Cyber Security Analyst I
Job Description
Benefits and culture We offer a comprehensive benefits package that includes medical, dental, vision, life insurance, a 401(k), and paid time off. As part of Tuvli, an Akima company, we support Alaska’s Iñupiat communities, with a mission that touches the lives of about 15,000 shareholders. This is a environment where integrity, collaboration, and professional growth are valued as you contribute to meaningful federal security work.
The Cyber Security Analyst I will join the Security Operations Center to perform incident detection, containment, remediation, and threat hunting across Windows, Linux, and cloud environments. The role centers on hands-on response, continuous monitoring, and coordination with stakeholders to strengthen security posture.
Technologies involved include Windows, Linux, Azure, VMware, AWS, Oracle, MITRE ATT&CK, SIEM, EDR/XDR, firewalls, IDS/IPS, anti-malware, vulnerability scanners, encryption technologies, Python, PowerShell, Bash, Wireshark, Sysinternals, and SOAR.
Responsibilities
- Incident response and network forensics: triage, containment, eradication, and recovery for security incidents, including network-based forensics.
- Detection and monitoring: operate and tune SIEM, EDR/XDR, and network detection tools; create and maintain detection rules, alerts, and dashboards.
- Threat hunting and analysis: proactively hunt for threats using telemetry from endpoints, networks, cloud services, and logs; map activity to MITRE ATT&CK techniques.
- Malware analysis: perform static and dynamic analysis of suspicious binaries and scripts.
- Vulnerability management: support vulnerability scanning, prioritize findings, and coordinate remediation with engineering teams.
- Cloud and identity security: investigate incidents in Azure and VMware; analyze identity and access events; support Zero Trust and IAM controls.
- Automation and playbooks: create and maintain incident response playbooks and SOAR workflows; automate repetitive tasks with scripting (Python, PowerShell, Bash).
- Logging and telemetry: analyze logs from systems and applications.
- Collaboration and communication: coordinate with system and network administrators, developers, and external stakeholders; prepare incident reports and brief leads.
- On-call and emergency response: on-call for emergencies and respond effectively under pressure to meet critical deadlines.
Requirements
- Experience: at least five years in Windows and Linux environments with hands-on incident response or SOC experience.
- Certifications: CCNA, GCIH, GCIA, OSCP, CEH, Security+ or equivalent.
- Cloud certifications: AWS, Azure, Oracle security certifications or hands-on cloud security experience.
- Technical knowledge: strong understanding of TCP/IP, DNS, SMTP, HTTPS, and other Internet protocols.
- Security technologies: practical experience with SIEM, EDR/XDR, firewalls, IDS/IPS, anti-malware, vulnerability scanners, and encryption technologies.
- Network forensics and log analysis: ability to collect, parse, and interpret logs and artifacts from endpoints, servers, network devices, and cloud services.
- Threat and exploit knowledge: familiarity with common exploitation techniques, software vulnerabilities (for example, input validation flaws), and attacker tradecraft.
- Scripting and tools: proficiency in at least one scripting language (Python, PowerShell, Bash) and experience with forensic and analysis tools such as Wireshark and Sysinternals.
- Incident handling: familiarity with the incident response lifecycle, containment and isolation techniques, evidence collection, and chain-of-custody practices.
- Communication: excellent written and verbal communication; able to explain technical decisions clearly to technical and non-technical stakeholders.
- Soft skills: strong prioritization, organization, analytical reasoning, attention to detail, and ability to perform under stress.
- Teamwork: proven ability to collaborate in tightly coordinated teams during emergencies and mentor junior staff.
- Security mindset: high integrity and ability to handle confidential and sensitive information appropriately.