Junior Information Security Analyst / Cybersecurity Specialist
Role details
Job location
Tech stack
Job description
You will be an integral part of an IT security team supporting the operations, data governance, and endpoint security of a key public agency. In this role, you will assist with all aspects of a primarily Microsoft technical stack, supporting installation and management of the MS 365 suite and EDR (Endpoint Detection & Response) software. This position will also help conduct Third-Party Risk Management (TPRM) assessments. This is an excellent opportunity for a developing specialist to work across data protection platforms, security operations, and compliance frameworks in a supportive team environment., * Assist with multiple phases of Microsoft products, including Data Loss Prevention (DLP) implementations, ensuring that data protection policies are defined and technically enforced across the environment. Use discovery tools to identify PII/PCI in unstructured data.
- Assist with the technical optimization of CrowdStrike to help achieve 100% endpoint coverage. Monitor, identify, and work with CrowdStrike alerts to resolve system detections.
- Support MS 365 (Azure) accounts as well as Defender and Microsoft OS implementations.
- Support risk assessments required with NIST and TSA audit standards.
- Extend security operations by identifying resiliency controls and crafting realistic templates to be used in employee phishing simulations.
- Help map technical controls to audit requirements, utilizing a foundational familiarity with compliance frameworks like PCI DSS.
- Maintain detailed records of security incidents, risk assessments, and remediation efforts. Prepare accurate summaries and updates for management.
Requirements
Do you have experience in Writing skills?, Do you have a Bachelor's degree?, * Ability to communicate effectively both orally and in writing.
- Ability to prepare clear, accurate and informative reports containing findings, conclusions, and recommendations.
- Ability to select and apply established practices, theories, techniques, and methodologies to the problems encountered.
- Ability to present orally and discuss complex matters in a clear and convincing manner.
- Ability to provide sound advice, assistance, and instructions.
- Ability to understand the roles and responsibilities of various levels of management.
- Ability to gather, assemble, correlate, and analyze facts and draw conclusions.
- Ability to organize assigned work.
- Ability to develop effective work methods and work independently.
- Ability to read, write, speak, understand, or communicate in English sufficiently to perform the duties of this position.
- Ability to understand the problems, procedures and objectives of the Client's IT projects.
- Ability to work as a team or alone on complex Information Technology projects and initiatives.
- Foundational knowledge of Microsoft Purview and DLP tools for data discovery.
- Basic proficiency or hands-on familiarity with CrowdStrike Falcon administration, alert triage, and security automation concepts.
- Understanding of how to evaluate vendor security postures (SOC2/ISO reports) and perform baseline risk assessments.
- Basic familiarity with PCI DSS v4.0.1 and mapping controls to audit standards.
Education:
- Bachelor's degree in computer science or information security preferred. Relevant experience in lieu of a degree may be considered.
Applicable Certifications:
- Microsoft Certified:
- Security Operations Analyst Associate
- Azure Fundamentals
- Security, Compliance, and Identity Fundamentals
- CompTIA Security +
- CompTIA Network +
- CompTIA Cybersecurity Analyst (CySA+) certification
- CompTIA PenTest+
Additional Preferred Certifications:
- Certified Information Systems Security Professional
- Fortinet Certified Professional Network Security
- Cisco CCNP Security
- Microsoft Certified: Security Operations Analyst Associate
Experience:
- Minimum of 2 years of experience in an IT security operations, or data compliance role
Physical Requirements:
- Ability to work indoors at a desk for extended periods of time.
- Ability to work outdoors traveling to other job sites as needed.
- Ability to lift and carry 10-20 pounds as needed.
- Listen, talk, interact, and effectively communicate with other employees, supervisors and outside contacts.
- Standing and/or sitting for extended periods of time
- Use of phone and/or computer for extended periods of time
- Bending, reaching, and twisting in the performance of daily job functions
- Seeing, reading, writing, utilizing a computer keyboard, mouse and other computer implements
- Ability to work a set schedule consistent with job and/or business needs.
- Persons with mental or physical disabilities are eligible as long as they can perform the essential functions of the job after reasonable accommodation is made to their known limitations. If accommodation cannot be made because it would cause the employer undue hardship, such persons may not be eligible.
Must be able to pass FAA security background check
Hybrid Position: 2 days remote, 3 days in office.
Job Type: Full-time
Benefits & conditions
Pulled from the full job description
- Professional development assistance
- 401(k)
- Health insurance
- 401(k) matching
- Paid time off
- Vision insurance
- Health savings account, * 401(k)
- 401(k) matching
- Dental insurance
- Health insurance
- Health savings account
- Life insurance
- Paid time off
- Professional development assistance
- Vision insurance, * 401(k)
- 401(k) matching
- Dental insurance
- Health insurance
- Health savings account
- Life insurance
- Paid time off
- Professional development assistance
- Vision insurance
Application Question(s):
- What is 4+2.5? Nothing funny here. Just a simple math problem.
- This is a hybrid position. Is this clear?