- Monitor and analyze security events from SIEM, endpoint, network, email, and cloud security platforms
- Triage security alerts and escalade or respond according to incident response procedures
- Support incident response, including investigation, containment, eradication, recovery, documentation, and evidence handling
- Perform vulnerability scanning and assist with risk-based prioritization and remediation tracking
- Maintain and improve security documentation, runbooks, SOPs, and knowledge base articles
- Implement, configure, and validate security controls across endpoints, identity systems, networks, and cloud services
- Collaborate with infrastructure, application, business, and cross-functional teams to remediate findings and strengthen security posture
- Improve detection capabilities by tuning alerts and reducing false positives
- Support audit and compliance activities by maintaining evidence and control documentation and participating in assessments
- Research emerging threats, vulnerabilities, and attack techniques
- Generate reports on incidents, vulnerabilities, and security metrics for technical and non-technical stakeholders
- Provide occasional on-site or remote support for security implementations and assessments across multiple locations
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, or a related field
- Minimum 1 year of experience in a security-related role
- CompTIA Security+, CompTIA CySA+, (ISC)² SSCP, or equivalent certification
- Foundational understanding of security operations, threat detection, incident response, and vulnerability management
- Familiarity with SIEM, EDR, vulnerability scanners, firewalls, email security platforms, and identity/security controls
- Basic knowledge of Windows, Linux, networking fundamentals, and Active Directory or identity management systems
- Understanding of Zero Trust, least privilege access, and defense-in-depth
- Awareness of phishing, malware, credential attacks, and MITRE ATT&CK concepts
- Ability to identify and assess security risks and vulnerabilities
- Strong analytical and problem-solving skills with attention to detail
- Willingness to learn and stay current with evolving cybersecurity threats and technologies
- Ability to work independently and collaboratively
- Ability to communicate effectively with technical and non-technical stakeholders
- Ability to work in a fast-paced, dynamic environment
- Ability to collaborate with cross-functional teams
- Exposure to Microsoft 365, Azure, AWS, and associated security controls is a plus
- Understanding of NIST CSF, NIST SP 800-53, CIS Critical Security Controls, or ISO 27001 preferred
Core Competencies
Demonstrates expertise in security operations, incident response, and vulnerability management, with a strong foundation in threat detection and risk assessment. Proficient in collaborating with cross-functional teams to enhance security posture and maintain compliance with industry standards.
Highest-signal resume keywords
- CompTIA Security+ Certification
- Incident Response Procedures
- Vulnerability Management
- SIEM Familiarity
- Threat Detection
ATS Optimization Keywords
Hard Skills
- Security Operations
- Incident Response
- Vulnerability Scanning
- Risk Assessment
- Threat Detection
- Security Documentation
- Security Controls Implementation
- Analytical Skills
- Problem-Solving Skills
- Knowledge of MITRE ATT&CK
Soft Skills
- Attention to Detail
- Effective Communication
- Collaboration
- Willingness to Learn
- Ability to Work Independently
Certifications & Qualifications
- CompTIA Security+
- CompTIA CySA+
- (ISC)² SSCP
Industry Keywords
- Zero Trust
- Least Privilege Access
- Defense-in-Depth
- NIST CSF
- NIST SP 800-53
- CIS Critical Security Controls
- ISO 27001
- Phishing
- Malware
- Credential Attacks
Tools & Technologies
- SIEM
- EDR
- Vulnerability Scanners
- Firewalls
- Email Security Platforms
- Microsoft 365
- Azure
- AWS
- Active Directory
- Identity Management Systems