> Markdown version of [/jobs/ext/2187955-executive-office-of-technology-services-and-security](https://www.wearedevelopers.com/jobs/ext/2187955-executive-office-of-technology-services-and-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Executive Office of Technology Services and Security - **Company:** Commonwealth of Massachusetts - **Location:** Chelsea, MA, United States (Remote available) - **Contract:** Permanent contract - **Skills:** Testing (Software), Microsoft Windows, Amazon Web Services, ARM Architecture, Microsoft Azure, Cloud Computing, Cyber Security, Information Systems, Computer Networks, Linux, Extranet, Intrusion Detection Systems, Routing, Packet Analyzer, Network Protocols, Phishing, Security Information and Event Management, TCP/IP, Virtual Local Area Networks, Information Technology, Splunk, Vulnerability Analysis - **Published:** August 22, 2026 - **Apply:** https://massanf.taleo.net/careersection/ex/jobdetail.ftl?job=260005RW ## About the Role * Knowledge of SIEM (Security Information and Event Management) Splunk Preferred * TCP/IP, VLANs, computer networking, routing, and switching * IDS/IPS, penetration and vulnerability testing * Windows and Linux operating systems * Network protocols and packet analysis tools * EDR Tools Palo Alto Cortex preferred * Cloud computing (AWS/AZURE/GCP) * Understanding of Proofpoint and other email security tools. Non-technical Skills: * Critical thinking and problem-solving abilities. * Capability to communicate and listen to needs from organizational stakeholders. Education and Certifications: · Bachelor's Degree in computer science, Information Systems, Business Administration or other related field, or equivalent work experience. · Security certifications desired but not required. ','!*!, Applicants must have (A) at least one (1) year of full-time or equivalent part-time experience in the field of information technology security, or (B) any equivalent combination of the required experience and the substitutions below., I. An Associate's degree in a related field may substitute for the required experience. ## Description 'requisitionDescriptionInterface', 'descRequisition', ['1091115','true','1091115','false','Submission for the position: Cyber Detection and Response Analyst - (Job Number: 260005RW)','false','1091115','false','true','Cyber Detection and Response Analyst','260005RW','!*! The Executive Office of Technology Services and Security (EOTSS) is the lead enterprise technology organization for the Commonwealth of Massachusetts. Charged with driving the ongoing alignment of business and technology across the Commonwealth's Executive Branch, EOTSS oversees and manages the enterprise technology, digital infrastructure and services, as well as the Commonwealth Security Operations Center and an enterprise Standard Operating Environment that includes an information security and risk management framework for over 125 state agencies and over 43,000 state employees. We directly serve our constituents by providing digital services and tools that enable taxpayers, drivers, businesses, visitors, families and other citizens to do business with the Commonwealth in a way that makes every interaction with government easier, faster, and more secure. Our Mission: We provide technology leadership across the Commonwealth to enhance the quality of public service and foster positive community outcomes. This position will be a member of a Security Operations Center's Cyber Detection and Response Team. The EOTSS SOC Cyber Detection and Response Analyst I is primarily responsible for incident triage, detection, response, and remediation activities that occur within the TSS SOC. Analysts in Security Operations work with Security Engineers, Managed Security Service Providers (NuHarbor) and SOC Managers to give situational awareness via detection, containment, and remediation of IT threats. SOC Analysts cooperate with other team members to detect and respond to information security incidents, develop, and follow security events such as alerts, and engage in security investigations., * Managing day-to-day security monitoring, and IR activities, including but not limited to SIEM monitoring, Endpoint Detection and Response using Palo Alto's Cortex XDR, notifying agencies of potential malicious activities, managing, and/or maintaining security incident response practices * Assist in detection and incident response functions including, but not limited to, Security Incident Reporting tickets, customer and constituent notification, tracking, and reporting. Conduct and/or participate in agency, state, regional, and/or national cyber security incident simulation exercises * Monitor, report, and respond to anomalous Internet, Extranet, and/or Intranet activity related information provided through internal operations and/or credible external third-party threat intelligence organizations. Work with EOTSS customer organizations and EDR vendor to test software revision, EDR client file updating, and/or EDR related status reporting * Assist in the development and delivery of cybersecurity education and awareness initiatives on behalf of state government. * Review third party alerts to maintain overall situational awareness of security issues affecting Commonwealth agencies, EOTSS customer organizations, and/or MS-ISAC members. * Conduct research into new threats that may affect Commonwealth agencies, EOTSS customer organizations, and/or local entities. * Provide and promote security awareness. Assist in phishing campaigns for all users across the Commonwealth while furthering overall security awareness programs. * Support the preparations of security reports to management on security system activities and performance utilizing enterprise security tools (Tenable, DHS, Expanse, etc.) * Support troubleshooting security related problems. * Other duties and responsibilities as assigned., This position will be a member of a Security Operations Center's Cyber Detection and Response Team. The EOTSS SOC Cyber Detection and Response Analyst I is primarily responsible for incident triage, detection, response, and remediation activities that occur within the TSS SOC. Analysts in Security Operations work with Security Engineers, Managed Security Service Providers (NuHarbor) and SOC Managers to give situational awareness via detection, containment, and remediation of IT threats. SOC Analysts cooperate with other team members to detect and respond to information security incidents, develop, and follow security events such as alerts, and engage in security investigations. ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools)