Cyber Security Analyst

Holland, Inc
Denver, CO, United States
1 day ago
Apply on www.builtincolorado.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$81,000.0 - $135,000.0
Working hours
Regular working hours

Tech stack

Software Applications Software System Penetration Testing Cloud Computing Security Cyber Security Information Systems Computer Engineering Digital Forensics IT Management Information Technology Operations Microsoft Office Microsoft Visio Phishing
+9 more
Security Software Security Information and Event Management Software Vulnerability Management Wireless Networks Malware Information Technology Malware Detection Firewall Services Module Vulnerability Analysis

Job description

Be an Early Applicant Hybrid 2 Locations 81K-135K Annually Mid level Hybrid 2 Locations 81K-135K Annually Mid level Analyzes and remediates security threats using SIEM, EDR/XDR, anti-malware, vulnerability management, and forensic tools. Maintains security controls, policies, vulnerability programs, and reporting; performs assessments, penetration testing, phishing evaluations, and third-party risk reviews. Supports incident response, system hardening, access controls, cloud security, privacy assessments, audits, and security awareness initiatives while coordinating with IT, legal, vendors, and leadership. The summary above was generated by AI

General Purpose:

The Cyber Security Analyst will report to the Information Security Manager and has responsibility for assisting with risk assessments, enterprise vulnerability assessments, operating security software, evaluating third party risk, and designing controls for AI systems Utilizes and analyzes metrics to produce recommendations for future controls and improvements. Responds to alerts, contains cyber security incidents, and routinely interfaces with personnel throughout H&H. This position requires advanced knowledge of information technology verticals across the enterprise, the ability to quickly ascertain the associated security controls, and the ability to positively influence others to implement the controls., * Identify and document security and privacy risk. Using knowledge of best practice, will identify methods to control the risk and assist with control implementation.

  • Interface with MSS and EPP vendors regarding technical settings, perform analysis of alerts, and remediate threats. May interface with vendors to budget and plan for future security controls.
  • Assist with developing and maintaining information and privacy security policies, procedures, standards, and guidelines.
  • May install and administer security protection devices including end point protection (EPP) and SIEM technology.
  • Evaluate suspicious threats and activities in email and systems, using Endpoint Detection and Response (EDR) tools.
  • Utilize malware analysis and sandboxing tools to analyze suspicious events.
  • Leverage security tools to analyze suspicious links, email and documents.
  • Implement remediation controls to block suspicious email and other threats.
  • May evaluate and analyze events using Security Event and Incident Management (SEIM) tools. Will develop reporting from SEIM and other devices.
  • Assists in developing and implementing Security Awareness and Phishing Awareness campaigns. Through analysis of campaign data, will recommend addition controls to improve security.
  • Assist in generating metrics and Key Performance Indicators (KPIs) to improve security decision making, such as vulnerability metrics.
  • Review and evaluate desktop, server, and other device configurations against CIS standards and work with administrators to harden systems.
  • Inform others within IT Security and IT Management regarding security issues.
  • Assist with routine penetration testing and vulnerability assessments against applications, systems, and networks.
  • Performs vulnerability testing of wireless infrastructure in concordance with standards and requirements. Will integrate threat intelligence sources with vulnerability management processes.
  • May conduct third party risk assessments and audits through application of established criteria.
  • May evaluate and propose controls for AI systems.
  • Identify methods to document and track third-party risk and get third party commitment to implement risk controls.
  • May conduct privacy impact assessments of third parties using established processes.
  • Ensures that proper documentation for new and existing third-party relationships is properly completed, maintained, and retained.
  • Maintains vulnerability management program and scanning engines.
  • Maintain an advanced working knowledge of emerging security trends including the latest attack methods, vulnerabilities, and remediation techniques.
  • Participate with client audits and assessments to ensure the firm’s security and privacy program meet client expectations.
  • Routinely interfaces with the CISO, DPO, IT Security team, IT Operations, IT Applications, H&H Legal, and third parties to determine the applicable obligations, initial and on-going risks, recommends mitigations, and tracks risks to closure.
  • Provides evaluation of suspected malware and provides recommendations of remediation.
  • Provides recommendations on physical security risks and controls.
  • Supports and provides recommendations for access controls for applications, systems, and networks., While performing the duties of this position, the employee must have the ability to sit, stand and/or walk for extended periods of time; manipulate (lift, carry, move) weights of at least ten (10) pounds; have repetitive wrist/hand/finger movement to work on a computer and/or related office equipment; speak clearly and concisely so listeners can understand; and regularly understand the speech of another person.

The physical demands described here are representative of those that must be met by this position to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Work Environment:

Professional office atmosphere. Sedentary work that primarily involves sitting or standing for prolonged periods. Position may require occasional off-hour meetings and events.

The work environment characteristics described here are representative of those this position may encounter while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Note: This job description is intended to convey information essential to understanding the scope of the job and the general nature and level of work performed by job holders within this job. However, this job description is not intended to be an exhaustive list of qualifications, skills, efforts, duties, responsibilities or working conditions associated with the position.

Schedule:

At this time, this position allows for a hybrid schedule, generally in-office two to three days per week. Additional days in-office may be required depending on business need and the demands of specific tasks. The hybrid work structure may change at any time, including the number of in-office days requirement.

Requirements

  • Communication: Understands the importance of and demonstrates verbal, written, and non-verbal communications.
  • Customer/Client Experience: Creates a consistent and exceptional experience for others, whether directly to external clients/customers or indirectly through internal support, that elevates the overall perception of the firm.
  • Organization & Planning: Proactively takes actions, finds solutions, and displays skills to be efficient and productive.
  • Team Player: Works within team and cross-functionally to meet required results., * Bachelor’s degree in information technology, information systems, computer science or computer engineering.
  • Three (3) years of cyber security experience.
  • Minimum of one security technical certification such as SSCP, GSEC, CEH and Security+.
  • Must have direct experience in the following:

  • Vulnerability management and how to manage risk using the MITRE Attack Framework including threat intelligence sources.
  • Maintaining and performing analysis using Security Event and Incident Management (SEIM) systems.
  • Digital forensics, reverse malware analysis and incident response.
  • Analyzing events using EDR/XDR and anti-malware systems.
  • Performing phishing and social engineering testing.
  • Active Directory and Auditing Systems.
  • Reviewing firewall rules and configuration.
  • Cloud Security Architecture.

Experience maintaining physical security systems and IoT systems is preferred.

Understands IT security frameworks (NIST 800 series and ISO 27001), compensating controls and how to work with members of IT to implement the corresponding controls.

Understands how to quantify vendor risk.

Understands and may analyze contractual agreements, privacy policies, and other third-party documentation.

Aptitude and a mindset for security.

Self-learner with an ability to research new security trends.

Advanced understanding of how computers work and how they may be exploited.

Understanding of IT Security best practice industry standards and how they are applied

Capable of performing one or more phases of low-complexity projects.

Can forecast budget for low-complexity projects.

Excellent Microsoft Office skills including Visio.

Ability to write scripts and generate reporting from security systems.

Strong adherence to integrity & confidentiality.

Must be collaborative, creative, and driven with a proven ability to be a team player.

Able to think strategically, develop solutions quickly and implement efficiently.

Excellent verbal, written, and overall communication skills.

Excellent analytical skills.

Detail oriented to ensure that the success of implementations is paramount.

Strong analytical, evaluative, and problem-solving skills with a keen attention to detail.

Self-starter with the ability to multi-task and work in a very fast paced environment.

Exceptional client service demeanor and interpersonal skills required.

Must effectively prioritize work/projects and execute tasks in a high-pressure environment

Benefits & conditions

Holland & Hart offers of employment take into consideration a candidate’s education, training, and experience, as well as the position’s work location, external market and internal value, including seniority and merit systems, and internal pay alignment when determining the salary level for potential new employees. The Colorado & Nevada salary range is $80,919.39 - $134,865.66. A discretionary bonus may be available based upon performance., Holland & Hart works hard to promote work/life balance with a 37.5-hour scheduled work week for most staff employees, a robust wellness program, and generous PTO and holiday pay for eligible employees. Full-time employees become eligible for benefits on the date hire, with a benefits offering that includes medical, dental, vision, life, AD&D, EAP, STD, and LTD. Also available are voluntary income protection benefits such as supplemental life, accident, critical illness, and hospital indemnity insurances, as well as a 401(k)-retirement plan with a company match. In addition, the firm has programs that may provide for educational assistance, free or discounted legal services, and opportunities through the Holland & Hart Foundation, which is a non-profit organization dedicated to creating volunteer opportunities for lawyers, staff, families, and friends of Holland & Hart LLP. Part-time employees may have access to some of these benefits, which may be on a pro-rated basis., Remote or Hybrid United States 117K-158K Annually Senior level 117K-158K Annually Senior level Cloud * Fintech * Software * Business Intelligence * Consulting * Financial Services Leads Procore consulting engagements by translating client business needs into requirements, architecting and implementing solutions, designing quality processes, reviewing testing and budgets, improving workflows, supporting sales, and mentoring engineering and consulting teams. The role serves as a Procore subject matter expert, oversees quality management and SDLC methodologies, develops service offerings, and drives client satisfaction and team growth. Top Skills: ProcoreSoftware Development Life Cycle (Sdlc) PNC Bank, 41K-83K Annually Mid level 41K-83K Annually Mid level Machine Learning * Payments * Security * Software * Financial Services Provides enterprise technology support through phone, ticketing, and potentially chat channels. Troubleshoots hardware, software, network, access, and application issues; manages incidents and escalations; documents resolutions in ServiceNow or similar ITSM tools; analyzes trends and operations data; supports knowledge management, training, process improvement, and automation; and coaches junior analysts while maintaining customer service, security, and confidentiality standards., 86K-173K Annually Senior level 86K-173K Annually Senior level Machine Learning * Payments * Security * Software * Financial Services Leads the design, automation, deployment, monitoring, and security of Azure cloud infrastructure. Builds Infrastructure as Code with Terraform, Bicep, or ARM templates; manages CI/CD pipelines through Azure DevOps and GitHub; and implements monitoring, logging, alerting, incident response, patching, and vulnerability management. Collaborates with engineering, development, architecture, security, and incident management teams to improve system reliability, scalability, performance, and cost efficiency. Top Skills: Arm TemplatesAzureAzure DevopsAzure MonitorBashBicepCi/CdElastic StackElk StackGithub ActionsGithub EnterpriseInfrastructure As CodeKubernetesPowershellTerraform

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.builtincolorado.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah · World Congress 2025

10:42 min

Essential soft skills and evaluating security candidates

Kurt Eder · LIVE

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

Videos

See all

Related articles

See all