Overview
Information Security Specialist Jobs in Los Angeles, CA at DeSanti
Title: Information Security Specialist
Company: DeSanti
Location: Los Angeles, CA
We're looking for an Information Security Specialist who thrives on variety and wants to make a real impact. In this hands-on role, you'll help shape, strengthen, and operate the internal security program while working across a wide range of security disciplines—not just one niche area.
From security operations and identity management to endpoint protection, network defense, vendor risk, compliance, and employee security awareness, you'll be at the center of keeping our business secure and resilient. You'll partner closely with IT, engineering, and business teams to build practical security solutions that enable the company to move fast with confidence.
This opportunity is ideal for someone with 3–5 years of broad IT and security experience who enjoys wearing multiple hats and is ready to grow into a senior internal security leadership role over time.
What You'll Do:
- Support day-to-day security operations, including alert triage in our SIEM and EDR platforms, log review, and assisting with incident response when something needs investigation.
- Help administer identity and access management systems, including SSO, MFA, directory services, and the onboarding, transfer, and offboarding processes. Conduct periodic access reviews and clean up stale accounts and entitlements.
- Maintain and improve endpoint security across the fleet, including EDR health, patch management, configuration baselines, and disk encryption.
- Assist with network security tasks such as firewall rule reviews, VPN administration, segmentation work, and monitoring for misconfigurations.
- Support the vulnerability management program: scanning, prioritizing findings, coordinating remediation with system owners, and tracking metrics over time.
- Contribute to our compliance program by helping collect evidence, maintain policies, complete customer security questionnaires, and prepare for audits including CMMC/NIS2/Cyber Essentials+/[other compliance obligations].
- Support vendor risk management, including reviewing third-party security documentation and tracking risk acceptances.
- Build and deliver security awareness content, including phishing simulations, onboarding training, and internal guidance.
- Serve as a knowledgeable point of contact for employees with security questions, suspicious emails, lost devices, or access requests.
- Document processes, runbooks, and standards so the program scales as the company grows.
Required Qualifications
- 3+ years of experience in information security, IT operations, or a closely related field, with hands-on exposure to multiple security domains.
- Working knowledge of common security tools: SIEM, EDR, vulnerability scanners, identity providers (Okta, Entra ID, or similar), and cloud platforms (AWS, Azure, or GCP).
- Solid fundamentals in networking, operating systems and authentication protocols.
- Familiarity with compliance frameworks, especially CMMC [Cyber Essentials / etc for Europe]
- Comfortable scripting in Python, PowerShell, or Bash for automation and ad hoc tasks.
- Strong written and verbal communication skills, with the ability to explain security concepts to non-technical audiences.
- Self-directed and comfortable working across teams in a fast-moving environment.
- Industry certifications such as CISSP, CISM, CCIE, CCNP Security, CompTIA Security+, Network+, CISA, CRISC or similar.
- Willingness to be part of the on-call rotation
Nice to Have
- Experience supporting or leading audits
- Exposure to cloud security posture management.
- Familiarity with offensive security concepts and tooling.