Security Analyst - Entry

Globalpundits, Inc

  • Blythewood, SC
  • 3 days ago

    Highlights

    Assist in initial triage of security incidents by following response frameworks (e.g., NIST, MITRE ATT&CK). Gather and analyze relevant evidence, such as logs or alert data, to determine incident scope and severity.

    Numbers & Facts

    LocationBlythewood, SC

    Description

    Key Responsibilities

    1. Threat Intelligence Research

    • Monitor and analyze threat intelligence feeds to identify emerging threats relevant to the organization.
    • Document findings, such as new attack methods or vulnerabilities, and share them with the team.
    • Use open-source intelligence (OSINT) tools to gather data on potential risks and adversaries.

    2. Threat Hunting and Detection Rule Creation

    • Conduct proactive searches for suspicious behavior in network and endpoint activity using provided tools and playbooks.
    • Utilize threat feeds, investigate suspicious activity, and stay current on cyber threats.
    • Collaborate with senior analysts to refine and test detection rules (e.g., SIEM queries or Defender for Endpoint rules).
    • Document hunting methodologies and findings to support continuous improvement.

    3. Log Analysis

    • Review and interpret logs from firewalls, endpoints, and servers to identify indicators of compromise (IOCs).
    • Escalate findings, such as anomalous IP addresses or unauthorized access attempts, to senior analysts.
    • Maintain a log of recurring patterns or anomalies for long-term tracking and analysis.

    4. Incident Response

    • Assist in initial triage of security incidents by following response frameworks (e.g., NIST, MITRE ATT&CK).
    • Identify and escalate potential security threats.
    • Gather and analyze relevant evidence, such as logs or alert data, to determine incident scope and severity.
    • Document findings during incidents and contribute to containment and remediation efforts.

    5. Documentation, Reporting, and Communication

    • Create clear, detailed reports, including incident reports, after-action reviews, and process documentation.
    • Deliver reports on security posture and propose mitigation strategies.
    • Draft training materials or guides to improve organizational awareness and readiness.
    • Regularly update and organize documentation for accuracy and accessibility.

    6. Vulnerability Management

    • Analyze reports, prioritize patching, and apply NIST best practices.

    7. Security Awareness Training

    • Develop and deliver training and assess employee awareness through simulations.

    8. Security Automation and Scripting

    • Leverage SCCM, GPO, and PowerShell for patch deployment.
    • Automate tasks beyond SCCM, GPO, and PowerShell to increase efficiency.

    9. Endpoint and Network Security

    • Configure policies, analyze alerts, and manage endpoint protection.
    • Apply knowledge of network protocols and firewalls to strengthen overall security posture.

    10. Digital Forensics and Cloud Security

    • Investigate security incidents and collect evidence for deeper analysis.
    • Develop knowledge of cloud-specific security solutions as cloud adoption grows.

    Required Skills

    • Understanding of security concepts and processes
    • Understanding of basic computer and network concepts

    Preferred Skills

    • 1+ year of experience in an IT security-focused role
    • Experience with SIEM and endpoint security tools
    • Experience with PowerShell, Group Policy, and endpoint management
    • Knowledge of vulnerability management and cloud security
    • 1+ years of experience in server or network administration
    • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field

    Additional Skills

    • Problem-Solving: Analyze data, identify anomalies, and recommend solutions.
    • Attention to Detail: Ensure accurate analysis and configuration for effective security measures.
    • Teamwork: Communicate and work effectively within a mid-size team.

    Education: High School Diploma required at minimum.

    Certifications (not required, but preferred):

    • GIAC Security Essentials (GSEC)
    • CompTIA Security+
    • CompTIA Network+
    • GIAC Certified Incident Handler (GCIH)

    Similar Jobs

    See more jobs