Cybersecurity Analyst
Job Description
The Cybersecurity Analyst will monitor and respond to security incidents and threats, support security risk activities, and help strengthen organizational security controls and policies in a hybrid work setting based in Tempe, Arizona.
Key Responsibilities
- Analyze security alerts and incidents to determine root cause, scope, and potential impact; contain, mitigate, and remediate identified threats as appropriate.
- Administer the security awareness program, including phishing simulations, employee training, and investigation of reported phishing threats.
- Participate in security assessments and penetration testing; document vulnerabilities and assist with remediation efforts.
- Maintain and update the Risk Register and POA&M by tracking risks, remediation activities, and status updates within the organization’s risk management program.
- Develop and implement security controls and countermeasures to reduce identified risks.
- Support vulnerability management by identifying, prioritizing, tracking, and reporting vulnerabilities and remediation activities aligned with established mean time to remediate (MTTR) standards.
- Assist with third-party risk management, including vendor onboarding assessments and periodic risk reviews.
- Support the development, review, and maintenance of cybersecurity policies and procedures aligned with NIST and other applicable security standards and regulatory requirements.
- Participate in the evaluation and deployment of new security technologies and solutions.
- Maintain ongoing research and continuous learning to stay current on emerging cyber threats, vulnerabilities, and security technologies.
- Perform other duties as assigned.
Required Qualifications
- 2-5 years of experience in the field.
- Bachelor’s Degree in IT/Security or a related field.
- Experience using security technologies and tools including SIEM, IDS/IPS, DLP (Data Loss Prevention), Vulnerability Management, and EDR (Endpoint Detection and Response).
- Experience participating in security assessments and penetration testing.
- Proficiency in incident response processes and tools.
- Basic understanding of security compliance frameworks (e.g., NIST 800-53, ISO 27001) and regulatory requirements (e.g., HIPAA, SOC2, StateRAMP, HITRUST).
- Ability to collaborate with team members and communicate effectively with both technical and non-technical stakeholders, including presentation skills.
- Ability to multitask and prioritize workload.
- Ability to act professionally and maintain appropriate boundaries with clients and staff.
- Ability to report on schedule to work, meetings, training, and job-related activities prepared as scheduled.
- Consistently demonstrate compassion and meet people with compassion, maintain an ownership mindset that supports company success, and practice an open and accepting mindset through active learning and self-reflection.
Technologies and Security Tools
- SIEM, IDS/IPS, DLP (Data Loss Prevention), Vulnerability Management, EDR (Endpoint Detection and Response)
- MTTR
- NIST 800-53, ISO 27001
- HIPAA, SOC2, StateRAMP, HITRUST
- CompTIA Security+, Microsoft Security Operations Analyst, Microsoft Azure Security Engineer, ISC2, GSEC, CySA+
Location and Work Style
Tempe, AZ with a hybrid schedule.
Compensation
USD 75,000 - 88,250 per year.
Benefits
- Friendly work environment
- Generous paid time off (PTO)
- Health benefits (Medical/Dental/Vision) start the first of the month following the hire date
- Competitive compensation
- Convenient office locations and Hybrid Schedule
- On-site fitness room free to all employees (Tempe Office)
- Basic Life Insurance
- Voluntary Life, Spouse, Child Insurance
- Critical Illness with free dependents; Critical Illness spouse coverage
- Short Term & Long Term Disability, with start on the first of the month after 90 days of employment
- 401K & 401K Roth, starting on the first of the month after 90 days of employment
- United Pet Care
- LifeLock for identity theft
- LYRA EAP Program with 25 free mental health sessions per family member
Working Conditions
- While performing job duties in the office or home office, the employee is frequently required to stand, walk, sit, and use hands; occasionally lift and/or move up to 25 pounds.
- Specific vision abilities required include close vision, distance vision, color vision, peripheral vision, depth perception, and the ability to adjust focus.
- Exposure to noise typical with office operations.
- Ability to hear and speak.
- Employees must maintain stable and secure private home internet with a minimum of 50Mbps download and 5Mbps upload, and an average jitter less than 20% of latency (https://speed.cloudflare.com/).