Display Goodwill’s Core Values of Hope, Dignity, Partnership, and Service
The Security Analyst plays a key role in safeguarding Goodwill Kentucky’s information systems, digital assets, and operational technology. Working closely with the VP of IT and Goodwill’s Managed Security Service Provider (MSSP), this role is responsible for monitoring, analyzing, and improving our security posture while ensuring risks are identified, communicated, and mitigated in alignment with business priorities.
This position blends hands-on security analysis with strong collaboration, documentation, and continuous improvement to keep Goodwill Kentucky safe, resilient, and compliant.
Security Operations & Monitoring
Partner with the Managed Security Service Provider (MSSP) to monitor security alerts, incidents, and threats across networks, systems, endpoints, and cloud environments.
Triage, investigate, and respond to security incidents reported by MSSP, escalating appropriately and coordinating remediation efforts.
Review MSSP reports and dashboards, translating findings into actionable insights for the CIO and IT leadership.
Risk Management & Governance
Assist in identifying, assessing, and documenting cybersecurity risks and vulnerabilities.
Support the development, maintenance, and enforcement of security policies, standards, and procedures.
Participate in risk assessments, audits, tabletop exercises, and compliance activities (e.g. PCI, or other applicable regulations).
Security Improvement & Hardening
Collaborate with IT teams to implement security best practices, controls, and remediation plans.
Help manage vulnerability scanning, patching coordination, and configuration reviews.
Recommend tools, processes, and improvements to strengthen Goodwill Kentucky’s overall security posture.
Awareness & Collaboration
Serve as a trusted security partner to IT, leadership, and business teams.
Support security awareness initiatives and promote a culture of cybersecurity across the organization.
Communicate security risks and incidents clearly to both technical and non-technical stakeholders.
Lead cybersecurity awareness training as needed and work closely with the Learning & Development team on cybersecurity training initiatives.
Documentation & Reporting
Maintain incident reports, risk registers, policies, and security documentation.
Provide regular updates and metrics to the CIO and leadership on security posture, trends, and areas of concern.
No supervisory responsibilities

Goodwill Kentucky is a 101-year-old nonprofit organization that operates in 103 of Kentucky’s 120 counties. The organization is committed to using resources from its nearly 70 retail stores to fund workforce resources that help lift individuals out of poverty. In 2024, Goodwill Kentucky helped place 3,092 Kentuckians into jobs with its 1,400-plus employer partners and inside its retail stores. Goodwill Kentucky uses approximately 90 cents from every dollar generated in its retail stores to operate workforce programs, so when you give to Goodwill, you do a lot of good.