Security Analyst 1

Spectraforce
United States
27 days ago

Role details

Contract type
Internship / Graduate position
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Amazon Web Services JIRA Microsoft Azure Software as a Service Cloud Computing Cyber Security Dynamic Host Configuration Protocol Linux Domain Name System (DNS) Hypertext Transfer Protocols (HTTP) Infrastructure as a Service (IaaS)
+24 more
Internet Control Message Protocol Issue Tracking Systems Log Analysis Networking Basics Network Monitoring Network Protocols Platform as a Service (PAAS) Cloud Services Phishing Security Information and Event Management TCP/IP Mitre Att&ck QRadar Generative AI Malware Firewalls (Computer Science) Containerization Kubernetes Ddos Splunk GPT Event Viewer Docker Servicenow

Job description

  • You will be the first point of contact for triaging security alerts and will engage more senior analysts and management as required
  • Correlate data from SIEM, EDR, and firewall logs
  • Perform basic log analysis and escalate suspicious activity
  • Follow standard operating procedures and escalate issues or improvement opportunities as needed.
  • Map basic security incidents to MITRE ATT&CK tactics during documentation
  • Identifies and escalates issues related to data privacy.
  • Document incidents in ticketing systems
  • Support endpoint and network monitoring activities
  • Participate in shift handovers and daily SOC briefings
  • Security Monitoring: Understands basic alert types and can triage low-level events
  • Security Operations: Follows established SOC procedures and documents findings
  • Incident Escalation: Recognizes when to escalate alerts to senior analysts

Requirements

  • 1+ years of experience in IT or security operations (internships or bootcamps acceptable)
  • Basic understanding of networking protocols and operating systems
  • Basic understanding of incident response phases
  • Awareness of common indicators of compromise (IOCs).
  • Familiarity with ticketing systems and escalation procedures.
  • Networking Basics: TCP/IP, DNS, DHCP, HTTP/S, ICMP
  • Security Concepts: CIA triad, types of malware, phishing, brute force, DDoS
  • Operating Systems: Basic Windows (Event Viewer, Task Manager), Linux (top, ps, netstat)
  • Security Tools:
  • SIEM: Splunk (basic search), IBM QRadar (offense monitoring)
  • AV/EDR: Windows Defender, CrowdStrike
  • Ticketing: ServiceNow, Jira
  • Familiarity with SIEM tools and log analysis
  • Cloud platforms: Basic AWS/Azure console navigation, understanding of cloud service types (IaaS, PaaS, SaaS)
  • Basic understanding of containerization concepts (Docker, Kubernetes fundamentals)
  • Strong attention to detail and documentation skills
  • GenAI tools: ChatGPT or similar for threat research assistance, automated report summarization
  • Foundational security certifications (e.g., Security+, Network+, CySA+, GSOC) or pursuing certification

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on leoforce.us

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

40 sec

Generative pre-trained transformer models powering code completions

lgonta lgonta +1 · WWC 2024

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

1:51 min

Rising DDoS attacks and evaluating CDN mitigation strategies

Chris Heilmann +2 · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

51 sec

Assessing GPT-4o performance for pull request feedback

Merrill Lutsky Merrill Lutsky · WWC 2025

14:14 min

Addressing audience inquiries on analytical implementation and career growth

Julian Joseph · LIVE

Videos

See all

Related articles

See all