About this role
About the Role
We are seeking a dedicated Cyber Security Analyst to join one of our client's teams of cybersecurity professionals. In this role, you will work closely with senior security team members to master existing security processes, procedures, and protocols. We are committed to the ongoing professional development of our team, providing the resources and collaborative environment needed to further elevate your technical expertise.
Scope of Work
- Incident Response & Triage: Conduct in-depth investigations and incident response for complex security events, including Managed Detection and Response (MDR) alerts, malware/phishing campaigns, and CASB/SOC escalations.
- Threat Hunting & Analysis: Analyze anomalous log data and collaborate during brainstorming sessions to proactively detect and eradicate threat actors across client networks.
- Process Improvement & Automation: Analyze security incidents to enhance the alert catalog and continuously improve processes. Leverage automation to streamline detection sets and build a more efficient security posture.
- Reporting & Remediation: Manage escalated investigations handed off from the Service Desk from start to finish. Provide comprehensive reports detailing the investigation's outcome, recommended remediation actions, and strategies to prevent future occurrences.
Required Qualifications & Skills
- Bachelor's degree and 4+ years of prior relevant cybersecurity experience; or an equivalent combination of education and hands-on work experience.
- Minimum of 3 years of experience in a dedicated Cyber Security support, incident response, or similar role.
- Strong ability to conduct incident investigations and provide comprehensive triage support with minimal supervision.
- Demonstrated understanding of network threat lifecycles, attack vectors, and exploitation methods, including strong familiarity with the MITRE ATT&CK framework and TTPs.
- Solid foundational knowledge of TCP/IP, common networking ports/protocols, traffic flow, the OSI model, system administration, and defense-in-depth strategies.
- Proficiency with modern enterprise security technologies, including Endpoint and Extended Detection and Response (EDR/XDR), Network Detection and Response (NDR), Next-Generation Firewalls (NGFW), and SIEM/SOAR platforms.
- Familiarity with Zero Trust architecture, Intelligence-Driven Defense, and/or the Cyber Kill Chain methodology.
- Introductory understanding of securing cloud services, containers, multi-tier web applications, data lakes, alongside solid SQL query skills.
- Experience utilizing ServiceNow or similar enterprise ticketing systems.
- Proficiency with Microsoft Excel and PowerPoint.
- Proven track record of managing multiple concurrent tasks and meeting strict deadlines.
- Must be willing to work USA Central time zone business hours.
Preferred Qualifications & "Plus" Factors
- Specialized Security Platforms: Hands-on experience with ThreatLocker for zero-trust endpoint security and application control is a strong plus. Experience with CyberArk for privileged access management (PAM) and identity security is also highly desirable.
- MDR & Incident Response: Advanced experience driving incident response specifically for Managed Detection and Response (MDR) security events.
- Network & Access Security: Experience implementing and managing Cisco Secure Access or modern Security Service Edge (SSE) environments is a plus.
- Web & Mobile Security: Proven experience managing website blacklisting and whitelisting, as well as administering Mobile Device Management (MDM) security tools and policies.
- Automation & Scripting: Strong scripting and programming experience (especially PowerShell) to drive process automation.
- OS Expertise: Intermediate knowledge of Windows 10, 11, and Windows Server administration, including OS hardening techniques. Familiarity with using and navigating Linux endpoints.
- Tooling: Hands-on experience utilizing various open-source incident response tools and utilities.
- Certifications: Advanced industry certifications (e.g., CISSP, SANS GIAC/GCIA/GCIH) or SIEM-specific training/certifications are highly preferred.
- Continuous Improvement: A demonstrated commitment to self-study, training, and maintaining ongoing proficiency across emerging technical cybersecurity domains.
