Associate Security Analyst - Remote

Hornblower
United States
about 2 months ago

Role details

Contract type
Internship / Graduate position
Employment type
Full-time (> 32 hours)
Experience level
Starter
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Amazon Web Services Microsoft Azure Bash Shell Cyber Security Computer Networks Linux Domain Name System (DNS) Hypertext Transfer Protocols (HTTP) Intrusion Detection Systems Virtual Private Networks (VPN) Python (Programming Language)
+15 more
Log Analysis Windows PowerShell Phishing Runbook Security Information and Event Management TCP/IP Scripting Google Cloud Cloud Platform System Mitre Att&ck Malware Information Technology Cybercrime Microsoft Sentinel Vulnerability Analysis

Job description

company that specializes in the operation and maintenance of government and commercial vessels. Additionally, Anchor Operating System, LLC, a Hornblower Group subsidiary and independent entity, provides reservation, ticketing and website integration services for clients in the transportation, tourism and entertainment industries. Today, Hornblower Group’s global portfolio covers over 10 countries, over 50 U.S. cities and serves more than 20 million guests annually. Headquartered in Orlando, Florida, Hornblower Group’s additional corporate offices reside in San Francisco, California; Boston, Massachusetts; Chicago, Illinois; London, United Kingdom; New York, New York; Dublin, Ireland; and across Ontario, Canada. For more information, visit hornblowercorp.com., Cybersecurity at Hornblower is responsible for protecting the business. We do so by establishing, maintaining and enforcing policies to meet and exceed industry standards for security and compliance. We are seeking a motivated Junior Security Analyst to join our information security team. In this role, you will help defend our organization against cyber threats by monitoring security tools, investigating alerts, and supporting incident response efforts. This is an excellent opportunity for an early-career professional to develop hands-on experience across a broad range of security disciplines while working alongside experienced practitioners., * Monitor security information and event management (SIEM) platforms, intrusion detection systems, and other security tools for suspicious activity.

  • Triage and investigate security alerts, escalating confirmed incidents to senior analysts according to established playbooks.
  • Assist in incident response activities, including evidence collection, containment, and post-incident documentation.
  • Conduct regular vulnerability scans and help track remediation efforts with system owners.
  • Review logs from firewalls, endpoint protection, identity providers, and cloud platforms to identify anomalies.
  • Support phishing investigations, including analysis of suspicious emails, URLs, and attachments in a sandboxed environment.
  • Contributes to the maintenance of security documentation, runbooks, and knowledge base articles.
  • Assist with user access reviews, security awareness initiatives, and routine compliance tasks.
  • Stay current on emerging threats, vulnerabilities, and attacker techniques, sharing relevant findings with the team.

Requirements

Do you have experience in Windows?, Do you have a Bachelor’s degree?, * Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field - or equivalent practical experience (internships, home labs, military, or self-directed study).

  • Foundational understanding of networking concepts (TCP/IP, DNS, HTTP/S, VPNs) and common operating systems (Windows and Linux).
  • Familiarity with core security concepts: the CIA triad, common attack types (phishing, malware, brute force, privilege escalation), and basic defensive controls.
  • Hands-on exposure to SIEM platforms (Microsoft Sentinel, Elastic, etc.), EDR tools, or vulnerability scanners.
  • Basic scripting ability in Python, PowerShell, or Bash for log parsing or task automation.
  • Familiarity with frameworks such as MITRE ATT&CK, NIST CSF, or the Cyber Kill Chain.
  • Experience with cloud environments (AWS, Azure, or Google Cloud) and their native security services
  • Strong analytical and problem-solving skills, with attention to detail.
  • Clear written and verbal communication, including the ability to document findings for both technical and non-technical audiences.
  • Eagerness to learn and a methodical, curious approach to investigation.

About the company

Hornblower Group is a global leader in experience and transportation. Spanning a 100-year history, Hornblower Group’s portfolio of international offerings includes water- and land-based experiences and ferry and transportation services. City Experiences, Hornblower Group’s premier experience division, offers dining and sightseeing cruises and walking and food tours through the City Cruises, Walks, and Devour brands. City Ferry, part of Hornblower Group’s Ferry and Transportation Division, is the largest private operator of high-speed passenger and vehicle ferries in the United States, carrying more than 10 million passengers annually and operating services including NYC Ferry, Puerto Rico Ferry, and other regional ferry systems. Hornblower Group’s subsidiaries include Hornblower Marine, which provides vessel outhaul and maintenance services at Bridgeport Boatworks in Bridgeport, Connecticut, and Seaward Services, Inc., a full-service shipping, waterfront logistics and management

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · WWC 2022

Videos

See all

Related articles

See all