Cyber Security Analyst

FuelCell Energy•Danbury, CT
•$95,000 - $110,000•Hybrid

About The Position

We are currently seeking a motivated and experienced Cyber Security Analyst to join our Global Infrastructure team to help protect FuelCell Energy’s people, data, and systems across corporate, manufacturing, and operational (OT) environments. Reporting to the Senior Director, Infrastructure, Cybersecurity & AI, this hands-on analyst monitors for threats, hunts for emerging risks, responds to incidents, and strengthens the organization’s security posture. This is a hybrid position based in Danbury, CT, with onsite presence critical to collaborate with cross-functional teams, support operational systems, and ensure the security and resilience of our infrastructure. The Cyber Security Analyst combines technical security skills with strong judgment and clear communication. Core areas of focus include tuning firewall rules and security tooling to industry best practices, proactive threat hunting, and leading the company’s security awareness and phishing program-running simulated phishing campaigns, educating employees, and reducing human risk-while partnering with IT and business stakeholders to detect, respond to, and prevent security threats.

Requirements

  • Bachelor’s degree in information technology, cybersecurity, computer science, or a related discipline. Extensive experience will be considered in lieu of a degree.
  • CompTIA Security+, CySA+, GIAC (GSEC/GCIH), Microsoft Security (SC-200), or similar certifications.
  • Three to five years of experience in cybersecurity, security operations, or IT with a security focus, spanning IT and OT environments.
  • Demonstrable knowledge/experience in security monitoring, alert triage, and incident response across endpoints, network, cloud, email, and identity.
  • Demonstrable knowledge/experience in running security awareness and simulated phishing programs, including campaign design, metrics, and follow-up education.
  • Demonstrable knowledge/experience in tuning firewall rules and policies to best practices, and monitoring firewalls to detect and mitigate risks.
  • Demonstrable knowledge/experience in proactive threat hunting to identify indicators of compromise and emerging threats.
  • Demonstrable knowledge/experience in tuning, maintaining, and serving as an SME for security tool sets, aligned to NIST CSF and industry best practices.
  • Demonstrable knowledge/experience in vulnerability management, including scanning, prioritization, and coordinating remediation.
  • Demonstrable knowledge/experience in security tooling such as EDR, SIEM, email security, and cloud security (ESET Protect, Microsoft Defender, or similar).
  • Demonstrable knowledge/experience in identity and access management concepts, including least privilege, access reviews, and multi-factor authentication.
  • Demonstrable knowledge/experience in common attacker techniques, phishing and social engineering, and how to detect, contain, and prevent them.
  • Demonstrable knowledge/experience in security standards and frameworks, such as NIST CSF and IEC 62443, and how they influence security controls and processes.
  • Excellent communication skills with the ability to create clear documentation and communicate security concepts to non-technical stakeholders.
  • Strong problem-solving skills, attention to detail, and sound judgment under pressure.

Responsibilities

  • Monitor security tools, alerts, and logs across endpoints, network, cloud (Azure), email, and identity to detect, triage, and respond to potential threats.
  • Investigate and respond to security incidents, including containment, eradication, and recovery, and document findings, root causes, and lessons learned.
  • Perform vulnerability management activities, including scanning, prioritization, tracking, and coordinating remediation with IT and infrastructure teams.
  • Support identity and access management controls, including access reviews, least-privilege enforcement, and multi-factor authentication.
  • Contribute to the company’s overall information systems and security architecture strategy, standards, and design.
  • Maintain and tune security controls and tooling, such as endpoint detection and response (EDR), email security, SIEM, and cloud security tools.
  • Assist with security compliance activities and control evidence in support of frameworks such as NIST CSF, IEC 62443, and SOX.
  • Develop and maintain security documentation, including procedures, playbooks, and reporting for technical and non-technical audiences.
  • Provide guidance and second-level support to IT and end users on security issues, safe practices, and incident reporting.
  • Track the evolving threat landscape and recommend improvements to controls, processes, and awareness efforts.
  • Tune firewall rules and policies in alignment with security best practices, removing unnecessary or risky rules and enforcing least-privilege network access.
  • Continuously monitor firewalls and network security events, and take timely action to investigate, contain, and mitigate relevant risks.
  • Tune and optimize existing security toolsets to industry best practices and in alignment with NIST CSF, improving detection, coverage, and signal quality.
  • Maintain the organization’s security tool sets and become a subject matter expert (SME) across each, ensuring they are healthy, current, and effective.
  • Regularly review and update security tools as new features, capabilities, and risks emerge, and recommend enhancements or replacements where appropriate.
  • Perform proactive threat hunting across endpoints, network, cloud, and identity to identify indicators of compromise and emerging threats before they cause impact.
  • Use threat hunting and monitoring findings to strengthen controls, tune detections, and reduce the organization’s attack surface over time.
  • Design, run, and continuously improve simulated phishing campaigns across the organization, using realistic scenarios that reflect current attacker techniques.
  • Analyze simulation results, track click and report rates, identify high-risk users and departments, and target follow-up education where it is needed most.
  • Develop and deliver phishing and security awareness education, including training content, tips, and just-in-time coaching that changes user behavior and reduces human risk.
  • Manage the response and remediation process for repeat offenders, coordinating additional training and appropriate follow-up actions with IT and leadership.
  • Promote a strong security culture through ongoing communication, awareness campaigns, and clear guidance on how employees can recognize and report threats.
  • Investigate real reported phishing emails, contain and remediate malicious messages, and use lessons learned to strengthen both technical controls and user education.
  • Report on program effectiveness-awareness metrics, phishing trends, and improvements over time-to IT leadership and business stakeholders.

Benefits

  • medical
  • dental
  • vision
  • company-paid life/disability insurance
  • 401(k) plan
  • employee stock purchase plan
  • generous paid leave
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service