Job Title: jr. Security Analyst
Job Location: Blythewood, SC (Onsite)
Position Type: W2 Contract
Duration: 12+ months
Job Title: jr. Security Analyst
Job Location: Blythewood, SC (Onsite)
Position Type: W2 Contract
Duration: 12+ months
Primary Skills
Security concepts and processes, basic computer and network concepts, threat intelligence research, threat hunting, detection rule creation, log analysis, incident response, documentation and reporting, vulnerability management, security awareness training, security automation and scripting, endpoint and network security, digital forensics and cloud security
Preferred Skills
1+ year of experience in an IT security-focused role, SIEM and endpoint security tools, PowerShell, Group Policy, endpoint management, vulnerability management, cloud security, Bachelor's Degree in Information Technology, Computer Science, Cybersecurity or related field, 1+ years of server or network administration
Position Overview
A state agency's security team is seeking candidates to fill an entry-level security position. The selected candidate will be trained to perform the tasks listed below. At a minimum, the team is looking for basic server or network administration skills that can be built upon. The scope of the project is to enhance the security posture of the organization to protect sensitive citizen data and ensure the integrity of licensing and titling systems.
Note
Availability for Saturday and Sunday evening shifts is required, as they will be part of the selected resource's schedule after training. This is mandatory.
- Threat Intelligence Research
- Monitor and analyze threat intelligence feeds to identify emerging threats relevant to the organization.
- Document findings, such as new attack methods or vulnerabilities, and share with the team.
- Use open-source intelligence (OSINT) tools to gather data on potential risks and adversaries.
- Threat Hunting and Detection Rule Creation
- Conduct proactive searches for suspicious behavior in network and endpoint activity using provided tools and playbooks.
- Utilize threat feeds, investigate suspicious activity, and stay current on cyber threats.
- Collaborate with senior analysts to refine and test detection rules (e.g., SIEM queries or Defender for Endpoint rules).
- Document hunting methodologies and findings to support continuous improvement.
- Log Analysis
- Review and interpret logs from firewalls, endpoints, and servers to identify indicators of compromise (IOCs).
- Escalate findings, such as anomalous IP addresses or unauthorized access attempts, to senior analysts.
- Maintain a log of recurring patterns or anomalies for long-term tracking and analysis.
- Incident Response
- Assist in initial triage of security incidents by following response frameworks (e.g., NIST, MITRE ATT&CK).
- Identify and elevate potential security threats.
- Gather and analyze relevant evidence, such as logs or alert data, to determine the scope and severity of incidents.
- Document findings during incidents and contribute to containment and remediation efforts.
- Documentation, Reporting, and Communication
- Create clear, detailed reports, including incident reports, after-action reviews, and process documentation.
- Deliver reports on the security posture and propose mitigation strategies.
- Draft training materials or guides to help improve organizational awareness and readiness.
- Regularly update and organize documentation to ensure accuracy and accessibility for team use.
- Vulnerability Management
- Analyze reports, prioritize patching, and understand NIST best practices.
- Security Automation and Scripting
- Leverage SCCM, GPO, and PowerShell for patch deployment.
- Automate tasks beyond SCCM, GPO, and PowerShell to increase efficiency.
- Endpoint and Network Security
- Configure policies, analyze alerts, and manage endpoint protection.
- Understand network protocols and firewalls to strengthen the overall security posture.
- Digital Forensics and Cloud Security
- Investigate security incidents and collect evidence for deeper analysis.
- Develop knowledge of cloud-specific security solutions as cloud adoption grows.
- Understanding of security concepts and processes
- Understanding of basic computer and network concepts
- 1+ Year of Experience in an IT Security Focused Role
- Experience with SIEM and Endpoint Security Tools
- Experience with PowerShell, Group Policy, and Endpoint Management
- Knowledge of Vulnerability Management and Cloud Security
- Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, or a related field
- 1+ Years of Experience in Server or Network Administration
- Problem-Solving: Analyze data, identify anomalies, and recommend solutions.
- Attention to Detail: Ensure accurate analysis and configuration for effective security measures.
- Ability to communicate and work effectively with a mid-size team.
- GIAC Security Essentials (GSEC)
- Security+ (CompTIA)
- Network+ (CompTIA)
- GIAC Incident Handler (GCIH)