An application made for this job — a tailored resume and cover letter that speak straight to the posting.
State of Louisiana’s Division of Administration, Office of Technology Services, Information Security Team seeks an IT Infosec Associate Analyst. The role monitors security events, coordinates incident response, analyzes network activity, and assists with identity remediation across state systems.
The position reports to the Director of Information Security Engineering and Architecture and will work within a centralized security operations framework to protect state information assets.
The Division of Administration/Office of Technology Services has vacancy. This position is located in the Infosec Section. Req.226418 The Office of Technology Services aims to be a responsible partner in delivering innovative, effective, and reliable solutions that support and enhance the IT functions within Executive Branch Departments. The Office of Technology Services will work to increase the return on the State's investment in technology by promoting smart decision‑making, solving problems intelligently, increasing the rate of project success, and fostering a skilled and professional staff. This position is within the Office of Technology Services (OTS), Information Security Team. This position receives direction and priority from the Director of Information Security Engineering and Architecture to monitor, detect, analyze, and respond to cyber threats across the enterprise. This position is responsible for providing centralized security event triage, incident response coordination, and technical support across various computer systems, applications, and networks. The individual will utilize technical, analytical, and problem‑resolution skills to investigate security alerts, mitigate emerging threats, and collaborate across technical support teams and state agencies to protect the State's information assets.
The Division of Administration is the state government’s management arm and the hub of its financial operations. Division offices perform a wide variety of activities including the following:
The official job specifications for this role, as defined by the State Civil Service, can be found here.
Security Event Monitoring and Alert Response Monitor, triage, and investigate real-time security alerts generated through Palo Alto Networks Cortex XSIAM and CrowdStrike Falcon Complete platforms.
Validate high‑priority threat notifications, evaluate context, and execute initial containment protocols in accordance with enterprise incident response playbooks.
Coordinate remediation workflows with the CrowdStrike Falcon Complete managed service team and relevant OTS technical verticals.
Document investigation findings, root cause analyses, and response actions taken within the centralized security incident log.
Assist in tuning detection logic, correlation rules, and automated response playbooks within Cortex XSIAM to reduce false positives.
Proxy Operations and Ticket Resolution Monitor and manage the ServiceNow ticketing queue for proxy‑related issues, access requests, and categorized URL reclassification tickets.
Troubleshoot and resolve web filtering issues, SSL/TLS decryption exceptions, and secure web gateway (SWG) connection anomalies for enterprise users.
Analyze user traffic patterns against acceptable use policies to identify policy violations, unauthorized application usage, or potential evasion attempts.
Maintain operational documentation and standard operating procedures (SOPs) for enterprise proxy management and ticket workflows.
Network Traffic Analysis and Threat Hunting Investigate suspicious internal and perimeter network traffic, protocol anomalies, and anomalous host behaviors using network telemetry and log sources.
Perform proactive threat hunting using threat intelligence indicators (IoCs) and behavioral analytics to identify potential adversary activity (TTPs).
Correlate disparate log sources (firewall, DNS, VPN, authentication, and endpoint logs) to reconstruct attack timelines and assess scope of impact.
Escalate confirmed intrusions or advanced persistent threats (APTs) to senior incident response personnel and OTS leadership.
Identity Compromise Coordination and Remediation Monitor identity provider signals and behavioral analytics for indications of compromised user credentials, impossible travel, and unauthorized account modifications.
Coordinate directly with the OTS Service Desk and identity teams to initiate account locks, password resets, session revocations, and MFA step‑up authentication for compromised users.
Verify post‑compromise cleanup actions, ensuring persistent access mechanisms (e.g., malicious inbox forwarding rules, unauthorized OAuth applications) are identified and purged.
Advise agency points of contact and help desk personnel on best practices for user remediation and credential hygiene.
Additional Responsibilities Performs all other tasks, special projects, analysis, studies, and plans as directed by OTS Leadership.
Appointment Type: This vacancy will be filled by new hire or by promotion of a current permanent status classified employee.
Career Progression: This vacancy participates in a career progression group and may be filled from this recruitment as an IT Infosec Associate Analyst 1 or 2.