CybersecurityJobs.io
← Back to all jobs

Job Description

Cobalt Benefits Group LLC is hiring an Information Security Analyst to protect information assets and technology services across cloud and on-premises environments.

Responsibilities

  • Monitor managed detection and response, endpoint, identity, email, network, cloud, and security analytics platforms for suspicious activity.
  • Triaging and investigating alerts, documenting findings, coordinating containment, remediation, recovery, and post-incident follow-up.
  • Analyze event, identity, endpoint, cloud, application, and network logs to separate security incidents from expected behavior and false positives.
  • Maintain incident response plans, investigation procedures, escalation paths, and case documentation.
  • Evaluate and strengthen security across public cloud subscriptions, storage, workloads, applications, and hybrid connectivity.
  • Administer identity and access controls, including multifactor authentication, conditional access, role-based access, privileged access, service identities, access reviews, and joiner-mover-leaver processes.
  • Support Zero Trust and secure access services for private applications.
  • Collaborate with administrators and engineers on secure access designs for cloud data platforms, application hosting, and future AI-enabled services.
  • Operate data security posture management to discover sensitive data, excessive access, shadow data, orphaned files, and insecure sharing.
  • Administer data loss prevention controls across email, endpoints, collaboration platforms, cloud services, applications, and file repositories.
  • Support data discovery, classification, information protection, retention, encryption, and remediation workflows for regulated and confidential information.
  • Administer security awareness training, phishing simulations, targeted education, completion tracking, and human-risk reporting.
  • Support endpoint detection and response, device security, mobile device management, application control, browser protection, and workstation security baselines.
  • Coordinate vulnerability and exposure management across endpoints, servers, network devices, databases, applications, and cloud workloads; prioritize remediation through patching.
  • Assess application and infrastructure changes for secure configuration, logging, access, data protection, and resilience requirements.
  • Monitor security systems such as firewalls and intrusion detection systems to detect and respond to incidents in a timely manner.
  • Collaborate on OS, application, firmware, and security patching; validate remediation and document accepted exceptions.
  • Support backup, recovery, immutable storage, business continuity, and disaster recovery security requirements.
  • Maintain policies, standards, procedures, diagrams, and inventories.
  • Improve repeatable analysis and automation using scripting, query languages, and workflow integrations.
  • Evaluate emerging security requirements for cloud, SaaS, and AI Agents.
  • Partner with business and technology stakeholders to establish AI governance, security controls, and risk management practices enabling responsible use of generative AI, AI agents, automation, and machine-to-machine services.
  • Support the AI Risk Management Framework (AI RMF) program by contributing to AI inventory management, risk assessments, control validations, policy development, monitoring activities, and governance reviews.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent relevant experience.
  • Three to five years of experience in security operations, cloud security, infrastructure security, or a comparable role.
  • Hands-on experience investigating alerts across endpoint, identity, email, network, cloud, and data security controls.
  • Experience with vulnerability assessment, remediation tracking, patch management, incident response, and security control validation.
  • Understanding of data discovery, classification, data loss prevention, sensitive-information handling, and insider-risk concepts.
  • Ability to communicate technical findings, business impact, and recommended actions to both technical and non-technical audiences.
  • Strong judgment, discretion, documentation, analytical thinking, and ability to manage multiple priorities.
  • Experience in a regulated environment; familiarity with security or compliance frameworks such as NIST, MITRE ATT&CK, SOC 2, or HITRUST.

Preferred Qualifications

  • Experience securing hybrid environments including cloud infrastructure, productivity platforms, on-premises systems, virtualized infrastructure, and SaaS applications, plus working knowledge of cloud security, identity governance, and hybrid infrastructure.
  • Familiarity with SIEM, XDR/EDR, cloud security posture management, web application protection, and security orchestration.
  • Experience scripting or performing security analytics using PowerShell, query languages, or comparable automation methods.
  • Relevant industry or cloud security certifications.

Technologies

  • Managed detection and response
  • Endpoint detection and response
  • Multifactor authentication
  • Conditional access
  • Role-based access
  • Privileged access
  • Zero Trust
  • Data security posture management
  • Data loss prevention
  • Mobile device management
  • Application control
  • Browser protection
  • Firewalls
  • Intrusion detection systems
  • AI Risk Management Framework (AI RMF)
  • NIST
  • MITRE ATT&CK
  • SOC 2
  • HITRUST
  • PowerShell
  • Query languages

Location: Manchester, NH (onsite)

Compensation: USD 90,000 - 115,000 per year

Similar Jobs