Security Analyst - Level 1 - 26-13174
Job Description
Job DescriptionSecurity Analyst – Level 1
Location: Blythewood, South Carolina
Duration: 12 Months
Work Arrangement: Fully Onsite — No Hybrid or Remote Flexibility
Candidate Requirement: Must be a current South Carolina resident. No relocation candidates accepted.
Position Overview
We are seeking an Entry-Level Security Analyst to support an expanding cybersecurity team and increased security workload.
The selected candidate will receive training and support a variety of cybersecurity functions, including threat intelligence, threat hunting, log analysis, incident response, vulnerability management, security awareness, automation, endpoint security, network security, digital forensics, and cloud security.
Candidates should have a basic understanding of server or network administration, along with a strong interest in developing their cybersecurity skills.
Work Schedule
Availability for Saturday and Sunday evening shifts is mandatory and will be part of the selected candidate's regular schedule after training.
Expected schedule:
- Saturday: 8:00 PM – 8:00 AM
- Sunday: 8:00 PM – 8:00 AM
- Wednesday: 8:30 AM – 2:45 PM
- Thursday: 8:30 AM – 2:45 PM
Key Responsibilities Threat Intelligence Research
- Monitor and analyze threat intelligence feeds to identify emerging threats.
- Research new attack methods, vulnerabilities, and potential risks.
- Document findings and share relevant information with the security team.
- Use OSINT tools to gather information on potential threats and adversaries.
Threat Hunting & Detection
- Conduct proactive searches for suspicious network and endpoint activity.
- Utilize threat feeds and security tools to investigate suspicious activity.
- Collaborate with senior analysts to develop and test detection rules.
- Work with SIEM queries and endpoint detection rules.
- Document threat-hunting methodologies and findings.
Log Analysis
- Review and interpret logs from firewalls, endpoints, and servers.
- Identify indicators of compromise (IOCs), anomalous activity, and unauthorized access attempts.
- Escalate potential security concerns to senior analysts.
- Track recurring patterns and anomalies.
Incident Response
- Assist with initial security incident triage.
- Follow established incident response frameworks, including NIST and MITRE ATT&CK.
- Identify and escalate potential security threats.
- Gather and analyze logs, alerts, and other relevant evidence.
- Assist with incident containment and remediation.
- Document findings and activities throughout the incident lifecycle.
Documentation & Reporting
- Prepare incident reports, after-action reviews, and security documentation.
- Report on security findings and recommend mitigation strategies.
- Develop security training materials and user guides.
- Maintain accurate and organized security documentation.
Vulnerability Management
- Analyze vulnerability reports.
- Assist with prioritizing patching activities.
- Apply NIST best practices related to vulnerability management.
Security Awareness
- Assist with developing and delivering security awareness training.
- Support employee security awareness assessments and simulations.
Security Automation & Scripting
- Utilize SCCM, Group Policy (GPO), and PowerShell for patch deployment.
- Develop automation to improve efficiency and reduce manual processes.
Endpoint & Network Security
- Configure and maintain security policies.
- Analyze security alerts and manage endpoint protection.
- Apply knowledge of network protocols and firewalls to improve security.
Digital Forensics & Cloud Security
- Assist with security investigations and evidence collection.
- Develop knowledge of cloud-specific security solutions and security controls.
Required Skills
- Understanding of security concepts and processes.
- Understanding of basic computer and network concepts.
- Strong problem-solving and analytical abilities.
- Attention to detail.
- Ability to communicate and work effectively within a mid-sized team.
Preferred Skills & Experience
- 1+ year of Server or Network Administration experience.
- 1+ year of experience in an IT security-focused role.
- Experience with SIEM and Endpoint Security tools.
- Experience with PowerShell, Group Policy, and Endpoint Management.
- Knowledge of Vulnerability Management and Cloud Security.
- Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, or a related field.
Education
- High School Diploma required at minimum.
- Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, or a related field is preferred.
Preferred Certifications
Certifications are not required. Candidates with any of the following certifications are preferred:
- GIAC Security Essentials (GSEC)
- CompTIA Security+
- CompTIA Network+
- GIAC Certified Incident Handler (GCIH)
