Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Division of Administration/Office of Technology Services in Louisiana is seeking an IT Infosec Associate Analyst to monitor, triage, and respond to cyber threats across the enterprise. You will use Cortex XSIAM and CrowdStrike to analyze alerts, coordinate remediation with various teams, and help strengthen our security posture.
The role offers career progression within the Information Security team and requires a mix of education and IT experience.
The Division of Administration/Office of Technology Services has avacancy. This position is located in the Infosec Section. Req.226418
The Office of Technology Services aims to be a responsible partner in delivering innovative, effective, and reliable solutions that support and enhance the IT functions within Executive Branch Departments. The Office of Technology Services will work to increase the return on the State's investment in technology by promoting smart decision-making, solving problems intelligently, increasing the rate of project success, and fostering a skilled and professional staff.
This position is within the Office of Technology Services (OTS), Information Security Team. This position receives direction and priority from the Director of Information Security Engineering and Architecture to monitor, detect, analyze, and respond to cyber threats across the enterprise. This position is responsible for providing centralized security event triage, incident response coordination, and technical support across various computer systems, applications, and networks. The individual will utilize technical, analytical, and problem-resolution skills to investigate security alerts, mitigate emerging threats, and collaborate across technical support teams and state agencies to protect the State's information assets.
The Division of Administration is the state government's management arm and the hub of its financial operations. Division offices perform a wide variety of activities including the following:
Two years of experience in information technology; OR
Six years of full-time work experience in any field; OR
An associate's degree in information technology; OR
A bachelor's degree.
EXPERIENCE SUBSTITUTION:
Every 30 semester hours earned from an accredited college or university will be credited as one year of experience towards the six years of full-time work experience in any field. The maximum substitution allowed is 120 semester hours which substitutes for a maximum of four years of experience in any field.
NOTE:
A certification in an approved area may be substituted for the education and/or experience requirements at the time of hire or promotion, provided the appointment is made from a Certificate of Eligibles.
where the official job specifications for this role, as defined by the State Civil Service, can be found here.
Monitor, triage, and investigate real-time security alerts generated through Palo Alto Networks Cortex XSIAM and CrowdStrike Falcon Complete platforms.
Validate high-priority threat notifications, evaluate context, and execute initial containment protocols in accordance with enterprise incident response playbooks.
Coordinate remediation workflows with the CrowdStrike Falcon Complete managed service team and relevant OTS technical verticals.
Document investigation findings, root cause analyses, and response actions taken within the centralized security incident log.
Assist in tuning detection logic, correlation rules, and automated response playbooks within Cortex XSIAM to reduce false positives.
Monitor and manage the ServiceNow ticketing queue for proxy-related issues, access requests, and categorized URL reclassification tickets.
Troubleshoot and resolve web filtering issues, SSL/TLS decryption exceptions, and secure web gateway (SWG) connection anomalies for enterprise users.
Analyze user traffic patterns against acceptable use policies to identify policy violations, unauthorized application usage, or potential evasion attempts.
Maintain operational documentation and standard operating procedures (SOPs) for enterprise proxy management and ticket workflows.
Investigate suspicious internal and perimeter network traffic, protocol anomalies, and anomalous host behaviors using network telemetry and log sources.
Perform proactive threat hunting using threat intelligence indicators (IoCs) and behavioral analytics to identify potential adversary activity (TTPs).
Correlate disparate log sources (firewall, DNS, VPN, authentication, and endpoint logs) to reconstruct attack timelines and assess scope of impact.
Escalate confirmed intrusions or advanced persistent threats (APTs) to senior incident response personnel and OTS leadership.
Monitor identity provider signals and behavioral analytics for indications of compromised user credentials, impossible travel, and unauthorized account modifications.
Coordinate directly with the OTS Service Desk and identity teams to initiate account locks, password resets, session revocations, and MFA step-up authentication for compromised users.
Verify post-compromise cleanup actions, ensuring persistent access mechanisms (e.g., malicious inbox forwarding rules, unauthorized OAuth applications) are identified and purged.
Advise agency points of contact and help desk personnel on best practices for user remediation and credential hygiene.
Performs all other tasks, special projects, analysis, studies, and plans as directed by OTS Leadership
This vacancy will be filled by new hire or by promotion of a current permanent status classified employee.
This vacancy participates in a career progression group and may be filled from this recruitment as an IT Infosec Associate Analyst 1 or 2.
No Civil Service test score is required in order to be considered for this vacancy.
Information to support your eligibility for the position must be included in the application (i.e., relevant, detailed experience/education). Resumes will not be accepted in lieu of completed education and experience sections. Applications may be rejected if incomplete. The transcripts can be added as an attachment to your online application. The selected candidate will be required to submit original documentation upon hire.
Prior to a new hire, a background check, including criminal record history, will be conducted. Information from the background check will not necessarily preclude employment, but will be considered in determining the applicant’s suitability and competence to perform in the position. A criminal history check may be conducted on employees changing positions, including promotions, demotions, details, reassignments, and transfers. Also, prospective employees may be subject to pre-employment drug testing. New hires will be subject to employment eligibility verification via the federal government's E-Verify system.
Erica R. Gay
HR Specialist
Division of Administration/Office of Human Resources
Email: Erica.Gay@la.gov