysis\n Understanding of: Security incident response workflows\n Endpoint and network security concepts\n Identity and access management fundamentals\n Experience reviewing and analyzing security alerts and event data\n Strong documentation and communication skills\n Ability to work independently and manage daily operational responsibilities efficiently",
"jsonld_jobposting": {
"url": "https://metrosys.applytojob.com/apply/e1QjyoTJck/Security-Operations-Administrator",
"@type": "JobPosting",
"title": "Security Operations Administrator",
"@context": "http://schema.org/",
"baseSalary": {
"@type": "MonetaryAmount",
"value": {
"@type": "QuantitativeValue",
"maxValue": 60,
"minValue": 40,
"unitText": "HOUR"
},
"currency": "USD"
},
"datePosted": "2026-05-20",
"description": "<h3><strong>Position Overview</strong></h3><p>MetroSys is seeking a dependable and detail-oriented <strong>Security Operations Administrator</strong> for a short-term contract engagement supporting a client’s security monitoring and response operations. This role is responsible for reviewing, triaging, documenting, and responding to alerts generated across the client’s security platforms and infrastructure environment.</p><p>The ideal candidate has hands-on experience with endpoint security, email security, identity-related alerts, and incident response workflows, and can work independently while coordinating with help desk and infrastructure teams as needed.</p><p>This role is structured around a <strong>daily operational review window (~2 hours per day)</strong> while supporting a 24/7 alerting environment.</p><hr><h3><strong>Key Responsibilities</strong></h3><ul><li>Review and respond to security alerts and tickets generated from the client’s monitoring and security platforms</li><li>Investigate and triage alerts related to:<ul><li>Endpoint security events</li><li>Email threats and phishing activity</li><li>Suspicious authentication attempts</li><li>Firewall and network security events</li></ul></li><li>Perform incident response activities including:<ul><li>Documentation</li><li>Initial remediation actions</li><li>Escalation and coordination</li><li>Post-mortem reporting</li></ul></li><li>Validate email and phishing-related incidents using:<ul><li><strong>Mimecast</strong></li><li><strong>KnowBe4 / PhishER / PhishRip</strong> workflows</li></ul></li><li>Monitor and respond to endpoint alerts within:<ul><li><strong>Sophos EDR/XDR</strong></li><li><strong>Sophos Intercept X Advanced</strong></li></ul></li><li>Investigate identity and authentication alerts from Microsoft environments, including:<ul><li>Sign-in risk events</li><li>Suspicious token or authorization activity</li><li>IP/location anomalies</li></ul></li><li>Support security investigations involving:<ul><li>Sophos firewall alerts</li><li>Fortinet networking environments</li><li>MFA and authentication platforms (including YubiKey environments)</li></ul></li><li>Coordinate with client help desk and infrastructure teams for remediation support and escalation handling</li><li>Maintain accurate documentation of incidents, actions taken, and recommendations</li></ul><hr><h3><strong>Required Qualifications</strong></h3><ul><li><strong>3+ years</strong> of experience in security administration, SOC operations, or security incident response</li><li>Hands-on experience with:<ul><li>Mimecast</li><li>KnowBe4 / phishing remediation workflows</li><li>Sophos EDR/XDR and Intercept X</li><li>Microsoft 365 security and sign-in risk analysis</li></ul></li><li>Understanding of:<ul><li>Security incident response workflows</li><li>Endpoint and network security concepts</li><li>Identity and access management fundamentals</li></ul></li><li>Experience reviewing and analyzing security alerts and event data</li><li>Strong documentation and communication skills</li><li>Ability to work independently and manage daily operational responsibilities efficiently</li></ul>",
"jobLocation": {
"@type": "Place",
"address": {
"@type": "PostalAddress",
"postalCode": "",
"addressRegion": "(Multiple States)",
"addressLocality": ""
}
},
"validThrough": "2026-08-18",
"uniqueJobCode": "job_20260520204501_R6A6TJKA2OG9M1WV",
"employmentType": "CONTRACTOR",
"jobLocationType": "TELECOMMUTE",
"hiringOrganization": {
"logo": "https://s3.amazonaws.com/resumator/customer_20180126171527_FXPC7RC0DACCJARB/logos/20180213171524_Metro_Banner.jpg",
"name": "MetroSys",
"@type": "Organization",
"sameAs": "http://www.metro-sys.com"
},
"experienceRequirements": "Mid Level",
"applicantLocationRequirements": {
"name": "US",
"@type": "Country"
}
}
},
"list_job": {
"id": "e1QjyoTJck",
"title": "Security Operations Administrator",
"detailUrl": "https://metrosys.applytojob.com/apply/jobs/details/e1QjyoTJck?&"
},
"detail_errors": []
}Get this page with API
Rendered from the bluedoor Job Postings API. Reproduce it:
GET https://api.bluedoor.sh/job-postings/v1/jobs/27117e06afe95182a5ec42485bdb8a06bd93f81c?include=descriptionJSONGET https://api.bluedoor.sh/job-postings/v1/orgs/75d9d64e-050e-4014-bff2-cbe0dad5e57eJSONGET https://api.bluedoor.sh/job-postings/v1/sources/5504ef2f-a663-44cb-a4a8-da8c60abaa7eJSONGET https://api.bluedoor.sh/job-postings/v1/jobs/27117e06afe95182a5ec42485bdb8a06bd93f81c/eventsJSON