Security Analyst 1
Spectraforce
United States
27 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Internship / Graduate position
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours
Job source
Tech stack
Microsoft Windows
Amazon Web Services
JIRA
Microsoft Azure
Software as a Service
Cloud Computing
Cyber Security
Dynamic Host Configuration Protocol
Linux
Domain Name System (DNS)
Hypertext Transfer Protocols (HTTP)
Infrastructure as a Service (IaaS)
+24 more
Internet Control Message Protocol
Issue Tracking Systems
Log Analysis
Networking Basics
Network Monitoring
Network Protocols
Platform as a Service (PAAS)
Cloud Services
Phishing
Security Information and Event Management
TCP/IP
Mitre Att&ck
QRadar
Generative AI
Malware
Firewalls (Computer Science)
Containerization
Kubernetes
Ddos
Splunk
GPT
Event Viewer
Docker
Servicenow
Job description
- You will be the first point of contact for triaging security alerts and will engage more senior analysts and management as required
- Correlate data from SIEM, EDR, and firewall logs
- Perform basic log analysis and escalate suspicious activity
- Follow standard operating procedures and escalate issues or improvement opportunities as needed.
- Map basic security incidents to MITRE ATT&CK tactics during documentation
- Identifies and escalates issues related to data privacy.
- Document incidents in ticketing systems
- Support endpoint and network monitoring activities
- Participate in shift handovers and daily SOC briefings
- Security Monitoring: Understands basic alert types and can triage low-level events
- Security Operations: Follows established SOC procedures and documents findings
- Incident Escalation: Recognizes when to escalate alerts to senior analysts
Requirements
- 1+ years of experience in IT or security operations (internships or bootcamps acceptable)
- Basic understanding of networking protocols and operating systems
- Basic understanding of incident response phases
- Awareness of common indicators of compromise (IOCs).
- Familiarity with ticketing systems and escalation procedures.
- Networking Basics: TCP/IP, DNS, DHCP, HTTP/S, ICMP
- Security Concepts: CIA triad, types of malware, phishing, brute force, DDoS
- Operating Systems: Basic Windows (Event Viewer, Task Manager), Linux (top, ps, netstat)
- Security Tools:
- SIEM: Splunk (basic search), IBM QRadar (offense monitoring)
- AV/EDR: Windows Defender, CrowdStrike
- Ticketing: ServiceNow, Jira
- Familiarity with SIEM tools and log analysis
- Cloud platforms: Basic AWS/Azure console navigation, understanding of cloud service types (IaaS, PaaS, SaaS)
- Basic understanding of containerization concepts (Docker, Kubernetes fundamentals)
- Strong attention to detail and documentation skills
- GenAI tools: ChatGPT or similar for threat research assistance, automated report summarization
- Foundational security certifications (e.g., Security+, Network+, CySA+, GSOC) or pursuing certification
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on leoforce.usGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
CH
Chris Heilmann
almost 2 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
about 2 years ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
6 months ago
AJ
Austin Joy
What Are The Top Skills Required For Azure Developers?
over 4 years ago