Support day-to-day security operations, including incident investigation, penetration testing, and vulnerability mitigation. Collaborate with project and helpdesk teams to resolve security violations and report residual risks to the Risk Manager.
Information Security Analyst, I (FT Weekends, Remote)
Department: Security Incident Response
Employment Type: Full Time
Location: Remote
Description
The Information Security Analyst I will support day-to-day security operations, event/incident investigation, security control assessment, data analysis and reporting, and other infosec-related activities. The analyst will work with the Project team as well as Helpdesk Support team to mitigate risks and vulnerabilities and create documentation or reports regarding infosec activity and incidents.
While working from home, employees must have a reliable internet connection and must work in an environment free of noise and distraction.
Compensation Disclaimer: The pay range listed for this position is based on market data across various U.S. locations and reflects the company’s good faith estimate of what it reasonably expects to pay. Actual compensation may vary depending on geographic location, relevant experience, and other job-related factors. This range also accounts for potential growth and progression within the role. Final compensation will be determined after a successful interview process and may be discussed in more detail during later stages.
Essential Duties and Responsibilities
Perform penetration testing; along with internal and external scanning, assess report and escalate to appropriate team and engineers.
Resolve any computers with missing Hard Drive Encryption
Resolve and report out any violations of Office365 hardening security procedures; this includes but not limited to bypassing multi-factor authentication, device compliance policy, conditional access.
Resolve any computers and servers with missing vulnerability patch and Windows and third-party updates.
Responds to security incidents (Helpdesk Support), conducts forensic investigations and targets reviews of suspect areas as well as develop action plans to address root causes of security-related problems.
Collaborates on projects to ensure that security issues are addressed throughout the project life cycle.
Reports to Risk Manager concerning residual risk, vulnerabilities and other security exposures, including misuse of information assets and noncompliance.
Provides responsive support for problems found during normal working hours as well as outside normal working hours as needed.
Competencies, Skills, and Qualifications
1-2+ years of security experience working with Endpoint Security, Intrusion Prevention, and Firewall security
2+ years of experience working for an MSP/MSSP or SOC (Security Operations Center)
2+ years of Incident Response experience
Proven work experience as a system security engineer or information security engineer
Experience in building and maintaining security systems
Detailed technical knowledge of database and operating system security
Hands on experience in security systems, including firewalls, intrusion detection systems, anti-virus software, authentication systems, log management, content filtering, etc.
Experience with network security and networking technologies and with system, security, and network monitoring tools
Thorough understanding of the latest security principles, techniques, and protocols
Problem solving skills and ability to work under pressure
Development Expectations
Ethical Hacker - Preferred / Development Plan
Associate of (ISC)² - Preferred / Development Plan
CISSP (Certified Information Systems Security Professional) – Preferred / Development Plan
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”