Security Analyst
Job Summary (Security Analyst )
Partner with MDR Provider: Work closely with Managed Detection and Response (MDR) providers to support 24/7 threat monitoring and incident response.
SOC & SIEM Operations: Monitor, triage, and investigate security alerts within a Security Operations Center (SOC) environment using SIEM platforms.
Incident Response: Assist in analyzing, containing, and remediating security incidents and participate in ongoing security program execution.
Collaboration: Work with internal IT and security teams to improve detection, response procedures, and workflow efficiency.
Security Awareness: Support and help administer security awareness and phishing simulation programs, including user education and security training materials.
Vulnerability Management: Analyze vulnerability scan results, prioritize and track remediation efforts, and report on progress in collaboration with IT.
Identity & Access Management: Assist with identity security (Microsoft Entra ID), access reviews, role-based access control (RBAC), and privileged access management initiatives.
Endpoint Security: Monitor and support Endpoint Detection & Response (EDR) solutions (e.g., Microsoft Defender, CrowdStrike, SentinelOne) and assist with endpoint incident investigations and remediation.
Endpoint Hardening: Use tools such as Microsoft Intune and Group Policy to review and implement security baselines, configurations, and hardening best practices for endpoints.
Continuous Improvement: Recommend and implement improvements to security controls, policies, and detection/use cases.
Qualifications: Experience in SOC, SIEM, or MDR environments; hands-on collaboration with MDR providers; familiarity with incident response, vulnerability management tools, EDR solutions, and Microsoft Entra ID.
J-18808-Ljbffr