Back to search
NPAworldwide Linkedin · Posted yesterday

Information Security Analyst

Syracuse, New York, United States

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Job Description

About the Role

We are seeking an experienced Information Security Analyst to support security operations, incident response, vulnerability management, digital forensics, and security automation within a complex enterprise environment.

This is a hands-on technical role operating as a senior practitioner within a Security Operations Center (SOC). The Information Security Analyst will investigate security alerts and incidents, improve detection capabilities, support vulnerability remediation, administer and enhance security technologies, and develop automation using Python and PowerShell.

The position requires practical experience with SIEM and endpoint security platforms, Microsoft security technologies, firewall administration, identity and access technologies, Windows and Linux environments, and AI-assisted security tooling. The analyst will also provide technical guidance and mentorship to junior SOC team members.

Key Responsibilities

  • Monitor network, endpoint, system, application, and identity telemetry for potential security threats.
  • Investigate IDS/IPS and EDR alerts, security logs, system events, and network traffic to identify suspicious or malicious activity.
  • Perform second-level analysis of escalated alerts, determine severity and relevance, distinguish legitimate threats from false positives, and document findings.
  • Use SIEM and log-analysis platforms such as Splunk, Elastic/OpenSearch, Kibana, and Microsoft Sentinel to investigate and correlate security events.
  • Operate, tune, and recommend improvements to SIEM, EDR, endpoint security, and other SOC technologies.
  • Support Microsoft Defender and related Microsoft security technologies for alert investigation, containment, and response.
  • Develop threat-hunting and detection strategies based on emerging threats, observed activity, and established attack frameworks.
  • Identify and integrate additional security data sources to improve monitoring and detection coverage.
  • Develop Python 3 and PowerShell scripts to automate detection, enrichment, investigation, response, and security data analysis.
  • Support firewall administration, including security policy enforcement and ruleset maintenance.
  • Incorporate AI-assisted security capabilities into investigation, detection, analysis, automation, and response workflows.
  • Serve as a technical first responder for suspected and confirmed cybersecurity incidents.
  • Perform endpoint, identity, network, log, and system-level analysis to determine incident scope, impact, and potential root cause.
  • Support incident containment, eradication, evidence preservation, and recovery activities.
  • Conduct first-responder-level digital forensic analysis and breach assessment.
  • Prepare clear incident documentation and communicate findings to technical leadership and relevant stakeholders.
  • Configure and review vulnerability scans and analyze identified security weaknesses.
  • Prioritize vulnerabilities based on severity, exploitability, exposure, and business impact.
  • Coordinate remediation activities with infrastructure, application, networking, and system owners.
  • Validate remediation activities and monitor patching effectiveness for critical findings.
  • Mentor junior SOC analysts in alert investigation, log analysis, incident documentation, and escalation practices.
  • Assist with the onboarding, training, and day-to-day technical oversight of junior security team members.
  • Develop and maintain SOC runbooks, operating procedures, investigation workflows, and escalation guidelines.

Qualifications

QualificationsEducation

  • Bachelors degree in Cybersecurity, Information Security, Computer Science, Computer Engineering, Information Management, or a related technical discipline.

Experience

  • 5+ years of professional Information Technology experience.
  • 2+ years of professional Information Security or Cybersecurity experience.
  • 2+ years of hands-on SOC operations experience involving IDS/EDR alert triage, log analysis, and network traffic interpretation.
  • 2+ years of experience with SIEM or log-analysis technologies such as Splunk, Kibana, Elastic/OpenSearch, or Microsoft Sentinel.
  • 2+ years of experience with Microsoft Defender for Endpoint, including alert triage, investigation, and response.
  • 2+ years of Python 3 scripting experience supporting security automation, analysis, or SOC workflows.
  • 2+ years of experience with firewall administration and network security fundamentals.
  • 1+ years of experience with Windows and Active Directory administration and security.
  • 1+ years of experience analyzing endpoint and Windows security logs.
  • 1+ years of experience with PowerShell scripting and Group Policy.
  • 1+ years of Linux system administration experience.
  • 1+ years of first-responder-level digital forensic experience.
  • 1+ years of experience using AI-assisted security technologies, including AI-enabled SIEM, investigation, automation, or productivity capabilities.
  • Experience working in a production SOC or comparable security operations environment investigating active security alerts and incidents is strongly preferred.
  • Experience mentoring or providing technical guidance to junior security analysts is preferred.

Technical Skills

  • Strong knowledge of TCP/IP, common network protocols, network traffic analysis, and network security fundamentals.
  • Hands-on knowledge of IDS/IPS and network-based threat detection technologies.
  • Working knowledge of MITRE ATT&CK and Cyber Kill Chain concepts.
  • Experience with vulnerability scanning, risk prioritization, remediation tracking, and patch validation.
  • Working knowledge of cloud security principles and technologies.
  • Knowledge of security orchestration, automation, and response (SOAR) concepts.
  • Ability to develop script-based security automation using Python 3 and PowerShell.
  • Working knowledge of Microsoft security technologies, including Defender XDR, Microsoft Sentinel, Purview, and Entra ID.
  • Understanding of identity and access management concepts, technologies, and architecture.
  • Experience with Kusto Query Language (KQL) for security investigations, threat hunting, and analytics.
  • Working knowledge of Windows, Active Directory, Group Policy, and Linux security administration.
  • Ability to incorporate AI-assisted tools into security operations and technical problem-solving.
  • Ability to correlate security information across endpoint, identity, network, cloud, application, and infrastructure sources.

Certifications

  • Relevant cybersecurity certifications such as Security+, CySA+, GCIH, GCIA, CISSP, Microsoft Security certifications, or equivalent are preferred but not required.

Soft Skills

  • Strong analytical and investigative skills with the ability to correlate information from multiple security and infrastructure sources.
  • Sound judgment and composure during active cybersecurity incidents.
  • Clear written and verbal communication skills with technical and non-technical stakeholders.
  • Ability to collaborate effectively with infrastructure, networking, application, identity, and other technical teams.
  • Ability to mentor and develop less-experienced security professionals.
  • Strong documentation skills for incident reports, investigation findings, procedures, and SOC runbooks.
  • Ability to prioritize competing security issues based on risk and business impact.
  • Commitment to maintaining current knowledge of cybersecurity threats, technologies, attack techniques, and defensive practices.

Why Is This a Great Opportunity

This position provides the opportunity to work in a mature, security-focused environment with exposure to enterprise security operations, incident response, digital forensics, vulnerability management, threat detection, automation, and Microsoft security technologies. The role combines hands-on technical responsibilities with opportunities to improve SOC processes, develop security automation, mentor junior analysts, and contribute to the continued development of the organization's security capabilities.

Salary Type : Annual Salary

Salary Min : $ 85000

Salary Max : $ 90000

Currency Type : USD

Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search