Overview
Skills
Job Details
The Cybersecurity Analyst is responsible for protecting the organization s computer systems, networks, and data from security breaches, attacks, and unauthorized access. This role involves monitoring, detecting, investigating, and responding to security incidents, as well as implementing security measures and ensuring compliance with industry standards and regulations.
Key Responsibilities
1. Security Monitoring & Incident Response
Monitor security alerts from SIEM, IDS/IPS, firewalls, and endpoint protection tools.
Investigate and respond to security incidents, ensuring timely resolution and root cause analysis.
Maintain and improve incident response playbooks and escalation procedures.
2. Threat Intelligence & Vulnerability Management
Conduct vulnerability assessments and coordinate remediation with IT teams.
Research and analyze emerging cybersecurity threats, tactics, and techniques (TTPs).
Manage vulnerability scanners and patch management programs.
3. Security Operations & Maintenance
Maintain and configure security tools (firewalls, antivirus, EDR, DLP, etc.).
Monitor user activity and access controls to detect suspicious behavior.
Support continuous improvement of security posture through metrics and reporting.
4. Compliance & Governance
Assist with compliance audits (e.g., ISO 27001, NIST, SOC 2, GDPR, HIPAA).
Develop and maintain cybersecurity policies, procedures, and documentation.
Provide security awareness training and support to staff.
5. Collaboration & Reporting
Work with IT, DevOps, and business teams to integrate security best practices.
Generate reports on incidents, risks, and compliance metrics for management.
Qualifications
Education:
Bachelor s degree in Computer Science, Information Security, or related field (or equivalent experience).
Experience:
1 3 years of experience in cybersecurity, SOC operations, or IT security (for mid-level roles, 3 5 years+).
Technical Skills:
Familiarity with SIEM tools (e.g., Splunk, QRadar, Sentinel).
Knowledge of firewalls, IDS/IPS, and endpoint protection tools.
Understanding of TCP/IP, DNS, VPNs, and network protocols.
Experience with vulnerability scanners (Nessus, Qualys, etc.).
Scripting knowledge (Python, PowerShell, or Bash) a plus.
Certifications (Preferred):
CompTIA Security+, CEH, CySA+, or SSCP (for entry/mid-level).
CISSP, CISM, or OSCP (for senior roles).
Soft Skills:
Strong analytical and problem-solving skills.
Excellent communication and teamwork abilities.
Detail-oriented and proactive approach to risk management.