6 дней назад
Information Security Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Information Security Analyst (Cybersecurity): Operating and improving an enterprise security program with an accent on incident response, advanced security-event analysis, vulnerability management, and identity, cloud, SaaS, and data security. Focus on investigating complex incidents, coordinating containment and remediation, validating security controls, and producing audit-ready evidence across enterprise technologies.
Location: Hybrid in Atlanta, Georgia, with onsite work 2–3 days per week initially and twice per month thereafter. The department location is listed as Duluth, Georgia.
Company
is a technology services company delivering professional and managed services across cloud infrastructure, networking, cybersecurity, data and AI, automation, and enterprise service management.
What you will do
- Monitor, investigate, correlate, and respond to security events across endpoint, identity, email, network, SaaS, cloud, and other enterprise technologies.
- Lead or materially support moderate-to-complex incident response, including containment, remediation, recovery, evidence preservation, escalation, and communications.
- Improve detection, response, automation, orchestration, and scalable security processes in collaboration with internal teams, managed security providers, and vendors.
- Support vulnerability and exposure management, penetration testing, security assessments, control validation, remediation tracking, and high-risk closure verification.
- Investigate identity, access, data, SaaS, cloud, phishing, impersonation, and human-targeted threats while applying least-privilege and Zero Trust principles.
- Maintain investigation records, playbooks, procedures, evidence packages, control documentation, and risk updates for leadership, audit, Legal, HR, Compliance, and other stakeholders.
Requirements
- Associate degree in IT, cybersecurity, computer science, or a related field, or equivalent relevant experience.
- 3–5 years of experience in cybersecurity operations, SOC operations, incident response, security engineering support, or a similar area.
- Strong incident-response, investigation, evidence-handling, advanced log-analysis, and event-correlation skills.
- Working knowledge of SIEM/SOC operations, EDR, email security, identity security, cloud security, data-security monitoring, Microsoft 365, Entra ID, Windows security, networking, and authentication protocols.
- Knowledge of vulnerability management, CVE/CVSS, CISA KEV, risk-based prioritization, healthcare data security, PHI/HIPAA, PCI requirements, security automation, orchestration, PowerShell, and Zero Trust.
- Ability to communicate technical risk clearly, create repeatable SOPs and executive summaries, maintain audit-ready evidence, prioritize competing responsibilities, and participate in after-hours incident response when required.
Nice to have
- Experience providing guidance and mentoring in security operations, investigations, evidence collection, documentation, and repeatable procedures.
- Experience supporting security for new technologies, integrations, acquisitions, and business initiatives.
Culture & Benefits
- Six-month contract-to-hire opportunity with one of ’s clients.
- Work with distributed teams and collaborate across technical, business, vendor, and managed security functions.
- Inclusive work environment that welcomes people from diverse backgrounds and perspectives.
- Opportunity to support enterprise security operations across evolving technologies, business initiatives, and threat landscapes.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →