The Security Analyst role involves continuous review and correlation of security event data from various sources including SIEM, EDR, IDS/IPS, and threat intelligence to identify complex attack patterns, emerging threats, and security incidents. The analyst will perform deep-dive analysis of suspicious activity, validate incidents, determine root cause and impact, and escalate critical incidents with detailed context. Responsibilities include creating detailed incident reports, timelines, and post-incident summaries, contributing to lessons-learned documentation, and recommending remediation and preventative measures. The role also involves investigating user-reported phishing and malware, advising on containment and recovery, recommending updates to SOC playbooks and workflows, fine-tuning detection rules, and integrating new threat intelligence feeds. The analyst will proactively hunt for threats using up-to-date tactics, techniques, and procedures (TTPs), serve as a customer-facing SME, document processes, and coordinate with various teams to meet goals.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
Associate degree