IT SECURITY ANALYST II at Kingspan Group in Deland, FL
- Company: Kingspan Group
- Location: Deland, FL
- Posted: Sep 23, 2026
- Type: Full-Time
- Experience: 4+ years
Overview
Kingspan Americas is part of Kingspan Group, a global leader in high‑performance insulation and building envelope solutions. With operations in more than 80 countries, the Group is committed to advancing a net‑zero emissions future and delivering sustainable, high‑performance products for buildings …
Job description
- Kingspan Americas is part of Kingspan Group, a global leader in high‑performance insulation and building envelope solutions. With operations in more than 80 countries, the Group is committed to advancing a net‑zero emissions future and delivering sustainable, high‑performance products for buildings around the world.
- Across North America and LATAM, Kingspan Americas includes multiple business units, 25 manufacturing sites, and continues to grow through ongoing investment and strategic acquisitions. The region operates within a decentralized model, with each business managing its own systems and applications while leveraging shared IT infrastructure and support.
- Kingspan Americas IT functions as a divisional shared service, providing the core network, infrastructure, and frameworks that enable each business to innovate, streamline processes, and adopt new technologies, including automation and AI, to drive efficiency and growth.
- We are looking for an IT Securities Analyst II for our Deland, FL office!
- This is a full time, onsite, in-person position
- Sponsorship is not available for this opportunity
- Summary: The IT Security Analyst II is the senior hands-on technical practitioner on the Kingspan Americas security team and the primary responder for security incidents across the organization. This role leads incident response, drives vulnerability assessment and remediation validation, and builds out the threat-hunting capability, leveraging deep expertise in CrowdStrike and the broader security stack to detect and stop malicious activity before it becomes a breach.
- The Analyst II operates with a high degree of autonomy. The analyst manages day-to-day security operations with minimal direction and is expected to prioritize their work, drive investigations to closure, and recognize when a finding requires escalation to, or reporting through, the IT Security Manager.
Responsibilities
- Incident Response (Primary)
- Incident Leadership: Serve as primary responder and technical lead for security incidents: detection, triage, containment, eradication, and recovery. Act as subject matter expert where exploitation is suspected.
- IR Program: Maintain and improve incident response playbooks and runbooks. Document root cause analysis and lessons learned and drive corrective actions to completion.
- Readiness: Support tabletop exercises and IR readiness activities across business units.
- Phishing & User Reports: Oversee analysis of user-reported phishing and suspicious emails. Analyze headers, links, and attachments; initiate remediation such as blocking senders and purging inboxes through the FreshService ticketing system.
- Threat Hunting & Detection Engineering
- Proactive Hunting: Build and mature the threat hunting practice: form hypotheses grounded in MITRE ATT&CK, hunt across endpoint, network, and identity telemetry, and translate findings into new detections and monitoring coverage.
- CrowdStrike Expertise: Serve as the resident CrowdStrike expert. Advanced use of Falcon for detection, investigation, real-time response, and custom IOA/IOC development. Tune detections to reduce noise and close visibility gaps.
- Vulnerability & Patch Management
- Assessment & Validation: Run vulnerability scanning (Qualys, Tanium), prioritize findings by exploitability and business risk, and validate patch cycle effectiveness through scan data and reporting. Identify systemic gaps and escalate.
- Remediation Guidance: Issue clear remediation guidance to system administrators, who execute the patch cycles, and track findings through to closure.
- Emerging Threats: Rapidly assess emerging high-severity CVEs and zero-day exploits, determine exposure across divisions, and drive time-sensitive remediation with administrators.
- Security Operations & Tool Management
- Tool Ownership: Manage, tune, and maintain enterprise security tooling (CrowdStrike, Cisco Umbrella, Meraki, Qualys, Tanium) and translate security requirements into technical controls and configuration standards. Partner with platform and service owners to close control gaps.
- Endpoint Policy Governance: Review, standardize, and maintain security policies within Microsoft Intune (compliance policies, configuration profiles, and security baselines). Partner with endpoint administrators and the service desk, who retain platform ownership, to move policy management from one-off changes to a documented review cadence.
- Reporting: Develop and present security metrics, incident summaries, and program status to IT leadership in clear, business-relevant terms.
- Security Training & Awareness
- Awareness Program: Implement and maintain security training and awareness campaigns, including phishing simulations, that educate staff on cyber hygiene and best practices. Track completion and results and report findings to the IT Security Manager.
- General
- Support audit and compliance activities by providing security evidence, logs, and control documentation as requested.
- Verify the security posture of third-party vendors and requested software in support of onboarding and procurement.
- Follow the Group Code of Conduct and Group Compliance.
- Follow Compliance requirements per “KNA-SOP-1705 Compliance Roles and Responsibilities.”
- Perform all other duties as assigned.
Requirements
- Experience: Minimum 4 years of hands-on experience in cybersecurity, SOC operations, incident response, or threat hunting.
- CrowdStrike: Demonstrated hands-on experience with CrowdStrike Falcon (detection, investigation, real-time response). CrowdStrike certifications (CCFA, CCFR, CCFH) are a strong plus.
- Autonomy: Runs investigations and technical projects end-to-end with minimal supervision.
- Education: Bachelor’s degree in Computer Science, Information Security, or equivalent professional experience.
- Certifications: Preferred certifications include Security+, CySA+, GCIH, GCFA, GCIA, CISSP, or other industry-relevant security certifications.
- Industry: Experience in medium to large-scale multinational manufacturing, retail, or similar industry is advantageous.
- Communication: Ability to explain security risks, incident findings, and remediation needs clearly to technical and non-technical audiences.
- Language: Bilingual proficiency (English/Spanish) is preferred.
- Networking: Deep understanding of standard network protocols (TCP/IP, ARP, ICMP, DHCP, DNS, HTTP, SNMP) and proficiency with packet analysis tools.
- Tool Proficiency: CrowdStrike, Cisco Umbrella, Meraki, Qualys, Microsoft Intune (security policy administration), Power BI, Lansweeper, Tanium.
- IT Service Management: Experience using ticketing systems such as FreshService, ServiceNow, or Jira to manage security workflows.
- Frameworks: Working knowledge of NIST, CIS, and ISO 27001 standards.
Skills
Required
- Proficiency with packet analysis tools
- CrowdStrike
- Cisco Umbrella
- Meraki
- Qualys
- Power BI
- Lansweeper
- Tanium
Preferred
- Bilingual proficiency (English/Spanish)
Benefits
- We offer a comprehensive benefits package including 401k with company match, Medical, Dental, Vision, Identity Theft Protection, Critical Illness, Accident, Hospital Indemnity, Pregnancy and Parental Leave, Fitness Reimbursement, Educational Assistance, Life, AD&D, Short- and Long-Term Disability, and Life Assistance Program.