Cybersecurity Analyst (Digital Forensics/Incident Response)

Columbia University Information Technology

New York (NY)

On-site

USD 80,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A major educational institution is seeking a Cybersecurity Analyst to enhance security measures in response to cyber threats. The role focuses on threat detection, incident handling, and risk remediation while collaborating with IT teams to strengthen security posture across systems and cloud environments. Candidates should have significant experience with endpoint forensic tools and SIEM platforms, along with a Bachelor's degree. This position requires strong analytical and communication skills, and the ability to respond to high-severity incidents.

Qualifications

  • 3-5 years of related experience required.
  • 2+ years of experience with endpoint forensic tools.
  • Proficiency in analyzing NetFlow, packet data, and system logs.

Responsibilities

  • Initiates and supports DFIR investigations.
  • Conducts endpoint and network forensic analysis.
  • Coordinates incident response efforts across IT teams.

Skills

Endpoint forensic tools
Incident response
Vulnerability management
Communication skills
Analytical thinking

Education

Bachelor's degree or equivalent experience

Tools

SIEM platforms
Python
PowerShell

Job description

Reporting to the Manager of Cybersecurity Operations, the Cybersecurity Analyst supports Columbia University’s enterprise-wide Digital Forensics and Incident Response (DFIR) program. This role focuses on threat detection, incident handling, forensic investigation, and risk remediation. The analyst will collaborate across IT teams to strengthen security posture, improve detection and response capabilities, and mitigate cyber threats impacting the University’s systems, networks, and cloud environments.

Responsibilities
  • Initiates and supports DFIR investigations, including identification, containment, eradication, and recovery from cyberattacks.
  • Conducts endpoint and network forensic analysis to determine root cause and impact.
  • Performs malware analysis, memory forensics, and reverse engineering as needed.
  • Coordinates incident response efforts across IT teams, including phishing, DDoS, malware, and data breach events.
  • Develop post-incident reports and lessons-learned documentation to improve future response efforts.
  • Creates and optimizes SIEM alerts, dashboards, and metrics to proactively identify suspicious activity.
  • Monitors intrusion detection systems, log sources, and other telemetry for security events.
  • Investigates anomalies using NetFlow, packet capture, DNS logs, and endpoint data.
  • Continuously refines detection logic to address evolving attacker tactics.
Security Operations & Process Improvement
  • Develops and maintains incident response playbooks, workflows, and operational documentation.
  • Collaborate with campus IT departments to integrate standardized IR processes.
  • Enhance operational readiness through tabletop exercises and simulation drills.
  • Supports vulnerability management and assist in remediation prioritization.
  • Extend incident response and monitoring capabilities into cloud environments (AWS, Azure, GCP).
  • Oversees cloud configuration and vulnerability assessments to maintain security compliance.
Other Responsibilities
  • Participates in a 24/7 on-call rotation, responding to high-severity incidents as required.
  • Administers endpoint security tools, including application allowlisting and data loss prevention solutions.
  • Stays informed on emerging threats, vulnerabilities, and security best practices.
  • Willingness to attend cybersecurity-related training and seek security certifications when offered.
  • All other duties as assigned.
Minimum Qualifications
  • Bachelor's degree or equivalent experience required.
  • Minimum 3-5 years’ related experience.
  • 2+ years of experience with endpoint forensic tools and investigation techniques.
  • 2+ years of experience building alerts and dashboards in a SIEM platform.
  • Hands‑on experience with incident response, vulnerability management, and security monitoring at scale.
  • Proficiency in analyzing NetFlow, packet data, DNS, and system logs for investigative purposes.
  • Strong knowledge of exploits and attack vectors (e.g., OWASP Top 10, privilege escalation).
  • Familiarity with multiple operating systems: Windows, macOS, Linux/Unix, and mobile platforms (iOS/Android).
  • Excellent written and verbal communication skills.
  • Demonstrated ability to work in a fast‑paced, deadline‑driven environment.
  • Demonstrated excellence in a variety of competencies including teamwork/collaboration, analytical, thinking, communication and influencing skills, and technical expertise.
  • Ability to work with changing priorities and with multiple projects.
  • Ability to be precise and attentive to detail is essential.
  • Ability to work with minimal supervision.
  • Ability to work weekends and off‑hours as and when needed.
Preferred Qualifications
  • Advanced degree in Computer Science, Information Security, or a related field.
  • Experience scripting and automating tasks using Python, PowerShell, or similar languages.
  • Familiarity with SOAR platforms and automation workflows.
  • Background in penetration testing or network security engineering.
  • Experience with identity and access management tools and projects.
  • Security certifications (e.g., Security+, CISSP, GIAC, CISM, CEH).
  • Cloud security certification (e.g., AWS Security Specialty, Azure Security Engineer, Cloud+).

Equal Opportunity Employer / Disability / Veteran

Columbia University is committed to the hiring of qualified local residents.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IBM CISO - Cybersecurity Forensic Analyst
IBM CISO - Cybersecurity Forensic Analyst

IBM • Austin (TX)

On-site
USD 110,000 - 160,000
Mid-Level Digital Forensics and Incident Response Analyst
Mid-Level Digital Forensics and Incident Response Analyst

Jobtailor • Huntsville (AL)

On-site
USD 90,000 - 130,000
Sr. Cyber Defense Analyst
Sr. Cyber Defense Analyst

Patriot Talent Solutions • United States

On-site
USD 120,000 - 190,000
Sr. Incident Response Analyst
Sr. Incident Response Analyst

Compunnel, Inc. • Jersey City (NJ)

On-site
USD 100,000 - 130,000
Cybersecurity Analyst
Cybersecurity Analyst

Quantum Integrators Group • West Windsor (NJ)

Hybrid
USD 80,000 - 100,000
Competitive salary
Performance-based bonuses
Learning and professional development opportunities
+2
Cybersecurity Incident Response Analyst
Cybersecurity Incident Response Analyst

MFI Technologies Incorporated • New York (NY)

On-site
USD 75,000 - 100,000
Digital Forensics and Incident Analyst (TS)
Digital Forensics and Incident Analyst (TS)

Agile Defense • Washington

On-site
USD 120,000 - 160,000
Cyber Command Forensic Analyst
Cyber Command Forensic Analyst

Govserviceshub • New York (NY)

On-site
USD 80,000 - 100,000
Senior Security Analyst
Senior Security Analyst

Yardi • Santa Barbara (CA)

On-site
USD 97,000 - 110,000
Senior Cyber Manager
Senior Cyber Manager

Peraton • Washington

On-site
USD 120,000 - 170,000