What are the responsibilities and job description for the Entry level Security Analyst-W2 Only position at Information Resource Group, Inc.?
Job Details
Role: Entry level Security Analyst-W2 Only
Location: Blythewood, SC
Duration: One Year Contract with possibility of extensions
Hours/week: 37.50
Daily duties / responsibilities:
The agency security team is looking for candidates to fill two entry level security positions. The agency will train the selected candidates to perform the tasks listed below. At a minimum we are looking for basic server or network administration skills that we can build upon.
1. Threat Intelligence Research
- Monitor and analyze threat intelligence feeds to identify emerging threats relevant to the organization.
- Document findings, such as new attack methods or vulnerabilities, and share with the team.
- Use open-source intelligence (OSINT) tools to gather data on potential risks and adversaries.
2. Threat Hunting and Detection Rule Creation
- Conduct proactive searches for suspicious behavior in network and endpoint activity using provided tools and playbooks.
- Collaborate with senior analysts to refine and test detection rules (e.g., SIEM queries or Defender for Endpoint rules).
- Document hunting methodologies and findings to support continuous improvement.
3. Log Analysis
- Review and interpret logs from firewalls, endpoints, and servers to identify indicators of compromise (IOCs).
- Escalate findings, such as anomalous IP addresses or unauthorized access attempts, to senior analysts.
- Maintain a log of recurring patterns or anomalies for long-term tracking and analysis.
4. Incident Response
- Assist in initial triage of security incidents by following response frameworks (e.g., NIST, MITRE ATT&CK).
- Gather and analyze relevant evidence, such as logs or alert data, to determine the scope and severity of incidents.
- Document findings during incidents and contribute to containment and remediation efforts.
5. Documentation and Reporting
- Create clear, detailed reports, including incident reports, after-action reviews, and process documentation.
- Draft training materials or guides to help improve organizational awareness and readiness.
- Regularly update and organize documentation to ensure accuracy and accessibility for team use.
Required skills:
- Problem-solving: analyze data, identify anomalies, and recommend solutions.
- Attention to detail: ensure accurate analysis and configuration for effective security measures.
Preferred skills:
- Vulnerability management: analyze reports, prioritize patching, understand nist best practices.
- Threat hunting & intelligence: utilize threat feeds, investigate suspicious activity, stay current on cyber threats.
- Security awareness training: develop & deliver training, assess employee awareness through simulations.
- Security automation: leverage SCCM, GPO, and POWERSHELL for patch deployment.
- Endpoint security (defender for endpoint): configure policies, analyze alerts, manage endpoint protection.
- Incident response: identify and escalate potential security threats.
- Communication: deliver reports on security posture and propose mitigation strategies.
- Scripting: automate tasks beyond SCCM, GPO, and powershell for increased efficiency.
- Digital forensics: investigate security incidents and collect evidence for deeper analysis.
- Network security: understand network protocols and firewalls to strengthen overall security posture.
- Cloud security: as cloud adoption grows, understanding cloud-specific security solutions becomes valuable.
Required education and experience: A high school diploma is required, a bachelor's degree in information technology systems, computer science, cybersecurity, or a related field is preferred. At least 1 year server or network administration experience is required. 1 years of experience in a security focused role is preferred. Relevant experience may be substituted for the degree on a year-for-year basis.
CERTIFICATIONS: Not required, however we prioritize applicants who have:
- GIAC Security Essentials (GSEC)
- Security (CompTIA)
- Network (CompTIA)
- GIAC Incident Handler (GCIH)