Cyber Security Analyst

Holland & Hart LLP•Boulder, CO
•$80,919 - $134,866•Hybrid

About The Position

The Cyber Security Analyst will be responsible for identifying and documenting security and privacy risks, and assisting with the implementation of controls to mitigate these risks. This role involves interfacing with vendors, developing and maintaining security policies, administering security devices, and evaluating suspicious threats using various security tools. The analyst will also be involved in security awareness campaigns, generating performance metrics, and conducting vulnerability assessments. Additionally, the position requires participation in client audits, risk assessments, and providing recommendations for security controls and access management.

Requirements

  • Bachelor’s degree in information technology, information systems, computer science or computer engineering.
  • Three (3) years of cyber security experience.
  • Minimum of one security technical certification such as SSCP, GSEC, CEH and Security+.
  • Direct experience in vulnerability management and how to manage risk using the MITRE Attack Framework including threat intelligence sources.
  • Direct experience maintaining and performing analysis using Security Event and Incident Management (SEIM) systems.
  • Direct experience in digital forensics, reverse malware analysis and incident response.
  • Direct experience analyzing events using EDR/XDR and anti-malware systems.
  • Direct experience performing phishing and social engineering testing.
  • Direct experience with Active Directory and Auditing Systems.
  • Direct experience reviewing firewall rules and configuration.
  • Direct experience with Cloud Security Architecture.
  • Understands IT security frameworks (NIST 800 series and ISO 27001), compensating controls and how to work with members of IT to implement the corresponding controls.
  • Understands how to quantify vendor risk.
  • Understands and may analyze contractual agreements, privacy policies, and other third-party documentation.
  • Aptitude and a mindset for security.
  • Self-learner with an ability to research new security trends.
  • Advanced understanding of how computers work and how they may be exploited.
  • Understanding of IT Security best practice industry standards and how they are applied.
  • Capable of performing one or more phases of low-complexity projects.
  • Can forecast budget for low-complexity projects.
  • Excellent Microsoft Office skills including Visio.
  • Ability to write scripts and generate reporting from security systems.
  • Strong adherence to integrity & confidentiality.
  • Must be collaborative, creative, and driven with a proven ability to be a team player.
  • Able to think strategically, develop solutions quickly and implement efficiently.
  • Excellent verbal, written, and overall communication skills.
  • Excellent analytical skills.
  • Detail oriented to ensure that the success of implementations is paramount.
  • Strong analytical, evaluative, and problem-solving skills with a keen attention to detail.
  • Self-starter with the ability to multi-task and work in a very fast paced environment.
  • Exceptional client service demeanor and interpersonal skills required.
  • Must effectively prioritize work/projects and execute tasks in a high-pressure environment.

Nice To Haves

  • Experience maintaining physical security systems and IoT systems is preferred.

Responsibilities

  • Identify and document security and privacy risks, and assist with control implementation.
  • Interface with MSS and EPP vendors regarding technical settings, perform analysis of alerts, and remediate threats.
  • Assist with developing and maintaining information and privacy security policies, procedures, standards, and guidelines.
  • Install and administer security protection devices including end point protection (EPP) and SIEM technology.
  • Evaluate suspicious threats and activities in email and systems, using Endpoint Detection and Response (EDR) tools.
  • Utilize malware analysis and sandboxing tools to analyze suspicious events.
  • Leverage security tools to analyze suspicious links, email and documents.
  • Implement remediation controls to block suspicious email and other threats.
  • Evaluate and analyze events using Security Event and Incident Management (SEIM) tools, and develop reporting.
  • Assist in developing and implementing Security Awareness and Phishing Awareness campaigns, and recommend additional controls.
  • Assist in generating metrics and Key Performance Indicators (KPIs) to improve security decision making.
  • Review and evaluate desktop, server, and other device configurations against CIS standards and work with administrators to harden systems.
  • Inform others within IT Security and IT Management regarding security issues.
  • Assist with routine penetration testing and vulnerability assessments against applications, systems, and networks.
  • Perform vulnerability testing of wireless infrastructure and integrate threat intelligence sources with vulnerability management processes.
  • Conduct third party risk assessments and audits.
  • Evaluate and propose controls for AI systems.
  • Identify methods to document and track third-party risk and get third party commitment to implement risk controls.
  • Conduct privacy impact assessments of third parties.
  • Ensure that proper documentation for new and existing third-party relationships is properly completed, maintained, and retained.
  • Maintain vulnerability management program and scanning engines.
  • Maintain an advanced working knowledge of emerging security trends.
  • Participate with client audits and assessments to ensure the firm’s security and privacy program meet client expectations.
  • Routinely interfaces with the CISO, DPO, IT Security team, IT Operations, IT Applications, H&H Legal, and third parties to determine applicable obligations, risks, recommend mitigations, and track risks to closure.
  • Provide evaluation of suspected malware and recommendations for remediation.
  • Provide recommendations on physical security risks and controls.
  • Support and provide recommendations for access controls for applications, systems, and networks.

Benefits

  • 37.5-hour scheduled work week
  • robust wellness program
  • generous PTO
  • holiday pay
  • medical
  • dental
  • vision
  • life
  • AD&D
  • EAP
  • STD
  • LTD
  • supplemental life
  • accident
  • critical illness
  • hospital indemnity insurances
  • 401(k)-retirement plan with a company match
  • educational assistance
  • free or discounted legal services
  • opportunities through the Holland & Hart Foundation
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service