Information Security Analyst II
Job Description
The Federal Home Loan Bank of Des Moines is hiring an Information Security Analyst II to support security operations in a hybrid environment from Des Moines, IA. In this role, you will help monitor and investigate cybersecurity events, strengthen detection and response workflows, and contribute to vulnerability management efforts that protect organizational systems and data.
Working within the organization’s security operations function, you will analyze alerts across multiple platforms, perform triage and investigation activities, and help coordinate containment and remediation efforts with internal technology teams. You will also assist with security administration, threat hunting, audit support, and documentation that enables effective incident response and ongoing control validation.
Location and schedule
- Location: Des Moines, IA (hybrid)
- On-call rotation: Participate in an on-call incident response rotation for after-hours support
Compensation
- Salary range: USD 81,481 - 96,758 per year
- Incentive eligibility: Eligible to participate in the Bank’s annual incentive plan
Experience level
- Minimum experience: 2 years
- Experience expectation: 2-4 years in Information Security, SOC, Cybersecurity, IT, or a related technical discipline
Responsibilities
- Monitor security alerts and events produced by SIEM, EDR, email security, cloud security, identity, network, and other security technologies
- Analyze security events to validate activity, determine impact, assess severity, and select appropriate response
- Investigate suspicious activity and triage security incidents, coordinating with internal technology teams on containment and remediation
- Escalate confirmed incidents according to established incident response procedures
- Support containment, eradication, recovery, and post-incident reviews
- Document investigations, findings, evidence, and remediation activities
- Conduct threat hunting to identify malicious or abnormal behavior
- Correlate events across multiple security platforms to detect emerging threats
- Review IOCs and IOAs to support investigations
- Monitor threat intelligence sources and recommend defensive improvements
- Identify alert trends and recommend tuning to reduce false positives
- Assist with vulnerability management by reviewing scan results, validating findings, and tracking remediation
- Maintain documentation, runbooks, and standard operating procedures; test security controls and validate operational readiness
- Partner with Infrastructure, Cloud, Networking, Application Development, Risk Management, and IT Operations to resolve security issues
- Recommend improvements to detection capabilities and operational processes; assist in developing and refining incident response playbooks
- Support security projects and implementation efforts
- Stay current on cybersecurity threats, vulnerabilities, attack techniques, and industry best practices
- Participate in incident response tabletop exercises to validate procedures, identify gaps, and improve preparedness
- Support post-incident reviews by documenting lessons learned and recommending improvements to security controls, processes, and response procedures
- Perform initial forensic data collection and validate remediation activities following security incidents
- Provide evidence for internal and external audits related to security operations
- Assist with onboarding new security tools and capabilities and perform routine administration of existing tools
Required qualifications
- 2-4 years of experience in Information Security, Security Operations Center (SOC), Cybersecurity, Information Technology, or related technical discipline
- Experience investigating security alerts and responding to cybersecurity incidents
- Experience working with enterprise security technologies
- Working knowledge of one or more: SIEM platforms, EDR/XDR, IDS/IPS, email security, Network Security Monitoring, Active Directory/Azure AD/Entra ID, Windows and Linux operating systems
- Strong analytical and problem-solving abilities
- Ability to distinguish false positives from legitimate security events
- Understanding of the Cyber Kill Chain, MITRE ATT&CK Framework, or similar threat models
- Ability to assess risk and recommend appropriate remediation
- Excellent written and verbal communication skills
- Ability to prioritize multiple investigations simultaneously
- Strong attention to detail with excellent documentation skills
- Self-motivated with the ability to work independently and collaboratively
- Curiosity, integrity, and commitment to continuous learning
Technologies
- SIEM platforms
- Endpoint Detection & Response (EDR/XDR)
- IDS/IPS
- Email Security
- Network Security Monitoring
- Active Directory
- Azure AD
- Entra ID
- Windows
- Linux
- Cyber Kill Chain
- MITRE ATT&CK Framework
Benefits
- 11 paid holidays
- 5 weeks of PTO
- Work culture that values work/life balance
- Most roles are eligible for the hybrid work schedule
- 401(k) match: 100% of the first 6% you contribute
- Additional 4% non-discretionary contribution to your 401(k) at the end of year
- Eligibility for the Bank’s annual incentive plan
Preferred qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or related field (or equivalent experience)
- Security+, CySA+, GSEC, GCIA, GCIH, CISSP (Associate), or comparable certifications
- Experience with SOAR, threat intelligence platforms, cloud security, or digital forensics