Security Analyst
Summary
Security Analyst at D.R. Horton monitors and triages IT security alerts across SIEM, EDR, DLP, email, identity, and web filtering platforms; investigates incidents; supports vulnerability remediation, endpoint protection, and access control; and assists with phishing, DNS, and incident response in the corporate IT security team.
D.R. Horton, Inc., the largest homebuilder in the U.S., was founded in 1978 and is a publicly traded company on the New York Stock Exchange. It is engaged in the construction and sale of high quality homes designed principally for the entry-level and first time move-up markets. The Company also provides mortgage financing and title services for homebuyers through its mortgage and title subsidiaries. Please visit our website at www.drhorton.com for more information.
D.R. Horton, Inc. is currently looking for a Security Analyst. The right candidate will address daily tasks and routine processes for IT security. This position will be responsible for assessing IT security incidents and applying the necessary technical troubleshooting steps to resolve the issue. The Security Analyst will also be responsible for monitoring suspicious or malicious activity in the company IT infrastructure and addressing security risk and incidents.
Essential Duties and Responsibilities include the following. Other duties may be assigned.
Security Operations and Monitoring
- Monitor security alerts, tool queues, email, ITSM tickets, and Teams requests for potential security issues, access concerns, policy events, or operational security requests.
- Triage and investigate security events involving endpoints, identity, email, web access, data movement, privileged access, vulnerabilities, or suspicious user activity.
- Review logs and alerts from security platforms such as SIEM, EDR, email security, web filtering, identity, vulnerability, DLP, or access control tools.
- Document findings clearly, including affected users or systems, timestamps, evidence reviewed, impact, recommended remediation, and escalation needs.
- Escalate higher-risk issues to senior analysts, management, or the appropriate technical owner when additional review, containment, or business coordination is required.
Support user-reported phishing, suspicious email, unsafe website, malware, authentication, and access-related security concerns.
Identity, Access, and Enforcement Support
- Assist with security-related identity requests involving Active Directory, Microsoft Entra ID, MFA, privileged access, service accounts, group membership, and access troubleshooting.
- Support investigations involving suspicious sign-ins, account changes, MFA issues, administrative activity, access anomalies, or authentication failures.
- Help validate access control changes, group assignments, privileged access requests, and account lifecycle activity against approved security processes.
- Assist with enforcement-related activities such as certificate review, Group Policy security controls, sensitive data handling, privileged access evidence, and SIEM log review.
Vulnerability, Endpoint, and Data Protection Support
- Review vulnerability findings, endpoint security alerts, software risk, unsupported technology, patch status, and remediation evidence under the guidance of senior analysts.
- Assist with endpoint security investigations by reviewing EDR alerts, device status, file reputation, quarantine activity, containment actions, and remediation progress.
- Support vulnerability remediation tracking by identifying affected assets, confirming ownership, collecting evidence, and validating that risk has been reduced.
- Assist with data protection reviews involving DLP alerts, sensitive document handling, suspicious file access, email security events, or unusual data movement.
Email, Web, DNS, and Network Security Support
- Assist with email security reviews, phishing analysis, sender validation, email authentication checks, quarantine review, and user-reported suspicious messages.
- Support web security and content filtering requests by reviewing website risk, URL categorization, domain reputation, and access policy behavior.
- Help with DNS-related security requests, DNS record validation, domain review, and name-resolution evidence needed for troubleshooting or investigations.
Collaborate with network, infrastructure, and application teams when firewall, proxy, segmentation, traffic flow, or external exposure evidence is needed for a security review.
Incident Response and Investigation Support
- Participate in security incident triage by collecting evidence, reviewing alerts, identifying affected users or systems, and documenting the initial impact.
- Assist with containment and remediation coordination, including account action, endpoint response, access review, URL or sender blocking, vulnerability follow-up, or escalation to the appropriate team.
- Perform basic log review and correlation across available security tools to support investigation timelines and root cause analysis.
Prepare clear incident notes that can be understood by both technical and non-technical stakeholders.
Project, Documentation, and Operational Support
- Contribute to security projects, process improvements, platform upgrades, documentation updates, and operational cleanup efforts across Corporate IT Security.
- Maintain clear notes, procedures, checklists, and troubleshooting steps for recurring security tasks and common support scenarios.
- Work with cross-functional teams including Identity, Infrastructure, Network, Endpoint, Application, Audit, Compliance, Helpdesk, and vendor support teams.
- Follow approved change management, escalation, evidence handling, and request tracking processes.
Additional Responsibilities\:
- Participate in the weekly on-call rotation and respond to after-hours security incidents when assigned.
- Provide professional, customer-focused support to internal users and peer IT teams.
- Support IT operational emergencies when they create security risk or impact business-critical systems.
- Continue developing technical knowledge across security operations, identity, endpoint, vulnerability management, data protection, and enterprise security tools.
- Travel overnight as required.