IT - Security Analyst - Entry W-2 ONLY

United Global Technologies

  • Cayce, SC
  • 3 days ago

    Highlights

    o Gather and analyze relevant evidence, such as logs or alert data, to determine the scope and severity of incidents. o Assist in initial triage of security incidents by following response frameworks (e.g., NIST, MITRE ATT&CK).

    Numbers & Facts

    LocationCayce, SC

    Description

    W-2 ONLY NO SUBS NO SPONSORSHIP

    Daily Duties / Responsibilities:
    The Security Team is looking for candidates to fill an entry level security position. We will train the selected candidate to perform the tasks listed below. At a minimum We are looking for basic server or network administration skills that we can build upon.

    1. Threat Intelligence Research
    o Monitor and analyze threat intelligence feeds to identify emerging threats relevant to the organization.
    o Document findings, such as new attack methods or vulnerabilities, and share with the team.
    o Use open-source intelligence (OSINT) tools to gather data on potential risks and adversaries.

    2. Threat Hunting and Detection Rule Creation
    o Conduct proactive searches for suspicious behavior in network and endpoint activity using provided tools and playbooks.
    o Utilize threat feeds, investigate suspicious activity, and stay current on cyber threats.
    o Collaborate with senior analysts to refine and test detection rules (e.g., SIEM queries or Defender for Endpoint rules).
    o Document hunting methodologies and findings to support continuous improvement.

    3. Log Analysis
    o Review and interpret logs from firewalls, endpoints, and servers to identify indicators of compromise (IOCs).
    o Escalate findings, such as anomalous IP addresses or unauthorized access attempts, to senior analysts.
    o Maintain a log of recurring patterns or anomalies for long-term tracking and analysis.

    4. Incident Response
    o Assist in initial triage of security incidents by following response frameworks (e.g., NIST, MITRE ATT&CK).
    o Identify and escalate potential security threats.
    o Gather and analyze relevant evidence, such as logs or alert data, to determine the scope and severity of incidents.
    o Document findings during incidents and contribute to containment and remediation efforts.

    5. Documentation, Reporting, and Communication
    o Create clear, detailed reports, including incident reports, after-action reviews, and process documentation.
    o Deliver reports on the security posture and propose mitigation strategies.
    o Draft training materials or guides to help improve organizational awareness and readiness.
    o Regularly update and organize documentation to ensure accuracy and accessibility for team use.

    6. Vulnerability Management
    o Analyze reports, prioritize patching, and understand NIST best practices.

    7. Security Awareness Training
    o Develop and deliver training and assess employee awareness through simulations.

    8. Security Automation and Scripting
    o Leverage SCCM, GPO, and PowerShell for patch deployment.
    o Automate tasks beyond SCCM, GPO, and PowerShell to increase efficiency.

    9. Endpoint and Network Security
    o Configure policies, analyze alerts, and manage endpoint protection.
    o Understand network protocols and firewalls to strengthen the overall security posture.

    10. Digital Forensics and Cloud Security
    o Investigate security incidents and collect evidence for deeper analysis.
    o Develop knowledge of cloud-specific security solutions as cloud adoption grows.

    Required Skills (rank in order of Importance):
    • Understanding of security concepts and processes.
    • Understanding of basic computer and network concepts.

    Additional Skills
    • Problem-Solving: Analyze data, identify anomalies, and recommend solutions.
    • Attention to Detail: Ensure accurate analysis and configuration for effective security measures.
    • Ability to communicate and work effectively with a mid-size team.

    Required Education and experience: A High School Diploma is required at minimum.

    Preferred Skills
    • 1+ Year of Experience in an IT Security Focused Role
    • Experience with SIEM and Endpoint Security Tools
    • Experience with PowerShell, Group Policy, and Endpoint Management
    • Knowledge of Vulnerability Management and Cloud Security
    • Bachelor’s Degree in Information Technology, Computer Science, Cybersecurity, or a related field
    • 1+ Years of Experience in Server or Network Administration.

    Certifications: Not required, however we prioritize applicants who have:
    • GIAC Security Essentials (GSEC)
    • Security+ (CompTIA)
    • Network+ (CompTIA)
    • GIAC Incident Handler (GCIH)

    Similar Jobs

    See more jobs