Cybersecurity Analyst
Job Description
GFR MEDIA is seeking a Cybersecurity Analyst to support the security of its systems and infrastructure through assessments, incident-focused investigations, control implementation, and compliance-aligned monitoring. This onsite role in Guaynabo, PR includes managing security tooling, responding to alerts, and partnering with IT teams to reduce risk.
Key Responsibilities
- Perform regular security assessments and penetration tests to identify weaknesses across systems and infrastructure.
- Develop, implement, and maintain security controls and measures that mitigate risk and strengthen the overall security posture.
- Detect and investigate suspicious activity associated with potential security breaches, using fast event analysis and correlation to support timely resolution.
- Conduct weekly system scans aligned with compliance expectations for PCI regulations and internal policies.
- Support adherence to additional regulatory standards, including SOC2, by following processes and maintaining required documentation.
- Manage and maintain security tools and systems settings to support optimal performance and correct configuration.
- Remove redundant servers and computers, validate authorized user access permissions for applications and systems, and implement endpoint protection policies, including handling exceptions when needed.
- Assist in the creation of tailored training modules and simulated attacks using customizable templates to increase employee awareness of cybersecurity threats.
- Support ongoing updates to ensure users are informed of cybersecurity protocols, including onboarding changes for new personnel.
- Respond to alerts via email, Help Desk ticketing, and other employee notifications; prioritize actions based on alert criticality.
- Facilitate information sharing between security analysts and other IT departments.
- When a newly discovered vulnerability affects a product managed by another team, share relevant details promptly and recommend viable alternatives to address the issue.
- Verify scheduled tasks and updates complete successfully, coordinating with Infrastructure personnel to avoid operational disruption.
- Collaborate with cross-functional teams to implement security best practices and help maintain compliance with applicable standards.
- Stay current on cybersecurity trends, threats, and technologies to continuously improve security practices.
- Comply with company standards, policies, procedures, and applicable local and federal laws related to industry, business, and employment practices.
- Perform other duties and responsibilities as assigned, consistent with the stated education and experience requirements.
Required Qualifications
- Bachelor’s degree in Computer Science, Information Technology, or a related field.
- 2+ years of experience in information technology roles.
- Proven experience in cybersecurity analysis, incident response, and risk management.
- Strong knowledge of networking protocols and security technologies.
- Highly knowledgeable about computers, including networks, operating systems, applications, and web apps.
- Experience with security tools such as SIEM, IDS/IPS, firewalls, and vulnerability scanners.
- Excellent analytical, problem-solving, and communication skills.
- Ability to work independently and collaboratively.
- Strong multitasking ability and capacity to manage multiple projects.
- Proven ability to prioritize and handle multiple tasks simultaneously with strong attention to detail.
- Proven organizational skills in fast-paced, high-volume environments.
- Ability to identify solutions independently and make sound business decisions.
- Experience using Microsoft Office (MS Word, Excel, Outlook).
- Bilingual capabilities (writing, conversational, and reading comprehension) in English and Spanish.
Technologies
- SIEM
- IDS/IPS
- firewalls
- vulnerability scanners
- Microsoft Office (MS Word, Excel, Outlook)
Preferred Certifications and Affiliations
- Certifications such as CompTIA Security+, CEH (Certified Ethical Hacker), CISSP, CISM, or GIAC.
- Membership in recognized cybersecurity professional organizations (e.g., ISACA, (ISC)²).
Compensation
USD 45,000 - 55,000 per year
Benefits
- 401(k)
- 401(k) matching
- Employee assistance program
- Health insurance
- Life insurance
- Paid time off
- Retirement plan
Working Conditions
- Moderate noise level in the work environment.
- Indoor office work using a computer, copier, and other modern office equipment.
- Ability to work in a fast-paced environment with flexible hours, including evenings or weekends, to respond to security incidents, perform system maintenance, or support cross-functional cybersecurity initiatives.
- Occasional offsite visits may be required as requested by the organization.
Physical Requirements
- Ability to sit for extended periods while working on a computer and managing cybersecurity projects and incidents.
- Regular use of hands and fingers for typing, digital navigation, and handling office equipment.
- Occasional lifting and carrying of equipment such as laptops, servers, or security hardware, typically up to 25 pounds.
- Strong visual and auditory skills for monitoring alerts, analyzing logs, and assessing potential threats.
Work Location
In person
Guaynabo, PR (onsite)