Job Purpose:
Primary responsibility of the Cyber Security Analyst is to safeguard organization’s networks and systems. Responsible for real-time monitoring and analysis of security events, incident investigation, and response to threats. The ideal candidate has a solid understanding of security principles, tools, and methodologies.
Job Description:
Monitoring & Detection:
- Continuously monitor security tools and systems (SIEM, IDS/IPS, firewalls) for unusual activity or potential threats.
- Analyze logs, alerts, and network traffic for indicators of compromise (IoC).
Incident Response:
- Respond to security incidents, performing root cause analysis and containment.
- Escalate incidents to higher-tier support teams if necessary.
- Document incident findings and provide recommendations for remediation.
Threat Intelligence & Analysis:
- Stay updated on the latest cyber threats, vulnerabilities, and trends.
- Utilize threat intelligence feeds to identify and mitigate risks.
Security Tool Management:
- Maintain and optimize security tools such as SIEM platforms, endpoint protection, Cloud Security solutions and vulnerability scanners.
- Perform regular health checks and updates for security systems.
Collaboration & Reporting:
- Collaborate with IT and other teams to address security risks.
- Generate and present detailed security reports for management and stakeholders.
Qualifications / Experience / Competencies:
Qualifications & Certifications:
- Bachelor’s degree in computer science, Cybersecurity, Information Technology, or related field (or equivalent experience).
Technical Skills:
- Knowledge of SIEM tools like Splunk, QRadar, or LogRhythm.
- Familiarity with IDS/IPS, firewalls, and endpoint security solutions.
- Understanding of network protocols, TCP/IP, and packet analysis tools (e.g., Wireshark).
- Experience with scripting (Python, PowerShell) and automation.
- Knowledge of incident response frameworks (NIST, MITRE ATT&CK).
Certifications
- (Preferred):CompTIA Security+
- Certified CYBER SECURITY Analyst (CSA)
- GIAC Certified Incident Handler (GCIH)
- Certified Information Systems Security Professional (CISSP)