CybersecurityJobs.io
← Back to all jobs

Job Description

Support security investigations and first-line response across email, identity, endpoint, and network environments.

Responsibilities

  • Investigate security alerts spanning email security, identity, endpoint, firewall, VPN, and wireless systems
  • Perform first-line incident response, including initial scoping, evidence collection, and containment using established runbooks
  • Handle user-reported phishing via the Proofpoint reporting workflow and follow up with reporters
  • Escalate confirmed incidents with clear, documented findings
  • Contribute to detection rule and alert notification tuning so valid detections reach the right team
  • Assist with security configuration reviews and close identified gaps across email, identity, and endpoint controls
  • Maintain and extend CrowdStrike Fusion SOAR triage automation
  • Track hardening activities through completion and keep task status visible
  • Assist with firewall rule reviews, change preparation, and documentation
  • Support VPN operations and access-related tasks
  • Maintain network diagrams, inventory, and monitoring
  • Support configuration backups, health checks, and routine maintenance
  • Maintain runbooks, SOPs, and troubleshooting guides
  • Document incidents, investigations, and changes accurately for later reference and reporting
  • Use approved AI tooling to accelerate analysis, drafting, and research

Requirements

  • 2 to 4 years of hands-on experience in security operations, IT security, or a closely related role
  • Working knowledge of IP addressing, subnets, routing, and VLANs, including how firewalls and VPNs operate in an enterprise network
  • Hands-on experience investigating security alerts and reviewing logs from email, identity, endpoint, or firewall systems
  • Familiarity with SIEM and EDR concepts and the phases of incident response
  • Ability to run first-line investigation and response with limited supervision
  • Strong written communication for incident documentation and reporting
  • Ability to use AI tools such as Claude for analysis, research, and documentation

Technologies

  • Proofpoint
  • Microsoft 365
  • Entra ID
  • Okta
  • CrowdStrike Falcon
  • NG-SIEM
  • EDR
  • Fusion SOAR
  • Palo Alto firewalls
  • GlobalProtect VPN
  • Arista switches
  • Ruckus wireless
  • Zabbix
  • syslog
  • Oxidized
  • Claude
  • AI assistant

Preferred (Not Required)

  • Direct experience with Proofpoint, Okta, Microsoft 365 security, CrowdStrike, or Palo Alto Networks
  • Scripting with Python or PowerShell
  • Exposure to SOAR or other security automation
  • Linux and command-line familiarity
  • Security certifications such as Security+, CySA+, or equivalent

Growth Path

  • Senior Security Analyst
  • Security Engineer

Location: Cleveland, OH (onsite)

Minimum Experience: 2 years

Similar Jobs