IT / Information Security Analyst II
About the roleBloom Credit is hiring an IT / Information Security Analyst II to own day-to-day IT operations and hands-on security work across a fully remote Mac fleet. This is a combined role: roughly 50/50 IT and IS in theory, with the mix shifting by project and business need.
You will work with strong support from the Head of IT/IS and partner across the entire organization—engineering, compliance, product, people ops, and other functions—as identity, devices, access, and security touch every team. You operate with high autonomy in a remote environment.
We maintain SOC 2 and PCI DSS (self-attested) obligations. Experience supporting audits and evidence collection is valued.
What you'll own (Analyst II)IT operations- Endpoint lifecycle for a remote Mac fleet (provisioning, configuration, support, offboarding)
- Identity and access: JumpCloud directory / IdP / MDM, SSO app lifecycle, joiner–mover–leaver flows
- Google Workspace administration (mail, groups, Drive, Meet) and related automation where useful
- Helpdesk / end-user support: clear triage, resolution, and documentation
- Asset lifecycle coordination (procurement, shipping, disposition) with existing tooling
- Prefer native integrations and scripted automation over repetitive console click-ops; keep manual break-glass and validation paths documented
- CrowdStrike EDR health, detections, containment, and response coordination
- DLP controls and data-handling practices in daily ops, including policy tuning and exception handling
- SIEM / security signal work in Datadog (alerting, investigation support, tuning with stakeholders)
- Security hygiene: least privilege, access reviews, device posture, exception handling
- Support SOC 2 and PCI evidence gathering with Compliance; keep controls operational, not theoretical
- Zero Trust mindset preferred (identity-centric access, device trust, least privilege)—not required if you learn fast in this model
- Endpoint lifecycle for a remote Mac fleet (provisioning, configuration, support, offboarding)
- Identity and access: JumpCloud directory / IdP / MDM, SSO app lifecycle, joiner–mover–leaver flows
- Google Workspace administration (mail, groups, Drive, Meet) and related automation where useful
- Helpdesk / end-user support: clear triage, resolution, and documentation
- Asset lifecycle coordination (procurement, shipping, disposition) with existing tooling
- Prefer native integrations and scripted automation over repetitive console click-ops; keep manual break-glass and validation paths documented
- CrowdStrike EDR health, detections, containment, and response coordination
- DLP controls and data-handling practices in daily ops, including policy tuning and exception handling
- SIEM / security signal work in Datadog (alerting, investigation support, tuning with stakeholders)
- Security hygiene: least privilege, access reviews, device posture, exception handling
- Support SOC 2 and PCI evidence gathering with Compliance; keep controls operational, not theoretical
- Zero Trust mindset preferred (identity-centric access, device trust, least privilege)—not required if you learn fast in this model
No single path is required. Degrees, certifications, and on-the-job experience are weighed equally.
- College - Associate's or bachelor's in IT, cybersecurity, CS, or related—or equivalent practical experience
- Certifications - 1–2 relevant certs (e.g. Security+, Google Workspace Admin, JumpCloud, CrowdStrike, CySA+, GSEC) or equivalent demonstrated depth
- On-the-job - ~4–6 years with ownership beyond ticket-only work; can run identity/endpoint/security ops with light oversight
- Fully remote; no traditional office network—access is identity- and device-centric
- Prefer native vendor integrations, then maintained scripts/automation, then console click-ops when that is the right business case
- High-impact actions require clear scope, blast radius, and rollback thinking; Head of IT/IS approves before execution
- Head of IT/IS available for support, escalation, and prioritization—not day-to-day micromanagement
- Clear, concise written communication across the org
- Calm triage under interruption (helpdesk + security signals)
- Ownership of outcomes without waiting to be told
- Collaborative posture—enable teams, don't gatekeep for its own sake
Similar Jobs at Bloom Credit
What you need to know about the Colorado Tech Scene
Key Facts About Colorado Tech
- Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
- Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
- Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
- Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

