CybersecurityJobs.io
← Back to all jobs

Job Description

Kahana & Feld LLP is hiring a Cybersecurity Analyst to help protect the firm’s systems, networks, applications, and confidential information. This hybrid (or remote) role supports day-to-day security operations, strengthens security controls across key environments, and partners with infrastructure and applications teams to keep security programs current.

What you’ll do

  • Implement, operate, and document security controls in line with approved firm policies, standards, procedures, and change-management requirements.
  • Monitor security alerts, logs, dashboards, and managed security service notifications; triage events, document findings, and escalate issues using established procedures.
  • Support incident response with evidence collection, investigation, containment activities, user coordination, documentation, and remediation tracking.
  • Run or coordinate vulnerability scans, validate results, assign remediation tasks, and track corrective actions through closure.
  • Collaborate with infrastructure and applications teams to maintain security controls across endpoint, network, cloud, identity, email, web, and data-protection capabilities.
  • Assist with security tooling such as endpoint detection and response, event monitoring, email protection, multifactor authentication, mobile device management, and data loss prevention.
  • Help with user and privileged access reviews, joiner-mover-leaver controls, and investigation of unusual sign-in activity.
  • Complete client and prospective-client security questionnaires by gathering and coordinating accurate, consistent, and timely responses.
  • Maintain an organized library of approved questionnaire responses, control descriptions, supporting evidence, policies, certifications, and other due-diligence materials.
  • Track findings from audits, tests, assessments, client reviews, and incidents, and follow up with assigned owners until completion.
  • Support third-party security reviews by collecting questionnaires, reviewing documentation, recording findings, and escalating concerns.
  • Assist with phishing simulations, security awareness communications, user training, and follow-up coaching for employees who need additional guidance.
  • Maintain operating procedures, system records, incident notes, knowledge base articles, metrics, and other security documentation.
  • Stay current on relevant threats, vulnerabilities, product updates, and law-firm security concerns.
  • Perform other assigned security duties.

What you bring

  • Associate’s or Bachelor’s degree in cybersecurity, information technology, computer science, or a related field, or equivalent professional experience.
  • Minimum of 2 years of information security, cybersecurity, or security-focused IT experience supporting a law firm.
  • Hands-on experience with Microsoft 365 security and technologies such as Entra ID, Intune, Defender, Azure, or comparable platforms.
  • Working knowledge of network, identity, endpoint, and email security, including vulnerability management, patching, encryption, and backup protection.
  • Experience completing client security questionnaires, collecting audit evidence, maintaining control documentation, or supporting security and compliance reviews.
  • Familiarity with NIST Cybersecurity Framework, CIS Controls, ISO 27001, SOC 2, or comparable security requirements.
  • Ability to investigate alerts using logs, endpoint detection and response tools, event monitoring systems, vulnerability scanners, or managed security providers.
  • Strong attention to detail and documentation, with strong written communication, organization, and follow-through for multiple tasks and deadlines.
  • Sound judgment and discretion when handling confidential information.
  • Security+, SSCP, or comparable certification is preferred but not required.

Location and schedule

  • Job type: Full-Time
  • Work location: Hybrid or Remote
  • Location: Irvine, CA
  • Travel: Up to 10% domestic travel by ground and/or air, dependent on firm needs

Physical requirements

Primarily sedentary work. Exerting up to 40 pounds of force occasionally and/or negligible amount of force frequently or constantly to lift, carry, push, pull, or otherwise move objects. Repetitive motion; substantial movements of the wrists, hands, and/or fingers; close visual acuity for preparing/analyzing data, transcribing, viewing a computer terminal, and extensive reading. Office environment with ability to operate standard office equipment and keyboards. Ability to walk short distances and/or drive a vehicle to deliver and pick up materials. Work may be performed with or without accommodations.

Tools and frameworks you may use

  • Microsoft 365 security, Entra ID, Intune, Defender, Azure
  • NIST Cybersecurity Framework, CIS Controls
  • ISO 27001, SOC 2
  • Security+, SSCP

Similar Jobs