Associate Cybersecurity Analyst
Job Description
Iron Bow Technologies is seeking a Handler on Duty to support cybersecurity operations through front-line monitoring, alert analysis, incident triage, and response activities. This is a swing shift role focused on incident investigation and customer communications as security events are validated and brought to resolution.
Location and Schedule
- Location: United States (onsite)
- Shift: Sunday–Wednesday, 12pm–10pm PST
Compensation
- Pay rate: USD 24–27 per hour
Role Responsibilities
- Monitor and respond to cybersecurity alerts and potential security incidents.
- Participate in Computer Network Defense (CND) and support cybersecurity incident response investigations.
- Collect, track, and document security incidents from initial detection through final resolution.
- Analyze security logs and data from multiple sources, including host logs, proxy logs, network traffic, firewalls, and intrusion detection systems (IDS).
- Triaging incidents to determine scope, urgency, potential impact, and associated vulnerabilities.
- Identify potential threats and recommend actions to support timely containment and remediation.
- Support real-time incident handling activities, including intrusion correlation and tracking, threat analysis, and system remediation.
- Assist deployable Incident Response Teams (IRTs) during security investigations and response activities.
- Receive and analyze security alerts from multiple sources to help determine root cause.
- Communicate with customers to validate and investigate potentially anomalous activity.
- Respond to customer requests and provide timely updates regarding security incidents and activities.
- Accurately document investigative actions, findings, and incident resolution.
- Preserve evidence integrity in accordance with established procedures and applicable standards.
- Perform additional duties as assigned.
Minimum Requirements
- Experience: 2–4 years of general IT, cybersecurity, networking, or related technical experience
- Foundational understanding of cybersecurity operations and incident response concepts.
- Knowledge of TCP/IP, DHCP, DNS, and how core networking technologies support network communications.
- Understanding of cybersecurity policies, procedures, and incident handling methodologies.
- Knowledge of common cyberattack types, stages, threats, and vulnerabilities.
- Familiarity with intrusion detection concepts and host- and network-based intrusion detection technologies.
- Understanding of security event correlation and the use of security logs to investigate suspicious activity.
- Knowledge of common system and application security threats and vulnerabilities, including malicious code, injection attacks, cross-site scripting, privilege escalation, and other common attack techniques.
- Understanding of network security architecture, protocols, components, and defense-in-depth principles.
- Familiarity with packet analysis and network traffic analysis.
- Basic knowledge of malware concepts and methods used to protect networks from malicious activity.
- Understanding of basic system administration, operating system security, and network hardening techniques.
- Familiarity with evidence preservation, damage assessment, and incident documentation practices.
- Basic understanding of data backup and recovery concepts.
- Strong written and verbal communication skills.
- Strong interpersonal skills with the ability to communicate effectively with customers and technical teams.
- Ability to follow established procedures and instructions while exercising sound judgment.
- Ability to work effectively both independently and as part of a team.
Skills That Drive Success
- 2–4 years of general IT, cybersecurity, networking, or related technical experience.
- Foundational understanding of cybersecurity operations and incident response concepts.
- Knowledge of TCP/IP, DHCP, DNS, and how core networking technologies support network communications.
- Understanding of cybersecurity policies, procedures, and incident handling methodologies.
- Knowledge of common cyberattack types, stages, threats, and vulnerabilities.
- Familiarity with intrusion detection concepts and host- and network-based intrusion detection technologies.
- Understanding of security event correlation and the use of security logs to investigate suspicious activity.
- Knowledge of common system and application security threats and vulnerabilities, including malicious code, injection attacks, cross-site scripting, privilege escalation, and other common attack techniques.
- Understanding of network security architecture, protocols, components, and defense-in-depth principles.
- Familiarity with packet analysis and network traffic analysis.
- Basic knowledge of malware concepts and methods used to protect networks from malicious activity.
- Understanding of basic system administration, operating system security, and network hardening techniques.
- Familiarity with evidence preservation, damage assessment, and incident documentation practices.
- Basic understanding of data backup and recovery concepts.
- Strong written and verbal communication skills.
- Strong interpersonal skills with the ability to communicate effectively with customers and technical teams.
- Ability to follow established procedures and instructions while exercising sound judgment.
- Ability to work effectively both independently and as part of a team.
What Sets You Apart
- CompTIA Security+, Network+, A+, or other relevant industry certification.
- Previous exposure to a Security Operations Center (SOC), Network Operations Center (NOC), help desk, cybersecurity, or incident response environment.
- Hands-on experience reviewing security alerts, logs, or network traffic.
- Familiarity with SIEM, intrusion detection/prevention, endpoint security, or other cybersecurity monitoring tools.
- Experience with packet-analysis tools and network traffic investigation.
- Knowledge of malware analysis concepts and methodologies.
- Familiarity with Federal Government cybersecurity requirements, CND operations, or other highly regulated environments.
- Strong interest in developing a career in cybersecurity operations, threat analysis, or incident response.