Security Analyst – Network & Cybersecurity
Position Summary
We are seeking a technically driven Security Analyst to help identify, investigate, and remediate cybersecurity risks across complex client environments.
This role goes beyond monitoring alerts. The ideal candidate understands the intersection of cybersecurity, networking, infrastructure, and threat detection and can investigate security events while understanding what is happening across the underlying network.
The Security Analyst will work across security monitoring, vulnerability management, network security, endpoint protection, firewall technologies, Zero Trust initiatives, and incident investigation while collaborating with engineers, architects, and clients.
Key Responsibilities
Security Monitoring & Investigation
- Monitor, investigate, and analyze security events across client environments.
- Investigate alerts generated through SIEM, EDR, XDR, firewall, and other security platforms.
- Differentiate legitimate security incidents from false positives.
- Analyze logs, endpoints, authentication activity, and network traffic to determine potential threats.
- Escalate confirmed incidents and assist with containment and remediation.
- Document findings, remediation activities, and recommendations.
Network Security
- Analyze firewall events, configurations, and security policies.
- Assist with firewall rule reviews and policy management.
- Troubleshoot security issues involving DNS, TCP/IP, VPNs, routing, and network connectivity.
- Support network segmentation and microsegmentation initiatives.
- Assist with Zero Trust and secure-access initiatives.
- Identify potentially suspicious traffic patterns and network behavior.
Vulnerability Management
- Assist with vulnerability assessments and security reviews.
- Analyze identified vulnerabilities and help prioritize remediation based on risk.
- Work with engineering teams to address vulnerabilities across endpoints, servers, applications, and network infrastructure.
- Validate remediation and maintain accurate documentation.
Endpoint & Identity Security
- Monitor and investigate EDR/XDR alerts.
- Assist with endpoint protection and threat remediation.
- Investigate suspicious authentication and account activity.
- Support MFA, identity security, Conditional Access, and Zero Trust initiatives.
- Assist with Microsoft 365, Entra ID, Azure, and cloud security environments.
Client & Engineering Collaboration
- Work directly with clients, engineers, and security leadership to communicate findings and recommendations.
- Translate technical security findings into understandable business risks.
- Collaborate with Network Engineers, Security Engineers, and Architects during remediation efforts.
- Participate in security assessments, implementation projects, and continuous improvement initiatives.
Required Qualifications
- 2–5+ years of cybersecurity, network security, SOC, or security engineering experience.
- Strong understanding of networking fundamentals including TCP/IP, DNS, DHCP, routing, switching, VPNs, and firewalls.
- Experience investigating security alerts and suspicious activity.
- Hands-on experience with SIEM and/or XDR/EDR technologies.
- Experience with firewall administration, monitoring, or analysis.
- Understanding of vulnerability management and remediation.
- Working knowledge of Windows environments, Active Directory, and identity management.
- Understanding of common cybersecurity threats, attack techniques, and security controls.
- Strong troubleshooting and analytical skills.
- Strong written and verbal communication skills.
Preferred Qualifications
Experience with one or more of the following is highly desirable:
- Cisco security technologies
- Palo Alto Networks
- Network segmentation and microsegmentation
- Zero Trust architecture
- SASE technologies
- Microsoft 365 and Entra ID security
- Azure or AWS security
- Vulnerability management platforms
- Security automation
- VMware or virtualized environments
- Security frameworks such as NIST, CIS, SOC 2, ISO 27001, PCI DSS, HIPAA, or CMMC
Experience within an MSP, MSSP, cybersecurity consultancy, VAR, technology integrator, or other client-facing technology organization is strongly preferred.
Certifications
Relevant certifications may include:
- CompTIA Security+
- CompTIA CySA+
- Cisco CyberOps
- CCNA / CCNP Security
- Microsoft Security certifications
- Palo Alto Networks certifications
- GIAC certifications
Equivalent hands-on experience will also be considered.
What We're Looking For
We're particularly interested in someone who understands that cybersecurity does not exist in isolation from infrastructure.
The ideal candidate can look at a security alert and ask:
What happened? How did it happen? What systems were affected? What is happening on the network? How do we prevent it from happening again?
This individual should be:
- Naturally curious and investigative
- Technically hands-on
- Strong in networking fundamentals
- Comfortable communicating with clients
- Able to work across multiple technologies
- Detail-oriented with strong documentation habits
- Willing to escalate when appropriate
- Interested in continuously expanding technical knowledge
What Success Looks Like
Success in this position means:
- Security events are investigated thoroughly and efficiently.
- Threats are distinguished from false positives.
- Vulnerabilities are identified, prioritized, and remediated.
- Network and endpoint security issues are understood—not simply escalated.
- Security findings are clearly documented.
- Engineers receive actionable information for remediation.
- Clients understand both the technical issue and associated business risk.
- Recurring security issues lead to improvements in controls, processes, and architecture.