> Markdown version of [/jobs/ext/1747837-cyber-triage-and-forensics-junior-analyst](https://www.wearedevelopers.com/jobs/ext/1747837-cyber-triage-and-forensics-junior-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Triage and Forensics - Junior Analyst - **Company:** Ernst & Young LLP - **Location:** Hoboken, NJ, United States - **Experience:** Starter - **Salary:** $60,400.0 - $109,600.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, Information Systems, Linux, Intrusion Detection and Prevention, OSI Models, Security Information and Event Management, TCP/IP, Windows Desktop, Information Technology - **Published:** July 9, 2026 - **Apply:** https://dejobs.org/x/x/5D84C4B2DD8D424B94FF36AF3728B95B/job/ ## About the Role * The CTF Analyst I must be competent to work at a technical level, be capable of identifying threats and vectors that cause security events and be able to follow defined procedures for mitigating said threats. Skills and attributes for success * How to respond to network, cloud and host based security events * Ability to participate in detecting, investigating, and resolving security events * Capable of working independently * Identify and propose areas for improvement within the Cyber Triage and Forensics * Good interpersonal skills To qualify for the role you must have Bachelors in Computer Science, Information Systems, Engineering or 2 - 3 years of related work experience. Experience: * Minimum of 1-2 years of experience in one or more of the following: * Working in a Security Monitoring/Security Operations Center environment (SOC) * Experience investigating security events, threats and/or vulnerabilities * Demonstrate incident handling ability * Demonstrate ability to analysis log output from various devices * Understanding of electronic investigation and log correlation * Proficiency with the latest intrusion detection platforms * Working knowledge of Windows systems administration (Including AD) and/or Linux. Ideally, you'll also have * Information Security Principles, Technologies, and Practices * Proven experience with multiple security event detection platforms * Thorough understanding of TCP/IP * Demonstrated integrity in a professional environment * Good social, communication and technical writing skills * Comfortable navigating and troubleshooting Windows system issues * Desired Certifications - Any Security Certifications What we look for Under limited supervision the CTF (Cyber Triage and Forensics) Analyst I will report to the CTF Global Service Manager. The CTF Analyst I will perform tasks including monitoring, research, classification and analysis of security events that occur on the network or endpoint. The CTF Analyst I should have familiarity with the principles of network and endpoint security, current threat and attack trends, a basic understanding of the OSI model, cloud security, and have a working knowledge of defense in depth strategies. ## Description * Perform front line accurate and precise real-time monitoring and analysis correlation of logs/alerts from a multitude of security devices with a focus on the determination of what was said as events constitute security incidents. * They will work multi-functionally to detect and respond to information security incidents, develop, maintain, and follow procedures for security event alerting, and participate in security investigations. ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [What Makes Open Source Work: Licensing and Beyond](https://www.wearedevelopers.com/videos/1416-what-makes-open-source-work-licensing-and-beyond) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)