GI
Security Analyst - Entry
Globalpundits, Inc
๐บ๐ธ United States
On-site
Entry level
2 days ago
- Threat Intelligence
- OSINT
- SIEM
- Defender
- Incident Response
- triage
- NIST
- Vulnerability Management
- SCCM
- PowerShell
- Network Security
- Group Policy
- GSEC
- CompTIA Security+
- CompTIA Network+
- GCIH
2 days ago
Key Responsibilities
1. Threat Intelligence Research
- Monitor and analyze threat intelligence feeds to identify emerging threats relevant to the organization.
- Document findings, such as new attack methods or vulnerabilities, and share them with the team.
- Use open-source intelligence (OSINT) tools to gather data on potential risks and adversaries.
2. Threat Hunting and Detection Rule Creation
- Conduct proactive searches for suspicious behavior in network and endpoint activity using provided tools and playbooks.
- Utilize threat feeds, investigate suspicious activity, and stay current on cyber threats.
- Collaborate with senior analysts to refine and test detection rules (e.g., SIEM queries or Defender for Endpoint rules).
- Document hunting methodologies and findings to support continuous improvement.
3. Log Analysis
- Review and interpret logs from firewalls, endpoints, and servers to identify indicators of compromise (IOCs).
- Escalate findings, such as anomalous IP addresses or unauthorized access attempts, to senior analysts.
- Maintain a log of recurring patterns or anomalies for long-term tracking and analysis.
4. Incident Response
- Assist in initial triage of security incidents by following response frameworks (e.g., NIST, MITRE ATT&CK).
- Identify and escalate potential security threats.
- Gather and analyze relevant evidence, such as logs or alert data, to determine incident scope and severity.
- Document findings during incidents and contribute to containment and remediation efforts.
5. Documentation, Reporting, and Communication
- Create clear, detailed reports, including incident reports, after-action reviews, and process documentation.
- Deliver reports on security posture and propose mitigation strategies.
- Draft training materials or guides to improve organizational awareness and readiness.
- Regularly update and organize documentation for accuracy and accessibility.
6. Vulnerability Management
- Analyze reports, prioritize patching, and apply NIST best practices.
7. Security Awareness Training
- Develop and deliver training and assess employee awareness through simulations.
8. Security Automation and Scripting
- Leverage SCCM, GPO, and PowerShell for patch deployment.
- Automate tasks beyond SCCM, GPO, and PowerShell to increase efficiency.
9. Endpoint and Network Security
- Configure policies, analyze alerts, and manage endpoint protection.
- Apply knowledge of network protocols and firewalls to strengthen overall security posture.
10. Digital Forensics and Cloud Security
- Investigate security incidents and collect evidence for deeper analysis.
- Develop knowledge of cloud-specific security solutions as cloud adoption grows.
Required Skills
- Understanding of security concepts and processes
- Understanding of basic computer and network concepts
Preferred Skills
- 1+ year of experience in an IT security-focused role
- Experience with SIEM and endpoint security tools
- Experience with PowerShell, Group Policy, and endpoint management
- Knowledge of vulnerability management and cloud security
- 1+ years of experience in server or network administration
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field
Additional Skills
- Problem-Solving: Analyze data, identify anomalies, and recommend solutions.
- Attention to Detail: Ensure accurate analysis and configuration for effective security measures.
- Teamwork: Communicate and work effectively within a mid-size team.
Education: High School Diploma required at minimum.
Certifications (not required, but preferred):
- GIAC Security Essentials (GSEC)
- CompTIA Security+
- CompTIA Network+
- GIAC Certified Incident Handler (GCIH)
Security Analyst - Entry ยท Globalpundits, Inc