An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Cabrillo Coastal General Insurance Agency is seeking a hands-on Cybersecurity Analyst to protect our information systems and data. You will investigate security incidents, administer security technologies, and partner with IT teams to implement safeguards and remediation actions.
The role emphasizes incident response, vulnerability management, and continuous improvement of security controls across endpoints, networks, and identity systems.
Our Cybersecurity Analyst is a hands‑on cybersecurity professional who is dedicated to maintaining the confidentiality, integrity and availability of Cabrillo Coastal’s information systems and data and helps protect the Company’s systems, networks, applications, data and users from cybersecurity threats. This position provides broad technical security support across the organization by investigating security incidents, administering cybersecurity technologies, identifying and evaluating risks and partnering with other technology teams to implement effective safeguards and corrective actions.
In the spirit of our Company’s mission, values and culture, the duties listed below serve as illustrations of the various types of work that may be performed by our Cybersecurity Analysts I/II/III. We also expect our Cybersecurity Analysts I/II/III to carry out other responsibilities that are similar, related or a logical assignment to this job class.
Requirements
Qualities: security-oriented; quality-oriented; detail-oriented; analytical; self-starter; team player; multi-tasker; adaptable; flexible; dependable; inquisitive; collaborative; service-oriented; coachable; strong work ethic; positive “can do” attitude; sound judgment; discretion; strong sense of ownership and accountability.
Strong skill sets in the following areas: cybersecurity incident investigation and response; technical troubleshooting; problem analysis and solving; risk identification and prioritization; effective decision-making; organization; time management and working under tight deadlines; technical research; documentation; active listening; asking productive questions; applying learned information to a variety of related or similar situations; oral and written communication; interpersonal communication; collaborating with technical and non-technical team members; translating complex technical findings into understandable business risks and actionable technical requirements; reviewing and analyzing endpoint, identity, authentication, firewall, email, network, cloud, application and operating-system logs; independently investigating a technical security finding, identifying potentially affected systems and users, evaluating possible business impact and recommending practical corrective actions; creating clear and complete security-remediation tickets that communicate the affected asset, identified condition, supporting evidence, potential risk, required action, priority and criteria for successful completion; appropriately handling confidential, sensitive and restricted Company information and maintaining discretion during cybersecurity investigations.
Strong working knowledge of: cybersecurity principles and practices, including defense in depth, least privilege, zero-trust concepts, identity security, endpoint security, network security, vulnerability management, system hardening, secure configuration, security monitoring, incident response and risk-based decision-making; cybersecurity threats and attacker techniques, including phishing, credential theft, malicious software, ransomware, social engineering, unauthorized access, privilege escalation, persistence, lateral movement and data exfiltration; Microsoft Windows operating systems, Active Directory, Microsoft Entra ID, Microsoft 365, identity and access-management principles, multifactor authentication and privileged-access controls; endpoint detection and response, antivirus, application control, firewall, vulnerability-management, email-security, identity-security and security-monitoring technologies; networking principles and technologies, including TCP/IP, DNS, DHCP, HTTP/S, VPNs, routing, switching, network segmentation, wireless networking and firewall rules; standard business writing, grammar and punctuation rules; telephone and email business etiquette rules; desktop computer operations; standard business software and web-based operations, including Microsoft Word, Microsoft Excel, Microsoft Outlook, Microsoft PowerPoint, Microsoft Teams and web browsers; familiarity with PowerShell, Python, application programming interfaces or other scripting and automation technologies is a plus; and familiarity with recognized cybersecurity frameworks, standards and regulatory requirements, including the NIST Cybersecurity Framework, CIS Controls, NIST security publications, NYDFS cybersecurity requirements and PCI DSS, is a plus.
Education for All levels: Bachelor’s degree in Cybersecurity, IT, Computer Science, or related field or equivalent experience and training.
Experience, LIcenses and Certifications:
IT Security Analyst I: 1–3 years in cybersecurity, IT operations, systems, networking, or related technical support; experience reviewing security alerts, logs, or suspicious activity. Security+ or similar entry-level certification preferred and relevant Microsoft or vendor certifications are a plus.
IT Security Analyst II: 3–5 years of cybersecurity or related infrastructure experience, signficiant experience independently investgating security incidents, hands‑on experience with EDR, firewalls, IAM/MFA, vulnerability management, or security monitoring and experience translating security findings into actionable remediation work. CySA+, Microsoft Security, GCIH, CEH, or relevant vendor certifications preferred.
IT Security Analyst III: 5–8+ years of cybersecurity or security engineering experience; experience leading incident investigations and complex remediation efforts; advanced experience managing enterprise security platforms; eExperience with security architecture, vulnerability management, threat hunting, and technical standard; experience mentoring others and serving as a technical escalation point. CISSP, CISM, GIAC, or advanced Microsoft/vendor certifications preferred.