KEY RESPONSIBILITIES:
- Monitor, analyze, investigate, and report on security events, alerts, vulnerabilities, and risks across the organization’s information systems.
- Independently perform incident response activities including triage, containment, eradication, recovery, root cause analysis, and post-incident reporting.
- Conduct advanced threat hunting activities to identify malicious activity, security gaps, and emerging threats.
- Perform vulnerability management activities including scanning, risk analysis, remediation planning, validation, and executive reporting.
- Develop and maintain security use cases, alerting logic, dashboards, correlation rules, and reporting within security monitoring platforms.
- Perform security reviews of infrastructure, cloud services, applications, and business systems to identify security risks and recommend corrective actions.
- Partner with IT teams to implement security controls, hardening standards, and remediation activities.
- Lead vendor security assessments and third-party risk evaluations.
- Assist with security governance initiatives including policy development, standards maintenance, risk assessments, and compliance activities.
- Evaluate emerging threats, vulnerabilities, and industry trends and recommend improvements to strengthen the organization's security posture.
- Participate in internal and external audits by gathering evidence, documenting controls, and validating security requirements.
- Develop security metrics, dashboards, and reporting for leadership.
- Lead security awareness and education initiatives throughout the organization.
- Assist in developing and maintaining incident response plans, playbooks, security procedures, and technical standards.
- Recommend and implement process improvements that enhance operational efficiency and reduce organizational risk.
- Participate in after-hours incident response as required.
- Perform other duties as assigned.
EDUCATION, TRAINING, AND EXPERIENCE:
Required
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Technology, or related field, or equivalent combination of education and experience.
- 3+ years of experience in information security, cybersecurity operations, security engineering, security administration, or related technical roles.
- Strong understanding of security frameworks, risk management methodologies, and cybersecurity best practices.
- Experience investigating cybersecurity incidents and conducting security event analysis.
- Experience with vulnerability management programs and remediation coordination.
- Experience supporting enterprise security technologies including SIEM, endpoint protection, email security, identity security, and network security controls.
- Working knowledge of cloud security concepts, Microsoft 365 security controls, identity and access management, and security monitoring practices.
- Experience documenting risks, findings, recommendations, and technical procedures.
Preferred
- One or more industry certifications such as:
- Security+
- GSEC
- SSCP
- CySA+
- CISM
- CISSP
- CISA
- GIAC certifications
- Experience with:
- Microsoft Sentinel
- Microsoft Defender suite
- Vulnerability management platforms
- Privileged Access Management (PAM)
- Security automation and orchestration solutions
- Cloud security platforms
- Threat intelligence platforms
- Familiarity with:
- NIST Cybersecurity Framework (CSF)
- CIS Controls
- ISO 27001
- PCI-DSS
- CPNI
- SOC 2
- Experience conducting security assessments and risk reviews.
- Experience leading security projects and initiatives.
CAPABILITIES AND SKILLS:
- Strong analytical, investigative, and critical-thinking skills.
- Advanced ability to troubleshoot and analyze complex security issues.
- Ability to independently prioritize and manage multiple security initiatives.
- Strong written and verbal communication skills with both technical and non-technical audiences.
- Excellent presentation and documentation abilities.
- Ability to influence security decisions through education, collaboration, and risk-based recommendations.
- Strong organizational and project management skills.
- Ability to maintain confidentiality and handle sensitive information with discretion.
- Demonstrated leadership and mentoring skills.
- Commitment to continuous improvement and professional development.
WORKING CONDITIONS AND PHYSICAL REQUIREMENTS:
- Primarily indoor work in an office environment requiring extended periods of sitting.
- Frequent use of computer systems, security monitoring tools, and technical documentation.
- Occasional lifting of equipment up to 50 pounds.
- May require evening, weekend, or holiday work during security incidents or maintenance activities.
- Occasional travel may be required.
- Ability to respond to critical cybersecurity incidents outside normal business hours.
