Job Title: Cybersecurity Analyst
Department: Information Technology
Classification: Exempt/Salary
Reports to: Director of IT Infrastructure and Information Security
Job Qualifications:
- Demonstrate a powerful sense of internal customer service and a strong work ethic to positively contribute to the company's mission and vision.
- Sound written and verbal communication skills; must be able to communicate proficiently to a non-technical audience.
- Proven experience working in an enterprise IT organization, concentrating in the following areas: Information security, SOC, Policy creation, and review.
- Knowledge of cyber-attack stages (reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks)
- Exceptional knowledge of penetration testing principles, tools, and techniques
- Strong Knowledge of network topology, WIFI, VLAN, routing, firewalls, servers, and cloud technologies.
- Strong knowledge in performing packet-level analysis to characterize and classify network traffic and trace vulnerability and potential compromise.
- Working experience in compliance with OSHA, SOC, HIPPA, and PCI.
- Requires knowledge of security issues, techniques, and implications across all existing computer platforms.
- Must have extensive knowledge in networking and server infrastructure, Azure cloud, and web applications.
- Experienced in security administration, management of security projects, and complicated security issues
- Strong experience working with EMDR, EDR, Antivirus, SIEM, log management, and vulnerability scanning tools (Nessus).
- Strong skills in creating and updating cybersecurity policy, employee security assessment training, and quarterly updates.
Educational Requirements:
Bachelor's degree from a four-year college or university and 2 to 4 years of varying environmental experiences centered around Information Security.
Job Summary:
Responsible for the operation of network security tools and devices under minimal guidance. Provides security monitoring operational service management and participates in ticket escalation. Troubleshoots and resolves complex security issues. Gives subject expertise to all security-related projects, changes, and enhancements.
Job Duties:
- Perform quarterly vulnerability scans internally and externally. Provide reports and findings to the Director of infrastructure and information security.
- Provide operational support and triage for issues related to security-related issues or concerns.
- Work with IT applications, operations teams, and lines of business to ensure processes, procedures, and applications meet the requirements for security and compliance.
- Develops and maintains skills in responding to system and data breaches by internal and external threat actors. Performs forensic duties in support of YCH as necessary.
- Assists with the testing of forensic capabilities and processes for proper functionality.
- Assists other staff members in performing forensic collections and investigations and delivering comprehensive reports of findings as requested.
- Demonstrates knowledge of the forensic requirements for collecting, preserving, and presenting evidence.
- Assists with the compilation of investigation reports, supporting evidence and data, and other incident or investigative-related documentation as requested.
- Develops and maintains effective security event monitoring, controls, processes, and technologies that identify threats to the infrastructure and systems so that production is not disrupted.
- Proactively monitors established controls for known threats and anomalous activity, indicating a potential risk to provide IT technical infrastructure support, including out-of-hours support when required.
- Identify opportunities and recommend improving the security posture with process, training, and tools.
- Analyze and report on threats that could impact the integrity of our systems, networks, and applications.
- All other duties as assigned or required
- Preferred experience in multiple technologies related to security and monitoring technologies and processes.
- Must have excellent business analysis, documentation, and communication skills
- familiar with standard concepts, practices, and procedures supporting multiple office locations, including globally (EU).
- Minimum 2+ years of experience in project managing, integrating, and implementing infrastructure technologies & services and related technologies.
- Minimum 2+ years of security administration experience strongly desired.
- Minimum 2+ years of experience with Microsoft technologies, including Windows OS and Cisco networking.
- Other duties may include special projects as assigned, providing support in all project phases from planning and analysis to implementation and ongoing maintenance.
- Adhere to all company policies.
- Able to work nights and weekends as required or requested.
- Able to manage multiple projects at once.
- Maintain sanitary and safe work environment and follow safety requirements.
- May actively participate on company’s Safety Committee.
- Ensure that company safety policies as well as federal, state and local safety and environmental regulations are observed.
- Must have a complete understanding of company’s policies, SOPs, QPs, EPs, HACCP and cGMP that pertain to their department to ensure quality, safety, efficiency and sustainability.
- Must adhere to all company policies.
- Examine documents, materials, and products and monitor work processes to assess completeness, accuracy and conformance to standards and specifications.
- Follow all SOPs in a given area.
- Perform all other duties as assigned by Manager and/or designee.
Benefits:
- Medical, Dental, & Vision insurance
- Health Savings Account (HSA)
- Flexible Savings Account (FSA)
- Company Paid Life & AD&D, Voluntary Life And AD&D Insurance
- Employee Assistance Program (EAP) - Lifeworks
- Calm for Work
- 401(k) retirement plan with 6% & Roth option
- Education Tuition Assistance Program
- 10 Recognized Holidays
- 50 hours of personal/sick time pro-rated based upon hire date
- 110 hours accrued Vacation
- Competitive Wages
- Performance Incentive Bonus opportunities
- Wellness Benefit
- Employee Giveback Program
- Individual Development Programs
- Youth Donation Program
- Continuing Education Programs
- Bring your Pet to Work Program (applies to admin positions only)
- Pet Insurance
- And much more…