The Cybersecurity Analyst is responsible for frontline security monitoring, incident response support, and maintaining compliance evidence. They will triage security alerts, manage exposure tracking, and support the engineering team in operational security processes.
Role Overview
The Cybersecurity Analyst is a hands-on operational role within the Cyber Operations team, responsible for frontline security monitoring, incident response support, exposure management validation, and compliance evidence. Working under the direction of the Director, Cyber Operations and senior engineers, the Analyst is the execution layer of KLDiscovery's security program monitoring what matters, responding when it counts, and keeping the team's operational processes running reliably. This is a remote opportunity with a clear growth path toward Sr. Cybersecurity Analyst.
Key Responsibilities
Security Monitoring & Alert Triage
Serve as first-line eyes on the environment validating and escalating CrowdStrike MDR-confirmed findings, reviewing MDR outputs, assessing context, and ensuring accurate internal escalation to the Engineers and Director
Monitor security alerts from tools operating outside MDR scope Triage alerts for AI tool misuse, anomalous AI-related activity, and other emerging threat patterns as directed by the Security Manager
Flag SIEM and identity health monitoring gaps, anomalies, and coverage issues to the engineering team — you are the first to notice when something looks wrong or missing
Incident Response Support
Serve as first-line support during security incidents like gathering evidence, documenting timelines, executing containment steps, and supporting the Security Manager through the full incident lifecycle
Conduct initial technical investigations to identify root cause of intrusions, anomalies, or policy violations
Maintain incident records, post-incident documentation, and lessons-learned notes to a standard that supports compliance evidence and future response improvement
Participate in on-call rotation to ensure coverage outside core business hours for escalated MDR findings or active incidents
Vulnerability & Exposure Management Support
Monitor the CrowdStrike Falcon Exposure Management dashboard tracking open findings, flagging severity changes, and keeping remediation status records current to support the engineer who owns the program
Follow up on patch deployment failures identifying affected systems and coordinating with IT on remediation timelines as directed by the engineering team
Support third-party penetration test logistics, internal scheduling communication, evidence gathering, and remediation ticket tracking under the direction of the engineer coordinating the engagement
Maintain accurate and current exposure tracking records so the engineering team always has clean data for prioritization decisions and compliance reporting
Compliance & Audit Support
Gather and maintain technical evidence for compliance frameworks and internal audits
Support internal audit and pre-assessment readiness reviews, organizing evidence packages and ensuring documentation is audit-ready at all times, not reconstructed at assessment time
Assist the GRC team with technical control evidence, gap tracking, and remediation documentation
Maintain documentation that supports annual security compliance attestations relevant to assigned business units
Qualifications
Experience
2+ years of hands-on experience in a security operation, IT, or closely related technical role
Practical experience with security monitoring, alert triage, or incident response in a corporate environment
Familiarity with MDR platforms (CrowdStrike Falcon Complete or equivalent) is a strong plus
Working knowledge of common security tools or ticketing systems(Remedy or equivalent)
Technical Knowledge
Understanding of core security domains sufficient to execute assigned tasks independently: access management, encryption, network security, vulnerability management, and incident response
Basic familiarity with cloud security concepts (AWS, Azure, or GCP) including IAM, logging, and posture monitoring
Foundational understanding of AppSec concepts is a meaningful differentiator: SAST/DAST tooling, secure SDLC, and pipeline security
Experience with AI security considerations (AI tool access governance, prompt injection awareness) is a plus
General Abilities
A strong sense of ownership, when you take on a task, it gets done; you follow through without being chased, flag blockers early, and close the loop reliably
Alert and attentive, you notice things others miss, take monitoring seriously, and understand that complacency in security operations has real consequences
Detail-oriented with high standards for accuracy and documentation, evidence, and escalation decisions require precision and you take that seriously
A strong communicator, able to summarize security findings clearly, escalate appropriately without overclaiming, and write incident notes that are useful to the people who read them
A collaborative team member, you work well within a team structure, take direction from senior staff, and contribute without needing to be the loudest voice in the room
Growth-oriented, you actively invest in your own development, stay current on the threat landscape, and approach each incident as a learning opportunity
Discreet and trusted, you handle sensitive incident data, client information, and security findings with appropriate confidentiality and professionalism
Education & Certifications
Formal education in Information Security, Computer Science, IT, or a related field is a plus but not required — we care more about what you can do than where you studied
Relevant certifications such as GSEC or CISSP are valued but not a prerequisite. If you don't have one yet, we'll support you in getting there
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”