HimalayasHimalayas logo
Sandy Hook PromiseSP

IT Security Analyst

Sandy Hook Promise is a national nonprofit organization founded by family members who lost loved ones in the Sandy Hook Elementary School shooting, dedicated to preventing gun violence through educational programs and policy advocacy.

Sandy Hook Promise

Employee count: 51-200

Salary: 80k-90k USD

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.


IT Security Analyst
*must be based in the U.S.*About Sandy Hook Promise
Sandy Hook Promise (SHP) envisions a future where all children are free from school shootings and other acts of violence. As a national nonprofit organization, SHP’s mission is to educate and empower youth and adults to prevent violence in schools, homes, and communities. Creators of the lifesaving, evidence-informed Know the Signs prevention programs, SHP teaches the warning signs of someone who may be in crisis, socially isolated, or at-risk of hurting themselves or others and how to get help. SHP also advances school safety, youth mental health, and responsible gun ownership at the state and federal levels through nonpartisan policy and partnerships.

SHP is led by several family members whose loved ones were killed in the tragic mass shooting at Sandy Hook Elementary School on December 14, 2012. 

Commitment to Belonging, Community, Engagement, and Respect 
SHP strives to ensure its culture and work environment reflect the values of belonging, community, engagement and respect. We actively seek to understand and respond to the diverse perspectives and lived experiences of individuals across socioeconomic backgrounds, rural and urban communities, and diversity of thought, in addition to traditional protected categories. We are committed to ensuring that every SHP employee feels heard, valued, and a true sense of belonging. SHP encourages individuals who share our commitment to these core values and to our mission to apply.  

Location
We are a U.S.-based organization, and most staff work remotely nationwide.

About the Role
We are seeking a proactive and detail-oriented IT Security Analyst with strong expertise in Microsoft security and compliance tools. This role will be instrumental in hardening our cloud-first environment, monitoring for threats, and advancing our prevention and detection capabilities.

The Security Analyst is responsible for protecting organizational data and systems by implementing, monitoring, and enhancing cybersecurity controls across Microsoft 365, Salesforce, and other cloud platforms. The role focuses on threat detection, incident response, and regulatory compliance, aligned with Zero Trust principles and industry best practices. Working closely with IT and Operations teams, the analyst manages endpoint security, conducts risk assessments, and ensures secure configurations to support a fully remote workforce.

The ideal candidate is collaborative, analytical, and motivated by the mission-driven challenges of securing a nonprofit organization operating in a dynamic and distributed environment

Job Responsibilities Include (but are not limited to)
  • Lead Cybersecurity Strategy & Governance: Develop and execute a comprehensive security roadmap aligned with Zero-Trust principles, organizational goals, and regulatory frameworks (CIS, NIST, ISO 27001, GDPR, HIPAA, PCI DSS).
  • Risk Management & Compliance: Maintain the enterprise risk register, conduct periodic risk assessments, and oversee remediation of identified vulnerabilities to strengthen resilience.
  • Cloud & SaaS Security Oversight: Harden and manage Microsoft 365 tenant security (MFA, conditional access, DLP, encryption, data residency) and perform ongoing security reviews of third-party SaaS vendors and integrations (e.g., Salesforce).
  • Endpoint & Remote Workforce Protection: Ensure secure device configurations, patch management, and endpoint compliance across a fully remote workforce.
  • Threat Detection & Incident Response: Monitor, investigate, and respond to security alerts using Microsoft Sentinel and Defender; conduct root-cause analyses and coordinate cross-functional incident response and recovery.
  • Vulnerability & Threat Management: Lead proactive testing (penetration, vulnerability, phishing simulations) and maintain continuous threat-intelligence monitoring.
  • Security Architecture & Continuity Planning: Support data-protection, backup, and recovery strategies; participate in business-continuity and disaster-recovery planning and exercises.
  • Policy, Documentation & Reporting: Maintain audit-ready security documentation; generate dashboards and KPIs that measure security posture, compliance, and incident trends.
  • Training & Awareness: Develop and deliver cybersecurity training programs to promote a security-first culture and reduce organizational risk through education.
  • Collaboration & Advisory Support: Partner with IT, Programs, and Operations to embed security in project design and technology adoption; advise on security implications of new initiatives.
  • A commitment to SHP's vision and values.
  • Other duties identified as organizational needs.
Desired Skills and Experience
  • 3+ years of experience in IT security, cybersecurity operations, or related roles.
  • Hands-on experience with Microsoft security tools (Defender, Sentinel, Intune, Entra ID/Azure AD, Purview).
  • Strong understanding of identity management, endpoint protection, threat detection, and incident response.
  • Familiarity with compliance frameworks (CIS Controls, ISO 27001, or similar).
  • Excellent analytical and problem-solving skills; ability to communicate technical issues to non-technical audiences.
    • Microsoft certifications:
      • SC-200 (Microsoft Certified: Security Operations Analyst Associate),
      • SC-300 (Microsoft Certified: Identity and Access Administrator Associate)
      • SC-401 (Microsoft Certified: Information Security Administrator Associate)
  • Preferred
    • MS-102 (Microsoft 365 Certified: Administrator Expert)
    • Experience supporting cybersecurity in nonprofit or resource-constrained environments.
    • Knowledge of PowerShell scripting, KQL (Kusto Query Language), or automation in Microsoft Sentinel.
    • Experience with vendor security assessments and SaaS risk management.  
Benefits and Salary Range
The salary range for this position is $80,000-$90,000.
SHP uses a structured internal rubric to guide salary placement and ensure equitable pay. Typically, new hires are placed at the start of the salary range to ensure equity with current employees, and as a practice, we do not negotiate salaries.
  • SHP offers a competitive benefits package, including:
    • Unlimited PTO
    • Flexible schedules
    • Paid holidays and10 days sick leave
    • Paid parental leave
    • Health, dental, and vision
    • Employer paid life insurance and short- and long-term disability
    • 401k match
    • Professional development stipend
    • Wellness & mental health support
    • Employer Paid Employee Assistance Program.
Our organization operates within a distributed workforce, allowing for location flexibility across the country for most positions. We provide remote office support for all staff, which includes a laptop, home office reimbursement, monthly Wi-Fi reimbursement up to $40, and monthly cell phone reimbursement up to $50.

Additional Instructions
  • SHP Staff and Volunteers have until Tuesday, May 5, 2026, to submit an application. Please contact Talent Acquisition and HR once you have applied.
  • All interested applicants are welcome to apply by Monday, June 1, 2026. Cover letter must be included.
    • The job listing may be taken down early if application volume becomes high.
    • Please note: applicants must be based in the U.S. Thank you!
Equal Opportunity Employment 
SHP is proud to be an equal opportunity employer. We strive to be an employer of choice: where a diverse mix of talented people want to come and do their best work. SHP does not make employment related decisions based on race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status, or any other protected characteristic. We are focused on promoting multiculturalism and inclusion so that all SHP employees feel valued and respected. We believe deeply that a diverse workforce comprised of people of all beliefs, backgrounds, and life experiences who seek to prevent gun violence and stop the tragic loss of life will make SHP a stronger, more effective organization. 

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Salary

Salary: 80k-90k USD

Experience

3 years minimum

Location requirements

Hiring timezones

United States +/- 0 hours

About Sandy Hook Promise

Learn more about Sandy Hook Promise and their company culture.

View company profile

At the heart of Sandy Hook Promise (SHP) is a solemn vow, born from the unimaginable tragedy of December 14, 2012, to protect children from gun violence. Founded and led by family members whose loved ones were taken at Sandy Hook Elementary School, the organization is built on a culture of transformation, turning grief into a powerful catalyst for change. The core mission is to create a future where all children are free from the fear of shootings and violence in their schools, homes, and communities. This is not just a goal; it is a deeply personal promise that fuels every action and program. The organization's culture is one of empowerment, education, and unwavering dedication. It fosters an environment of collaboration and respect, bringing together diverse voices from across the nation who share a common commitment to child safety.

The team at Sandy Hook Promise operates with a profound sense of purpose, driven by the memory of the lives lost and the urgent need to prevent future tragedies. The organizational ethos is rooted in the belief that violence is preventable when people are equipped with the right knowledge and tools. This belief is put into action through their acclaimed 'Know the Signs' programs, which educate students and adults to recognize warning signs of potential violence and to intervene before it's too late. The culture is one of proactive prevention, moving beyond political debate to focus on practical, evidence-informed solutions. By fostering inclusivity, empathy, and a sense of community, Sandy Hook Promise is building a national movement of 'upstanders' who are empowered to create safer environments for everyone. It's a culture of hope, resilience, and the relentless pursuit of a safer tomorrow for every child.

Employee benefits

Learn about the employee benefits and perks provided at Sandy Hook Promise.

View benefits

Paid sick leave

10 days of paid sick leave.

Life insurance

Employer-paid life insurance.

Flexible schedules

Offers flexible working schedules.

Paid parental leave

Offers paid leave for new parents.

View Sandy Hook Promise's employee benefits
Claim this profileSandy Hook Promise logoSP

Sandy Hook Promise

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

4 remote jobs at Sandy Hook Promise

Explore the variety of open remote roles at Sandy Hook Promise, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Sandy Hook Promise

Remote companies like Sandy Hook Promise

Find your next opportunity by exploring profiles of companies that are similar to Sandy Hook Promise. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan