Job Summary We are seeking a Security Analyst to support enterprise security operations by monitoring, analyzing, and responding to cybersecurity incidents across complex hybrid environments. This role is responsible for managing security incidents, performing network security analysis, supporting security controls, and collaborating with cross-functional teams to identify, investigate, and remediate security risks. The ideal candidate will have strong expertise in network security, incident response, threat analysis, ServiceNow, and cybersecurity frameworks. Key Responsibilities Manage security incident tickets within ServiceNow and ensure compliance with established incident response processes and service level agreements. Monitor, analyze, and investigate security events across firewalls, intrusion detection/prevention systems (IDS/IPS), web proxies, VPNs, and other network security technologies. Perform network traffic analysis to identify indicators of compromise, suspicious activity, unauthorized access attempts, and potential data exfiltration. Support the implementation, administration, and continuous improvement of network security controls, including firewalls, network access control (NAC), segmentation, VPNs, and secure remote access solutions. Review firewall rules, access control lists (ACLs), and network security configurations to ensure compliance with security standards and least-privilege principles. Collaborate with architecture, infrastructure, networking, cloud, identity, endpoint, and security operations teams to identify and remediate security risks and vulnerabilities. Participate in incident response activities, including packet capture analysis, threat containment, root cause analysis, and post-incident reviews. Monitor emerging cybersecurity threats, attack techniques, and security trends, and recommend enhancements to detection and prevention capabilities. Create and maintain operational reports, incident documentation, risk management artifacts, and security metrics. Coordinate security awareness initiatives and phishing simulation exercises, including user targeting, response tracking, and reporting. Respond to and resolve Privileged Access Management (PAM) requests and activities within defined service levels using ServiceNow. Coordinate with stakeholders during security incidents to provide timely updates and support decision-making. Analyze cybersecurity incidents and recommend improvements to incident response procedures and operational processes. Participate in change management activities by reviewing network and infrastructure changes for potential security impacts. Develop and maintain technical documentation, operational procedures, and remediation plans. Required Qualifications Bachelor's degree or diploma in Cybersecurity, Network Engineering, Computer Science, Information Systems, or a related field, or equivalent professional experience. Experience supporting enterprise security operations in complex, distributed, and hybrid environments. Strong understanding of firewalls, intrusion detection and prevention systems (IDS/IPS), VPNs, proxy services, secure web gateways, DNS security, load balancers, and network access controls. Experience reviewing firewall rules, access control lists (ACLs), network flows, routing paths, and security policies. Experience analyzing network traffic, packet captures, system logs, and security alerts to support threat detection and incident response. Strong knowledge of TCP/IP, routing, switching, VLANs, NAT, DNS, DHCP, VPNs, wireless security, and common network protocols. Familiarity with Zero Trust architecture, network segmentation, least-privilege access, and secure remote access principles. Experience documenting security findings, technical recommendations, risk assessments, and remediation activities. Knowledge of cybersecurity frameworks and standards, including NIST Cybersecurity Framework, CIS Controls, ISO/IEC 27001, and ISO/IEC 27002. Experience participating in change management and security review processes. Experience using ServiceNow for incident and service request management. Strong troubleshooting, analytical, communication, and problem-solving skills. Ability to communicate technical concepts effectively to both technical and non-technical stakeholders. Preferred Qualifications Experience supporting Privileged Access Management (PAM) platforms. Experience conducting phishing simulations and security awareness initiatives. Experience with packet capture analysis and digital forensic investigations. Familiarity with cloud security technologies and hybrid infrastructure environments. Experience working in Security Operations Center (SOC) environments. Certifications CISSP (Preferred). CISM (Preferred). CCNP Security (Preferred). CCIE Security (Preferred). Fortinet NSE (Preferred). Palo Alto PCNSE (Preferred). Check Point CCSA/CCSE (Preferred). CompTIA Security+ (Preferred). Education: Bachelors Degree Certification: CompTIA Security+ , Check Point CCSA/CCSE , Palo Alto PCNSE , Fortinet NSE , CCIE Security , CCNP Security , CISM , CISSP
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
- Dice Id: compun
- Position Id: JASDC5849574
- Posted 1 day ago