Information Security Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+9 more
Job description
StationMD is seeking an Information Security Analyst to serve as a core member of the Security Operations Center (SOC), responsible for monitoring, detecting, analyzing, and responding to cybersecurity threats and incidents. This role focuses on triaging security alerts, enhancing SIEM capabilities, and maintaining the organization’s security monitoring infrastructure to protect against cyber threats.
This is a fast-paced, growth-stage environment with frequently shifting priorities, and the successful candidate will be comfortable balancing multiple concurrent initiatives., * Serve as a core member of the Security Operations Center (SOC), providing real-time monitoring and alert triage coverage
- Review of security event logs and alerts from security systems and tools
- Provide an analysis of security events and investigate cybersecurity threats
- Identify and communicate threat intelligence
- Analyze, document, and escalate security events and alerts per policy
- Maintain updated knowledge of security threats, vulnerabilities, and mitigation techniques
- Enhance and customize SIEM monitoring capabilities and rule sets
- Manage and improve SIEM data collection and alerting capabilities
- Conduct regular testing and maintenance on monitoring systems
- Tune alert thresholds to reduce false positives while maintaining detection efficacy
- Regular review of security configurations, such as firewall configurations
- Review and act on vulnerability scan results (Qualys)
- Provide occasional after-hours and weekend support for security alerts and incidents
- Other duties as assigned
Requirements
Education/Certification
- Undergraduate degree in Computer Science, Cybersecurity, or related fields, * 2 years of experience in IT, Information Security, Compliance, Legal, Data Privacy, or a related industry (internship experience may be acceptable)
- General knowledge of cloud IaaS products such as AWS and Microsoft Azure
- Good troubleshooting/problem-solving skills
- Excellent writing and communication skills
- Ability to thrive in a fast-paced environment with competing priorities, * Previous experience in healthcare information security
- Working knowledge of Linux systems
- General knowledge of SIEMs, including Wazuh/ELK Stack
- Experience with vulnerability scanning tools such as Qualys
- Experience maintaining endpoint detection and response (EDR) systems
- Experience creating correlation rules for the purpose of improving security monitoring
- Familiarity with the MITRE ATT&CK framework
- Understanding of cloud security, including cloud-native logging and monitoring tools (e.g., AWS CloudTrail)
- Working knowledge of scripting languages (Python, Bash), and working with REGEX
Benefits & conditions
Commensurate with experience
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Walking Into The Era of Supply Chain Risks
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents
Data Analyst Salary in the UK
Understanding and Mitigating Common Web Vulnerabilities