Analyst, Cyber Security II
- triage
- Incident Management
- SIEM
- CrowdStrike
- EDR
- Azure
- Windows
- Linux
- Cisco
- Elastic
- Penetration Testing
- Threat Intelligence
- Incident Response
- Network Security
- Risk Management
- Configuration Management
- CISA
- CISM
- CISSP
Cyber Security – Security Operations / Incident Triage
Job Type: Contract
C2 Eligibility: Required
Credit Check: Required during pre-screen
Subcontractors: Not permitted
Work Arrangement: Partial Onsite – Tuesday, Wednesday, Thursday onsite and as needed
Hours: 8:00 AM – 5:00 PM ET, Monday–Friday
Interview: In-person preferred; remote interview may be accepted
Position Overview
Seeking a technically strongCyber Security professional to support a Cyber Security Operations environment focused onreal-time security alert monitoring, investigation, incident triage, threat detection, and response.
This role requires hands-on technical security experience rather than a primarily compliance-focused background.
Education Requirements
- Bachelor's degree inComputer Science, Information Technology, or another job-related field
- Degree equivalency accepted:
- 4 years of job-related work experience,or
- 2 years of job-related experience plus an associate's degree in Computer Science, Information Technology, or another job-related field
Required Experience
- Minimum6 years of job-related technical experience
- Strong experience withsecurity monitoring, incident investigation, and alert triage
- Experience analyzingnetwork attacks and security events
- Experience reviewing logs from multiple systems to establish theground truth of an event
- Experience withincident management, intrusion detection, and security troubleshooting
- Strong enterprise security operations experience
Required Technologies
- SIEM
- CrowdStrike / EDR
- Microsoft 365 / Azure
- Windows / Linux Server Operating Systems
Nice-to-Have Technologies
- ExtraHop
- Proofpoint
- Palo Alto
- Cisco
- Elastic
- Network Operating Systems
- Additional enterprise security monitoring and detection tools
Key Responsibilities
- Monitor and investigatesecurity alerts and events on a daily basis.
- Perform real-timesecurity alert monitoring and triage.
- Investigate potential security incidents and respond rapidly and accurately.
- Review and correlateevent logs from servers, endpoints, networks, cloud environments, email systems, and other security platforms.
- Determine the nature and potential impact of security events and escalate incidents appropriately.
- Analyzenetwork attacks, vulnerabilities, threats, and security risks.
- Perform security assessments such asvulnerability scanning and penetration testing.
- Identify weaknesses in systems and help assess potential attack paths.
- Support the tuning and optimization of security tools to improve threat detection and containment.
- Develop and implementinformation security architectures and solutions.
- Research and evaluate new security technologies, tools, infrastructure, and architectures.
- Identify, plan, and implement security tools and controls.
- Develop and improve procedures for theprevention, detection, containment, and correction of security incidents.
- Monitor the cyber threat landscape and use threat intelligence to identify emerging threats.
- Analyze business impact and exposure associated with security threats and vulnerabilities.
- Troubleshoot security issues acrossmulti-vendor environments.
- Provide security guidance related to procedures, controls, and incident response.
Day-to-Day Activities
A typical day will involve investigating security alerts generated by various security tools across the environment. The Cyber Security professional will review event logs from different systems to establish what actually occurred, determine whether an event represents a legitimate threat, andtriage and respond appropriately.
The role may involve working across multiple security consoles and technologies, including:
- SIEM
- EDR / CrowdStrike
- Email Security
- Network Security
- Cloud Security
- Server Security
- Security monitoring and threat detection platforms
Security Operations Focus
The position supports aCyber Security Operations environment consisting of teams focused on:
- Incident Triage, Analysis & Response
- Security Engineering & Administration
The position primarily focuses onreal-time alert monitoring, investigation, and triage, with an emphasis on communication, collaboration, and knowledge sharing.
Core Security Knowledge
- System and network security
- Security event monitoring
- Incident response and incident management
- Intrusion detection
- Log analysis
- Threat analysis
- Risk management
- Vulnerability assessment
- Security tool configuration and tuning
- Configuration management
- Business continuity and contingency planning
- Network troubleshooting
- Root-cause analysis
- Enterprise security architecture
- Security controls and risk reduction
Preferred Experience / Certifications
- Strongincident response experience in a medium-to-large enterprise environment
- Experience interpreting and acting oncyber threat intelligence
- Preferred certifications:
- CISA
- CISM
- CISSP
Soft Skills
- Strong analytical skills
- Strong data-gathering and investigative skills
- Excellent problem-solving abilities
- Ability to analyze network attacks
- Strong troubleshooting and root-cause analysis skills
- Ability to prioritize and execute tasks in a high-pressure environment
- Creativity in identifying and addressing new threats
- Strong communication and interpersonal skills
- Strong organizational skills
- Ability to collaborate and share security knowledge
Important Candidate Profile
Looking for: Hands-on, technically strong Cyber Security / Security Operations candidates with experience insecurity monitoring, SIEM, EDR, incident triage, log analysis, threat detection, and incident response.
Not looking for: Candidates whose background is primarilynon-technical security compliance, governance, or policy without hands-on security operations experience.
Additional Work Requirements
- Possible but likely rareovertime, weekends, or off-hours support
- Possible travel if business needs require it
- Fast-paced, multi-platform environment that may require24×7 security response/support.
Analyst, Cyber Security II · Talent Technical Services, Inc