IT Security Analyst
Job Description
NAKA Tech is looking for an IT Security Analyst to support hands-on security operations in a New York, NY onsite environment. This role centers on SIEM/SOC operations, monitoring and responding to cyber threats, and strengthening incident response through automation, threat intelligence integration, and continuous testing.
The position will help maintain the organization’s security monitoring capabilities across endpoints and networks, while supporting investigations, triage, and remediation planning. You will also contribute to the ongoing evolution of security controls, baselining of activity, and enforcement of security policies and procedures.
Key responsibilities
- Implement, administer, and support endpoint security software.
- Investigate security events such as unauthorized access, policy non-compliance, fraud, and service exploitation to identify malfunctions, breaches, and remediation steps.
- Respond to daily service issues, problems, and critical situations to support resolution and minimize downtime.
- Administer and operate SIEM technologies, including rule creation, reporting, correlation, and performance monitoring.
- Execute automation playbooks to support automated incident response investigations.
- Leverage threat intelligence sources and partners to stay current on emerging threats and advanced threat actor capabilities.
- Integrate threat intelligence feeds and sources with the organization’s security monitoring infrastructure.
- Use the Continuous Testing framework to identify, design, and deploy tests for security monitoring controls.
- Identify and implement tools to baseline activity and help alert or limit suspicious activity, including insider threat across networks, databases, data, and users.
- Assist in selecting, implementing, and managing systems, tools, and processes that keep the firm at the leading edge of security, including tracking gaps to be mitigated and shaping proactive evaluation and implementation strategies.
- Stay current on emerging security threats and technologies.
- Support development and implementation of security policies and procedures, including user log-on and authentication rules, security breach escalation procedures, security auditing procedures, and use of firewalls and encryption routines.
- Enforce security policies by administering and monitoring security profiles, reviewing security violation reports, investigating security exceptions, and updating, maintaining, and documenting security controls.
- Prepare status reports on security matters to support security risk analysis scenarios and response procedures.
- Perform other duties as assigned.
Required qualifications
- Bachelor’s Degree and/or 3 years work experience in a relevant role (for example: SOC Analyst, Incident Response, Cybersecurity Threat Analyst).
- B.S. in Computer Science or Engineering (or a similar technical program) or equivalent experience.
- At least one active security certification: CEH, OSCP, CPTE, CISM, CISSP, or related.
- Experience with event analysis using SIEM tools; log parsing and analysis; and developing or refining correlation rules.
- Hands-on experience deploying and operating security technologies across devices, networks, and systems that prevent, detect, and respond to threats.
- Strong understanding of security operations concepts such as perimeter defense, BYOD management, data loss protection, insider threat, kill-chain analysis, risk assessment, and security metrics.
- Strong understanding of network protocols.
- Development and scripting experience with Python and/or PowerShell.
- Knowledge of protocol analysis tools such as Wireshark, Gigastor, and Netwitness (examples listed).
- Working knowledge of the current cyber threat landscape (for example: threat actors, APT, cyber-crime).
- Working knowledge of Windows and Unix/Linux, including firewall and proxy technology.
- Knowledge of malware operation and indicators, DLP monitoring, forensic techniques, penetration techniques, and DDoS mitigation techniques.
- Ability to self-organize, prioritize independently, and produce documentation and reports.
- Ability to manage uncertainty using good enough but imperfect or incomplete information.
- Strong oral and written communication skills, including the ability to explain technical concepts to non-technical individuals.
- 3-5+ years in a hands-on technical information security role supporting a large organization.
- Knowledge of security frameworks, principles, and relevant technologies and vendors.
Compensation and location
- Location: New York, NY (onsite)
- Salary: USD 125,000 - 150,000 per year
Relevant technologies
- SIEM, endpoint security software, SIEM technologies
- Firewalls, proxies, network and host-based intrusion prevention, DLP
- Python, PowerShell
- Wireshark, Gigastor, Netwitness
- Windows, Unix/Linux
- Continuous Testing framework
- SIEM and SOC, security automation playbooks, threat intelligence feeds
- Security testing and assessment concepts listed include intrusion detection/prevention and third-party security assessment
Similar Jobs
S