IT / Information Security Analyst II

Posted Yesterday
Hiring Remotely in USA
Remote
Senior level
Fintech • Financial Services
Bloom provides modern tools and APIs for developers and fintech innovators to work with credit bureaus and credit data
The Role
Own day-to-day IT and information security operations for a fully remote Mac fleet. Responsibilities include endpoint lifecycle management, identity and access administration, Google Workspace, helpdesk support, asset coordination, CrowdStrike EDR monitoring, DLP controls, Datadog SIEM alerting, security hygiene, access reviews, and SOC 2 and PCI evidence collection. The role requires autonomous ownership, automation, clear documentation, cross-functional collaboration, and approximately 4–6 years of experience beyond ticket-only support.
Summary Generated by Built In

IT / Information Security Analyst II 

About the role

Bloom Credit is hiring an IT / Information Security Analyst II to own day-to-day IT operations and hands-on security work across a fully remote Mac fleet. This is a combined role: roughly 50/50 IT and IS in theory, with the mix shifting by project and business need.

You will work with strong support from the Head of IT/IS and partner across the entire organization—engineering, compliance, product, people ops, and other functions—as identity, devices, access, and security touch every team. You operate with high autonomy in a remote environment.

We maintain SOC 2 and PCI DSS (self-attested) obligations. Experience supporting audits and evidence collection is valued.

What you'll own (Analyst II)IT operations
  • Endpoint lifecycle for a remote Mac fleet (provisioning, configuration, support, offboarding)
  • Identity and access: JumpCloud directory / IdP / MDM, SSO app lifecycle, joiner–mover–leaver flows
  • Google Workspace administration (mail, groups, Drive, Meet) and related automation where useful
  • Helpdesk / end-user support: clear triage, resolution, and documentation
  • Asset lifecycle coordination (procurement, shipping, disposition) with existing tooling
  • Prefer native integrations and scripted automation over repetitive console click-ops; keep manual break-glass and validation paths documented
Information security
  • CrowdStrike EDR health, detections, containment, and response coordination
  • DLP controls and data-handling practices in daily ops, including policy tuning and exception handling
  • SIEM / security signal work in Datadog (alerting, investigation support, tuning with stakeholders)
  • Security hygiene: least privilege, access reviews, device posture, exception handling
  • Support SOC 2 and PCI evidence gathering with Compliance; keep controls operational, not theoretical
  • Zero Trust mindset preferred (identity-centric access, device trust, least privilege)—not required if you learn fast in this model
What you'll own (Analyst II)IT operations
  • Endpoint lifecycle for a remote Mac fleet (provisioning, configuration, support, offboarding)
  • Identity and access: JumpCloud directory / IdP / MDM, SSO app lifecycle, joiner–mover–leaver flows
  • Google Workspace administration (mail, groups, Drive, Meet) and related automation where useful
  • Helpdesk / end-user support: clear triage, resolution, and documentation
  • Asset lifecycle coordination (procurement, shipping, disposition) with existing tooling
  • Prefer native integrations and scripted automation over repetitive console click-ops; keep manual break-glass and validation paths documented
Information security
  • CrowdStrike EDR health, detections, containment, and response coordination
  • DLP controls and data-handling practices in daily ops, including policy tuning and exception handling
  • SIEM / security signal work in Datadog (alerting, investigation support, tuning with stakeholders)
  • Security hygiene: least privilege, access reviews, device posture, exception handling
  • Support SOC 2 and PCI evidence gathering with Compliance; keep controls operational, not theoretical
  • Zero Trust mindset preferred (identity-centric access, device trust, least privilege)—not required if you learn fast in this model
Education and credentials

No single path is required. Degrees, certifications, and on-the-job experience are weighed equally.

  • College - Associate's or bachelor's in IT, cybersecurity, CS, or related—or equivalent practical experience
  • Certifications - 1–2 relevant certs (e.g. Security+, Google Workspace Admin, JumpCloud, CrowdStrike, CySA+, GSEC) or equivalent demonstrated depth
  • On-the-job - ~4–6 years with ownership beyond ticket-only work; can run identity/endpoint/security ops with light oversight
How we work
  • Fully remote; no traditional office network—access is identity- and device-centric
  • Prefer native vendor integrations, then maintained scripts/automation, then console click-ops when that is the right business case
  • High-impact actions require clear scope, blast radius, and rollback thinking; Head of IT/IS approves before execution
  • Head of IT/IS available for support, escalation, and prioritization—not day-to-day micromanagement
Soft skills that matter here
  • Clear, concise written communication across the org
  • Calm triage under interruption (helpdesk + security signals)
  • Ownership of outcomes without waiting to be told
  • Collaborative posture—enable teams, don't gatekeep for its own sake

Skills Required

  • Associate's or bachelor's degree in IT, cybersecurity, computer science, or a related field, or equivalent practical experience
  • Approximately 4–6 years of experience with ownership beyond ticket-only work
  • Ability to run identity, endpoint, and security operations with light oversight
  • One or two relevant certifications, such as Security+, Google Workspace Admin, JumpCloud, CrowdStrike, CySA+, or GSEC, or equivalent demonstrated expertise
  • Experience with endpoint lifecycle management for a remote Mac fleet
  • Experience administering identity and access, SSO, MDM, and joiner-mover-leaver workflows
  • Experience administering Google Workspace
  • Experience with CrowdStrike EDR health, detections, containment, and response coordination
  • Experience with DLP controls and data-handling practices
  • Experience with SIEM or security signal work in Datadog
  • Experience supporting SOC 2 and PCI evidence gathering
  • Zero Trust experience or familiarity with identity-centric access, device trust, and least privilege
  • Clear written communication, calm triage, ownership, and collaborative cross-functional working style

What the Team is Saying

Scott
Teagan

Bloom Credit Compensation & Benefits Highlights

  • Healthcare Strength Healthcare coverage is considered comprehensive, with Bloom paying up to 100% of individual medical, dental, and vision premiums from the first month and including mental health, transgender care, and an EAP. Multiple plan options plus HSA/FSA access reinforce medical breadth.
  • Equity Value & Accessibility Equity is provided to every employee upon joining and described as “meaningful,” indicating accessible ownership across the organization. This accompanies a company‑sponsored 401(k) and other financial protections.
  • Leave & Time Off Breadth Time off is positioned as generous, featuring unlimited PTO and sick days, paid holidays and volunteer time, and monthly meeting‑free “Bloom Days.” Parental leave, family medical leave, and a return‑to‑work program add to overall leave depth.

Bloom Credit Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL
36 Employees
Year Founded: 2016

What We Do

Bloom Credit helps companies launch lending products, report consumers' payments, and create innovative credit experiences. We do this by providing our clients with the data they need from all three credit bureaus, the expertise they are looking for to launch seamlessly, and the proprietary analytics to supplement credit insights - all delivered through Bloom’s developer-friendly API. Over 12 million US consumers have material errors on their credit reports that lead to being denied credit or having to pay unnecessarily high interest rates. The tools and infrastructure we provide for working with credit data help reduce these errors, and improve access to affordable credit.

Why Work With Us

Our goal is simple: to help everyone from seed-stage startups to large, established banks (and everyone in between) access and furnish accurate credit data easily and without error. We believe this will lead to increased innovation and the creation of accessible, unique financial products for everyone.

Gallery

Gallery
Gallery
Gallery
Gallery

Bloom Credit Offices

Remote Workspace

Employees work remotely.

Bloom is a fully remote company. There is a small touchdown office in Chicago that local employees are welcome to use as needed. We try to bring the entire company together in-person for 2-3 days at least once a year.

Typical time on-site: None
HQChicago, IL

Similar Jobs

Bloom Credit Logo Bloom Credit

Implementation Manager

Fintech • Financial Services
Remote
United States
36 Employees

Bloom Credit Logo Bloom Credit

Marketing Manager

Fintech • Financial Services
Remote
United States
36 Employees

Bloom Credit Logo Bloom Credit

Support Engineer

Fintech • Financial Services
Remote
USA
36 Employees

Bloom Credit Logo Bloom Credit

Support Engineer

Fintech • Financial Services
Remote
United States
36 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account