Information Security Analyst

Cisive

Maryland

Hybrid

USD 80,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Cisive is looking for a Security Operations professional in Maryland who will be responsible for monitoring and managing security systems. The role demands hands-on experience with SIEM platforms and a solid understanding of vulnerability management.

The ideal candidate will have 3–5 years of experience in information security, along with excellent communication and analytical skills. The position also emphasizes collaboration and compliance efforts related to SOC 2.

Qualifications

  • 3–5 years of experience in an information security role.
  • Hands-on experience with SIEM platforms.
  • Strong analytical and problem-solving skills.

Responsibilities

  • Monitor and triage alerts across the SIEM platform.
  • Manage the vulnerability management lifecycle.
  • Support endpoint security and network monitoring tools.

Skills

Information security experience
SIEM platforms (Splunk, Microsoft Sentinel)
Vulnerability management tools (Tenable, Nessus)
SOC 2 Trust Service Criteria knowledge
Analytical and problem-solving skills
Communication skills

Tools

Python
PowerShell
GRC platforms (Archer, ServiceNow GRC)

Job description

Job Description

It's fun to work in a company where people truly BELIEVE in what they're doing! We're committed to bringing passion and customer focus to the business.

Security Operations & Tooling

Responsibilities
  • Monitor, tune, and triage alerts across the SIEM platform, escalating confirmed incidents per established runbooks
  • Manage the vulnerability management lifecycle— including scanning, prioritization, remediation tracking, and executive reporting
  • Support endpoint security, email security, and network monitoring tools; identify gaps and recommend configuration improvements
  • Conduct periodic threat hunting activities and contribute to the development of detection rules and playbooks
  • Participate in incident response activities including containment, eradication, and post-incident reviews
  • Governance, Risk & Compliance (GRC): Support ongoing SOC 2 Type II compliance efforts, including evidence collection, control testing, and coordination with external auditors
  • Assist with NIST CSF assessments — mapping current controls to framework functions and identifying gaps for remediation
  • Maintain and update security policies, standards, and procedures in collaboration with senior team members
  • Conduct periodic security risk assessments and contribute findings to the organization risk register
  • Track remediation efforts for identified risks and control deficiencies through to closure
  • Collaborate & Communicate: Partner with IT, Engineering, and business stakeholders to embed security best practices into day-to-day operations
  • Assist in security awareness initiatives and provide guidance to staff on security topics
  • Prepare clear, concise reporting on security metrics, vulnerability status, and compliance posture for management
Qualifications (Required)
  • 3–5 years of experience in an information security role with exposure to both technical operations and compliance functions
  • Hands‑on experience with SIEM platforms (Splunk, Microsoft Sentinel, or equivalent)
  • Working knowledge of vulnerability management tools such as Tenable, Nessus/IO, or Qualys
  • Demonstrated understanding of SOC 2 Trust Service Criteria and NIST Cybersecurity Framework
  • Familiarity with common attack techniques and defensive countermeasures (MITRE ATT&CK familiarity a plus)
  • Strong analytical and problem‑solving skills with the ability to work both independently and collaboratively
  • Excellent written and verbal communication skills; ability to translate technical findings for non‑technical audiences
Preferred
  • Relevant certifications such as CompTIA Security+, CySA+, CEH, CISM, or equivalent
  • Experience supporting a SOC 2 audit from end to end
  • Scripting or automation skills (Python, PowerShell) for security tooling and reporting
  • Exposure to cloud security (AWS, Azure, or GCP) environments
  • Experience working with GRC platforms (e.g., Archer, ServiceNow GRC, Drata, Vanta)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst
Security Analyst

The Phoenix Group • New York (NY)

On-site
USD 65,000 - 95,000
IT Security Specialist
IT Security Specialist

ibex • Palestine (TX)

On-site
USD 90,000 - 130,000
Information Security Engineer
Information Security Engineer

Gotham Technology Group • New York (NY)

On-site
USD 120,000 - 160,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

10xTalents • Washington

On-site
USD 80,000 - 110,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Information Security Analyst
Information Security Analyst

Jobtailor • Atlanta (GA)

On-site
USD 85,000 - 120,000
Information Technology Security Analyst
Information Technology Security Analyst

The Phoenix Group • New York (NY)

On-site
USD 80,000 - 120,000
Dover, DE - IT - DTI - Security Office - Information Security Analyst 1
Dover, DE - IT - DTI - Security Office - Information Security Analyst 1

Expedite Technology Solutions LLC • Dover (DE)

On-site
USD 70,000 - 90,000
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Sr. Security Engineer - SIEM, Automation & Elastic Security
Sr. Security Engineer - SIEM, Automation & Elastic Security

Red Lobster, Inc. • Orlando (FL)

On-site
USD 90,000 - 130,000