Job Description
Key Responsibilities
1. Threat Intelligence Research
- Monitor and analyze threat intelligence feeds to identify emerging threats relevant to the organization.
- Document findings, such as new attack methods or vulnerabilities, and share them with the team.
- Use open-source intelligence (OSINT) tools to gather data on potential risks and adversaries.
2. Threat Hunting and Detection Rule Creation
- Conduct proactive searches for suspicious behavior in network and endpoint activity using provided tools and playbooks.
- Utilize threat feeds, investigate suspicious activity, and stay current on cyber threats.
- Collaborate with senior analysts to refine and test detection rules (e.g., SIEM queries or Defender for Endpoint rules).
- Document hunting methodologies and findings to support continuous improvement.
3. Log Analysis
- Review and interpret logs from firewalls, endpoints, and servers to identify indicators of compromise (IOCs).
- Escalate findings, such as anomalous IP addresses or unauthorized access attempts, to senior analysts.
- Maintain a log of recurring patterns or anomalies for long-term tracking and analysis.
4. Incident Response
- Assist in initial triage of security incidents by following response frameworks (e.g., NIST, MITRE ATT&CK).
- Identify and escalate potential security threats.
- Gather and analyze relevant evidence, such as logs or alert data, to determine incident scope and severity.
- Document findings during incidents and contribute to containment and remediation efforts.
5. Documentation, Reporting, and Communication
- Create clear, detailed reports, including incident reports, after-action reviews, and process documentation.
- Deliver reports on security posture and propose mitigation strategies.
- Draft training materials or guides to improve organizational awareness and readiness.
- Regularly update and organize documentation for accuracy and accessibility.
6. Vulnerability Management
- Analyze reports, prioritize patching, and apply NIST best practices.
7. Security Awareness Training
- Develop and deliver training and assess employee awareness through simulations.
8. Security Automation and Scripting
- Leverage SCCM, GPO, and PowerShell for patch deployment.
- Automate tasks beyond SCCM, GPO, and PowerShell to increase efficiency.
9. Endpoint and Network Security
- Configure policies, analyze alerts, and manage endpoint protection.
- Apply knowledge of network protocols and firewalls to strengthen overall security posture.
10. Digital Forensics and Cloud Security
- Investigate security incidents and collect evidence for deeper analysis.
- Develop knowledge of cloud-specific security solutions as cloud adoption grows.
Required Skills
- Understanding of security concepts and processes
- Understanding of basic computer and network concepts
Preferred Skills
- 1+ year of experience in an IT security-focused role
- Experience with SIEM and endpoint security tools
- Experience with PowerShell, Group Policy, and endpoint management
- Knowledge of vulnerability management and cloud security
- 1+ years of experience in server or network administration
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field
Additional Skills
- Problem-Solving: Analyze data, identify anomalies, and recommend solutions.
- Attention to Detail: Ensure accurate analysis and configuration for effective security measures.
- Teamwork: Communicate and work effectively within a mid-size team.
Education: High School Diploma required at minimum.
Certifications (not required, but preferred):
- GIAC Security Essentials (GSEC)
- CompTIA Security+
- CompTIA Network+
- GIAC Certified Incident Handler (GCIH)
Skills
Analysis Skillsunmatched
Cloud Computingunmatched
Communication Skillsunmatched
CompTIA Network+unmatched
CompTIA Security+unmatched
Computer Networksunmatched
Computer Scienceunmatched
Computer Securityunmatched
Continuous Improvementunmatched
Data Analysisunmatched
Data Collectionunmatched
Detail Orientedunmatched
Documentationunmatched
Endpoint Securityunmatched
Firewallsunmatched
GCIH - GIAC Certified Incident Handlerunmatched
GIAC - Global Information Assurance Certificationunmatched
GSEC - GIAC Security Essentials Certificationunmatched
Huntingunmatched
IP (Internet Protocol)unmatched
Incident Responseunmatched
Information Technology & Information Systemsunmatched
Intelligence Analysisunmatched
Internet Securityunmatched
Network Administration/Managementunmatched
Network Protocolsunmatched
OSINT (Open Source Intelligence)unmatched
Problem Solving Skillsunmatched
Security Analysisunmatched
Security Attacksunmatched
Security Information and Event Management (SIEM)unmatched
Software Patchesunmatched
System Center Configuration Manager (SCCM)unmatched
Systems Administration/Managementunmatched
Team Playerunmatched
U.S. National Institute of Standards and Technology (NIST)unmatched
Windows PowerShellunmatched
Level up your application
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder