Cybersecurity Analyst

Jobtailor

Cincinnati (OH)

On-site

USD 110,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor seeks an experienced security operations professional to monitor SIEM/EDR and respond to alerts on a 24/7 basis across hybrid environments. You will lead investigations, coordinate with MDR/MSSP partners, and drive audit readiness for SOC 2 Type 2 and related programs.

Responsibilities include PAM policy design, privileged-access reviews, mailbox security investigations, and phishing defense, with collaboration across IT Ops and Compliance.

Qualifications

  • BS/BA in Computer Science, Electrical Engineering, Information Security, or related field; equivalent experience considered.
  • Progressive experience in software, automation, or logistics environments with accountability.
  • Hands-on SIEM/EDR and security tool experience (Rapid7, Defender, Abnormal, KnowBe4, Intune, Securden PAM).
  • Working knowledge of SOC 2 Type 2 evidence collection and audit support.
  • Strong organizational, PM, and communication skills; ability to build trust at all levels.
  • High ethical standards; self-starter, decisive, energetic.
  • Skills and platform experience considered a plus: Microsoft Purview, Intune, Rapid7, MS 365/Azure, SharePoint, Vanta, MITRE ATT&CK, security certifications.

Responsibilities

  • Monitor SIEM/alerts 24/7 across networks, servers, cloud, and endpoints.
  • Perform triage, containment, and restore of affected systems.
  • Lead investigations of phishing and token-theft events; review mailboxes.
  • Coordinate incident follow-up with MDR/MSSP partners and run playbooks.
  • Provide audit evidence and logs for auditors on request.
  • Serve as primary contact for SOC 2 Type 2 audit and quarterly reviews.
  • Maintain logs/reports for audit readiness and remediation tracking.
  • Define PAM policies and conduct privileged-access reviews.
  • Review privileged access requests and enforce policy.
  • Define endpoint security baselines and policy compliance.
  • Monitor EDR/NGAV coverage and disk encryption; maintain audit trails.
  • Coordinate patch validation and vendor vulnerability remediation.
  • Design and tune mail security (SPF/DKIM/DMARC; phishing filters).
  • Investigate mail threats and manage quarantine decisions.
  • Review backup security configurations and participate in DR testing.
  • Track threat intelligence and map to MITRE ATT&CK.
  • Maintain enterprise security documents and incident response plans.
  • Lead security vendor evaluations and test deliverables.

Skills

Organizational skills
Project management
Communication
Self-starter
Energetic

Education

BS/BA in Computer Science or related field

Tools

Rapid7
Microsoft Defender
Abnormal Security
KnowBe4
Intune
Securden PAM
Microsoft Purview
Data Protection
MS 365/Azure
SharePoint
Vanta
MITRE ATT&CK
Security certifications

Job description

Responsibilities
  • Monitor SIEM/alerts (Rapid7 InsightIDR, Microsoft Defender, Abnormal Security) on a 24/7 basis across KPI networks, servers, cloud platforms, and endpoints.
  • Monitor for and respond to security alerts; perform first‑level triage, containment, and isolation/restoration of affected systems.
  • Conduct intrusion detection analysis, correlate events across systems, and document formal technical incident reports (e.g., Jira incident write‑ups).
  • Lead investigations of phishing, account compromise, and token‑theft events, including mailbox review, removal of malicious inbox rules, and data‑exposure assessment.
  • Coordinate Security Incident Follow‑up cadence with MDR/MSSP partners and execute response playbooks.
  • Provide control evidence to auditors and supply logs, screenshots, and exported configurations on request.
  • Serve as the primary technical contact for the SOC 2 Type 2 audit and the Ares Cyber Program quarterly reviews.
  • Maintain logs and reports required for ongoing audit readiness and remediation tracking.
  • Define PAM policies and implement supporting tooling.
  • Perform recurring privileged‑access reviews, monitor usage/logs, and track exceptions.
  • Review and approve or deny privileged access requests.
  • Define endpoint security baselines and track policy compliance across managed devices.
  • Monitor EDR/NGAV coverage and disk encryption (BitLocker, USB encryption) and maintain audit trail.
  • Partner with IT Operations and Compliance to validate Intune/ManageEngine patch deployment and address vendor‑reported critical vulnerabilities.
  • Design and maintain SPF/DKIM/DMARC, tune phishing filters (Abnormal/Defender), and track mail security settings.
  • Investigate mail‑borne threats, manage quarantine release decisions, and ensure audit coverage of mail security controls.
  • Review backup security configurations, validate encryption, and participate in DR testing.
  • Log DR test results and prepare related audit artifacts.
  • Define network segmentation requirements and ensure segmentation policy is enforced.
  • Maintain audit evidence for VLAN/firewall configurations and tune IDS/IPS/SIEM detections.
  • Classify critical assets, maintain the asset control matrix, and map assets to audit scope.
  • Flag unmanaged or "Not Monitored" devices and drive remediation.
  • Tune DLP rules, deploy/maintain agents, and review DLP incidents.
  • Partner with the Compliance Analyst to identify client data and intellectual property requiring protection.
  • Enforce app protection and configure Intune/MDM device compliance policies.
  • Track enrollment status and monitor access from managed devices.
  • Drive SSO rollouts and conditional access design via Microsoft Entra.
  • Perform monthly roster / ADP‑to‑AD reconciliation and produce active employee/contractor lists for leadership and audit.
  • Audit offboarding to ensure terminated accounts remain disabled.
  • Monitor for non‑compliant platform usage and intervene as required to ensure compliance with KPI policies.
  • Run phishing simulations (Microsoft Attack Simulation) and assign role‑based training through KnowBe4, including Snyk for engineering staff.
  • Customize training content, track completion, elevate non‑completion, and share threat trends with the organization.
  • Author and maintain enterprise security documents (policies, standards, baselines, guidelines, procedures) in Vanta, including the Incident Response Plan and Operations Security Policy.
  • Compile and analyze data for management reporting, KPIs, and the Monthly Vulnerability & Risk Register Review and Weekly Threat Intelligence Review.
  • Monitor threat intelligence feeds and apply MITRE ATT&CK and similar frameworks to identify TTPs.
  • Serve as technical evaluator and primary point of contact for security vendors (Rapid7, Insight Assurance, Abnormal, KnowBe4, Intrust IT, Securden, Vanta, JFrog, Salesforce Security).
  • Coordinate penetration testing engagements and review deliverables.
Requirements
  • BS/BA in Computer Science, Electrical Engineering, Information Security, or related field. Equivalent experience will be considered.
  • Progressive experience in software, automation, or logistics environments characterized by service, employee engagement, and a culture of accountability.
  • Hands‑on experience administering SIEM/EDR (Rapid7 preferred), Microsoft Defender, Abnormal Security or comparable email security, KnowBe4 or comparable SAT platform, Intune, and a PAM tool such as Securden.
  • Working knowledge of SOC 2 Type 2 evidence collection and audit support.
  • Strong organizational, project management, and written/oral communication skills; ability to build relationships and establish trust at all levels.
  • High ethical and professional standards; self‑starter, decisive, high energy.
  • Skills and platform experience considered a plu s:
  • Microsoft Purview / Data Protection
  • Microsoft Intune
  • Rapid 7
  • MS O365 / Azure
  • SharePoint
  • Vanta
  • MITRE ATT&CK proficiency
  • Industry cybersecurity certifications (Security+, CySA+, CISSP, etc.)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial • Washington

On-site
USD 140,000 - 190,000
Senior Cybersecurity Associate
Senior Cybersecurity Associate

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
IT Security Specialist
IT Security Specialist

ibex • Palestine (TX)

On-site
USD 90,000 - 130,000
Cybersecurity Analyst
Cybersecurity Analyst

EXOS • Indianapolis (IN)

On-site
USD 90,000 - 120,000
Senior Security Analyst – Security Operations Center
Senior Security Analyst – Security Operations Center

Jobtailor • Town of Florida (NY)

On-site
USD 120,000 - 180,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Senior Security Analyst, Cyber Defense
Senior Security Analyst, Cyber Defense

Jobtailor • Minneapolis (MN)

On-site
USD 110,000 - 140,000
Security Engineer
Security Engineer

Eleven Recruiting • San Francisco (CA)

On-site
USD 120,000 - 160,000
Cyber Security Analyst
Cyber Security Analyst

L2R Consulting • Tampa (FL)

On-site
USD 70,000 - 110,000