About this role
KEY RESPONSIBILITIES:
• Monitor, analyze, investigate, and report on security events, alerts, vulnerabilities, and risks across the organization's information systems.
• Independently perform incident response activities including triage, containment, eradication, recovery, root cause analysis, and post-incident reporting.
• Conduct advanced threat hunting activities to identify malicious activity, security gaps, and emerging threats.
• Perform vulnerability management activities including scanning, risk analysis, remediation planning, validation, and executive reporting.
• Develop and maintain security use cases, alerting logic, dashboards, correlation rules, and reporting within security monitoring platforms.
• Perform security reviews of infrastructure, cloud services, applications, and business systems to identify security risks and recommend corrective actions.
• Partner with IT teams to implement security controls, hardening standards, and remediation activities.
• Lead vendor security assessments and third-party risk evaluations.
• Assist with security governance initiatives including policy development, standards maintenance, risk assessments, and compliance activities.
• Evaluate emerging threats, vulnerabilities, and industry trends and recommend improvements to strengthen the organization's security posture.
• Participate in internal and external audits by gathering evidence, documenting controls, and validating security requirements.
• Develop security metrics, dashboards, and reporting for leadership.
• Lead security awareness and education initiatives throughout the organization.
• Assist in developing and maintaining incident response plans, playbooks, security procedures, and technical standards.
• Recommend and implement process improvements that enhance operational efficiency and reduce organizational risk.
• Participate in after-hours incident response as required.
• Perform other duties as assigned.
EDUCATION, TRAINING, AND EXPERIENCE:
Required
• Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Technology, or related field, or equivalent combination of education and experience.
• 3+ years of experience in information security, cybersecurity operations, security engineering, security administration, or related technical roles.
• Strong understanding of security frameworks, risk management methodologies, and cybersecurity best practices.
• Experience investigating cybersecurity incidents and conducting security event analysis.
• Experience with vulnerability management programs and remediation coordination.
• Experience supporting enterprise security technologies including SIEM, endpoint protection, email security, identity security, and network security controls.
• Working knowledge of cloud security concepts, Microsoft 365 security controls, identity and access management, and security monitoring practices.
• Experience documenting risks, findings, recommendations, and technical procedures.
Preferred
• One or more industry certifications such as:
• Security+
• GSEC
• SSCP
• CySA+
• CISM
• CISSP
• CISA
• GIAC certifications
• Experience with:
• Microsoft Sentinel
• Microsoft Defender suite
• Vulnerability management platforms
• Privileged Access Management (PAM)
• Security automation and orchestration solutions
• Cloud security platforms
• Threat intelligence platforms
• Familiarity with:
• NIST Cybersecurity Framework (CSF)
• CIS Controls
• ISO 27001
• PCI-DSS
• CPNI
• SOC 2
• Experience conducting security assessments and risk reviews.
• Experience leading security projects and initiatives.
CAPABILITIES AND SKILLS:
• Strong analytical, investigative, and critical-thinking skills.
• Advanced ability to troubleshoot and analyze complex security issues.
• Ability to independently prioritize and manage multiple security initiatives.
• Strong written and verbal communication skills with both technical and non-technical audiences.
• Excellent presentation and documentation abilities.
• Ability to influence security decisions through education, collaboration, and risk-based recommendations.
• Strong organizational and project management skills.
• Ability to maintain confidentiality and handle sensitive information with discretion.
• Demonstrated leadership and mentoring skills.
• Commitment to continuous improvement and professional development.
WORKING CONDITIONS AND PHYSICAL REQUIREMENTS:
• Primarily indoor work in an office environment requiring extended periods of sitting.
• Frequent use of computer systems, security monitoring tools, and technical documentation.
• Occasional lifting of equipment up to 50 pounds.
• May require evening, weekend, or holiday work during security incidents or maintenance activities.
• Occasional travel may be required.
• Ability to respond to critical cybersecurity incidents outside normal business hours.