IT Cyber Security Analyst
This is technical, specialized work in the research, development, implementation and administration of all the security components of the Information Technology Department over a complex network.
This job description reflects the current assignment of essential functions and is not meant to be all-inclusive. Duties and responsibilities may be assigned or reassigned to this job at any time and may be modified to reasonably accommodate an individual with a disability or for other reasons.
ESSENTIAL DUTIES AND RESPONSIBILITIES
- Continuously monitor security alerts and notifications from various tools and platforms to identify potential threats and vulnerabilities.
- Assist in investigating and responding to security incidents, including performing initial triage and documenting findings. Manage annual incident response testing.
- Conduct basic threat analysis and research to understand emerging threats and vulnerabilities relevant to our environment.
- Support the configuration and maintenance of security tools and systems to ensure they are properly tuned and up to date.
- Help identify, assess, and prioritize vulnerabilities in systems and applications, and assist with remediation efforts.
- Maintain and update security documentation, including policies, procedures, and incident reports.
- Assist in developing and delivering cybersecurity awareness training to staff members.
- Support compliance efforts related to cybersecurity frameworks and standards (e.g., PCI, NIST).
- Maintaining a disaster recovery strategy and procedures backup plan.
- Software and hardware lifecycle and patch management.
- Monitor and manage the organization’s firewall infrastructure to safeguard network traffic.
- Intrusion Detection/Prevention Systems (IDS/IPS): Oversee IDS/IPS systems to detect and respond to malicious activities and policy violations.
- Antivirus and Endpoint Protection: Maintain and update antivirus solutions and endpoint protection tools to prevent and respond to malware threats.
- Security Information and Event Management (SIEM): Utilize SIEM tools to collect, analyze, and correlate security event data from various sources.
- Virtual Private Network (VPN): Support the management and security of VPNs used for remote access.
- Email Security Solutions: Monitor and manage email security systems to prevent phishing and other email-based threats.
- To enhance the cybersecurity awareness and skills of the IT Department and all employees across the organization.
- Backup and Recovery Systems: Assist in ensuring the integrity and security of data backup and recovery systems.
- Identity and Access Management (IAM): Audit IAM systems to control and monitor user access and authentication.
- Monitor Centralized log management system.
MINIMUM QUALIFICATIONS (Education, Training & Experience):
Bachelor’s degree from an accredited college or university in Computer Science or related field and 2 years experience in a progressively responsible position within information technology.
LICENSE AND CERTIFICATIONS: (If license(s) or certification(s) is required to practice a trade or profession, you must attach a copy. Cybersecurity certifications such as GIAC Security Essentials (GSEC) or PCI Professional Qualification (PCIP) or similar.
KNOWLEDGE, SKILLS AND ABILITIES:
- Technical Skills: Familiarity with security tools and technologies (e.g., firewalls, intrusion detection systems, antivirus software “Palo Alto, Symantec, Kaseya 365, Microsoft Defender). Knowledge of networking protocols and concepts.
- Analytical Skills: Strong analytical and problem-solving skills with the ability to think critically and act decisively in high-pressure situations.
- Communication: Excellent written and verbal communication skills, with the ability to clearly articulate security issues and recommendations.
- Attention to Detail: Meticulous attention to detail and a strong commitment to maintaining data integrity and confidenti