Security Analyst II
Job Description
Support security investigations and first-line response across email, identity, endpoint, and network environments.
Responsibilities
- Investigate security alerts spanning email security, identity, endpoint, firewall, VPN, and wireless systems
- Perform first-line incident response, including initial scoping, evidence collection, and containment using established runbooks
- Handle user-reported phishing via the Proofpoint reporting workflow and follow up with reporters
- Escalate confirmed incidents with clear, documented findings
- Contribute to detection rule and alert notification tuning so valid detections reach the right team
- Assist with security configuration reviews and close identified gaps across email, identity, and endpoint controls
- Maintain and extend CrowdStrike Fusion SOAR triage automation
- Track hardening activities through completion and keep task status visible
- Assist with firewall rule reviews, change preparation, and documentation
- Support VPN operations and access-related tasks
- Maintain network diagrams, inventory, and monitoring
- Support configuration backups, health checks, and routine maintenance
- Maintain runbooks, SOPs, and troubleshooting guides
- Document incidents, investigations, and changes accurately for later reference and reporting
- Use approved AI tooling to accelerate analysis, drafting, and research
Requirements
- 2 to 4 years of hands-on experience in security operations, IT security, or a closely related role
- Working knowledge of IP addressing, subnets, routing, and VLANs, including how firewalls and VPNs operate in an enterprise network
- Hands-on experience investigating security alerts and reviewing logs from email, identity, endpoint, or firewall systems
- Familiarity with SIEM and EDR concepts and the phases of incident response
- Ability to run first-line investigation and response with limited supervision
- Strong written communication for incident documentation and reporting
- Ability to use AI tools such as Claude for analysis, research, and documentation
Technologies
- Proofpoint
- Microsoft 365
- Entra ID
- Okta
- CrowdStrike Falcon
- NG-SIEM
- EDR
- Fusion SOAR
- Palo Alto firewalls
- GlobalProtect VPN
- Arista switches
- Ruckus wireless
- Zabbix
- syslog
- Oxidized
- Claude
- AI assistant
Preferred (Not Required)
- Direct experience with Proofpoint, Okta, Microsoft 365 security, CrowdStrike, or Palo Alto Networks
- Scripting with Python or PowerShell
- Exposure to SOAR or other security automation
- Linux and command-line familiarity
- Security certifications such as Security+, CySA+, or equivalent
Growth Path
- Senior Security Analyst
- Security Engineer
Location: Cleveland, OH (onsite)
Minimum Experience: 2 years