Cyber Security Analyst

Stefanini Group

Atlanta (GA)

On-site

USD 110,000 - 150,000

Full time

19 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Stefanini Group is seeking a Cyber Security Analyst with strong Splunk Enterprise and Splunk Enterprise Security experience to monitor, investigate, and respond to cyber threats in a banking and financial services environment.

You will focus on threat-alert triage, incident investigation, threat hunting, and security monitoring across critical financial systems, leveraging Splunk for detection, analysis, and response. The role emphasizes collaboration with SOC processes and MITRE ATT&CK mapping.

Qualifications

  • 5+ years of experience in cybersecurity operations, SOC monitoring, or incident response.
  • Strong hands-on experience with Splunk and SPL query development.
  • Experience in banking, financial services, payments, fintech, or regulated environments.
  • Knowledge of financial-sector risks, including fraud, account takeover, payment-system threats, insider risk, and protection of sensitive customer data.
  • Familiar with Windows / Linux, network security, identity and access management, EDR, cloud security, and incident‑response processes.

Responsibilities

  • Monitor and triage Splunk notable events, correlation searches, dashboards, and risk-based alerts.
  • Investigate suspicious authentication, privileged-account activity, malware, phishing, ransomware, data exfiltration, and unauthorized transactions or system access.
  • Write and optimize SPL queries for alert investigation, event correlation, and threat hunting.
  • Analyze logs from SIEM, EDR, firewalls, VPN, identity platforms, cloud services, applications, and banking systems.
  • Validate true and false positives, prioritize alerts by risk, and elevate confirmed incidents according to SOC procedures.
  • Develop and tune Splunk correlation searches, dashboards, reports, and detection rules to reduce false positives and improve coverage.
  • Support incident response, root-cause analysis, evidence preservation, and post-incident reporting.
  • Map threats and detections to MITRE ATT&CK and relevant financial-sector security controls.

Skills

SPL query development
Splunk knowledge
Incident response
Threat monitoring
Financial services domain knowledge

Tools

Splunk
EDR

Job description

We are seeking a Cyber Security Analyst with strong Splunk Enterprise / Splunk Enterprise Security experience to monitor, investigate, and respond to cyber threats within a banking and financial services environment. The role will focus on threat-alert triage, incident investigation, threat hunting, and security monitoring across critical financial systems.


Key Responsibilities:


  • Monitor and triage Splunk notable events, correlation searches, dashboards, and risk-based alerts.

  • Investigate suspicious authentication, privileged-account activity, malware, phishing, ransomware, data exfiltration, and unauthorized transactions or system access.

  • Write and optimize SPL queries for alert investigation, event correlation, and threat hunting.

  • Analyze logs from SIEM, EDR, firewalls, VPN, identity platforms, cloud services, applications, and banking systems.

  • Validate true and false positives, prioritize alerts by risk, and elevate confirmed incidents according to SOC procedures.

  • Develop and tune Splunk correlation searches, dashboards, reports, and detection rules to reduce false positives and improve coverage.

  • Support incident response, root-cause analysis, evidence preservation, and post-incident reporting.

  • Map threats and detections to MITRE ATT&CK and relevant financial-sector security controls.


Required Qualifications:


  • 5+ years of experience in cybersecurity operations, SOC monitoring, or incident response.

  • Strong hands-on experience with Splunk and SPL query development.

  • Experience in banking, financial services, payments, fintech, or regulated environments.

  • Knowledge of financial-sector risks, including fraud, account takeover, payment-system threats, insider risk, and protection of sensitive customer data.

  • Familiar with Windows / Linux, network security, identity and access management, EDR, cloud security, and incident‑response processes.

  • Strong analysis / key campo

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Analyst - Splunk & Threat Hunting
Cyber Security Analyst - Splunk & Threat Hunting

Stefanini Group • Atlanta (GA)

On-site
USD 110,000 - 150,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Mbi Llc • Richmond (VA)

On-site
USD 110,000 - 160,000
Cyber Security Specialist
Cyber Security Specialist

ECLARO • Jacksonville (FL)

On-site
USD 100,000 - 140,000
Cybersecurity Engineer
Cybersecurity Engineer

SSV Technologies Inc. • Richmond (VA)

On-site
USD 120,000 - 180,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Delan Associates Inc. • Richmond (VA)

On-site
USD 110,000 - 160,000
Cybersecurity Engineer
Cybersecurity Engineer

Creative Solutions Services, LLC • Richmond (VA)

On-site
USD 120,000 - 170,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Delan Associates, Inc • Richmond (VA)

On-site
USD 110,000 - 150,000
Cyber Analyst- Level 3
Cyber Analyst- Level 3

CRI Advantage, Inc. • Idaho Falls (ID)

On-site
USD 110,000 - 170,000
Cyber Intelligence Analyst
Cyber Intelligence Analyst

SECU • United States

On-site
USD 120,000 - 180,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Ampcus Inc • Richmond (VA)

On-site
USD 110,000 - 160,000