IT Statewide Infosec Analyst 1, 2
Job Description
The IT Statewide Infosec Analyst 1/2 will support Grambling State University’s Office of Technology Services by monitoring and responding to cyber threats across the enterprise. The role centers on centralized security event triage, incident response coordination, and hands-on technical support for systems, applications, and networks.
Key Responsibilities
- Monitor, triage, and investigate real-time security alerts generated through Palo Alto Networks Cortex XSIAM and CrowdStrike Falcon Complete platforms.
- Validate high-priority threat notifications, evaluate relevant context, and perform initial containment actions in alignment with enterprise incident response playbooks.
- Coordinate remediation workflows with the CrowdStrike Falcon Complete managed service team and applicable OTS technical verticals.
- Record investigation findings, root cause analyses, and response actions in the centralized security incident log.
- Assist with tuning detection logic, correlation rules, and automated response playbooks within Cortex XSIAM to reduce false positives.
- Monitor and manage the ServiceNow ticketing queue for proxy-related issues, access requests, and categorized URL reclassification tickets.
- Troubleshoot and resolve web filtering issues, SSL/TLS decryption exceptions, and secure web gateway (SWG) connection anomalies for enterprise users.
- Analyze user traffic patterns against acceptable use policies to identify policy violations, unauthorized application usage, or potential evasion attempts.
- Maintain operational documentation and standard operating procedures (SOPs) for enterprise proxy management and ticket workflows.
- Investigate suspicious internal and perimeter network traffic, protocol anomalies, and anomalous host behavior using network telemetry and logs.
- Conduct proactive threat hunting using threat intelligence indicators (IoCs) and behavioral analytics to identify potential adversary activity (TTPs).
- Correlate disparate log sources including firewall, DNS, VPN, authentication, and endpoint logs to reconstruct attack timelines and assess scope of impact.
- Escalate confirmed intrusions or advanced persistent threats (APTs) to senior incident response personnel and OTS leadership.
- Monitor identity provider signals and behavioral analytics for indications of compromised credentials, impossible travel, and unauthorized account modifications.
- Coordinate with the OTS Service Desk and identity teams to initiate account locks, password resets, session revocations, and MFA step-up authentication for compromised users.
- Verify post-compromise cleanup to ensure persistent access mechanisms (for example, malicious inbox forwarding rules and unauthorized OAuth applications) are identified and removed.
- Advise agency points of contact and help desk personnel on remediation best practices and credential hygiene.
- Perform other tasks, special projects, analysis, studies, and plans as directed by OTS Leadership.
Required Qualifications
- Four years of experience in information technology; or
- Six years of full-time work experience in any field plus two years of experience in information technology; or
- An associate’s degree in information technology plus two years of experience in information technology; or
- A bachelor’s degree plus two years of experience in information technology; or
- A bachelor’s degree with twenty-four semester hours in an information technology, computer science, engineering, mathematics, or business analytics field plus one year of experience in information technology; or
- A master’s degree plus one year of experience in information technology.
A certification in an approved area may be substituted for the education and/or experience requirements at the time of hire or promotion, provided the appointment is made from a Certificate of Eligibles.
Technologies
- Palo Alto Networks Cortex XSIAM
- CrowdStrike Falcon Complete
- ServiceNow
- SSL/TLS
- Secure Web Gateway (SWG)
- MFA
- OAuth
Additional Job Information
- Location: Baton Rouge, LA (onsite).
- Infosec Section. Req. 226052.
- Direction is provided by the Director of Information Security Engineering and Architecture to monitor, detect, analyze, and respond to cyber threats across the enterprise.
- Centralized security event triage, incident response coordination, and technical support are provided across computer systems, applications, and networks.
- Utilizes technical and analytical problem-resolution skills to investigate security alerts, mitigate emerging threats, and collaborate across technical support teams and state agencies.
- Appointment Type: filled by new hire or by promotion of a current permanent status classified employee.
- Career Progression: participates in a career progression group and may be filled as IT Statewide Infosec Analyst 1 or 2 from this recruitment.
- Louisiana is a “State as a Model Employer” for People with Disabilities.
How to Apply
- No Civil Service test score is required for consideration.
- Click the “Apply” link above and complete an electronic application.
- Resumes will not be accepted in lieu of completed education and experience sections on the application.
- Applicants qualifying based on college training or a baccalaureate degree must submit an official college transcript to verify credentials claimed prior to appointment.
- A criminal history check may be conducted for all new hires and employees changing positions, including promotions, demotions, details, reassignments, and transfers.
- Prospective employees may be subject to pre-employment drug testing.
- New hires will be subject to employment eligibility verification via the federal government’s E-verify system.
Contact
Erica R. Gay, HR Specialist, Division of Administration/Office of Human Resources
Email: [email protected]