Sr. Security Analyst - I.T.

Baker Group
Ankeny, United States of America
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior

Job location

Ankeny, United States of America

Tech stack

Amazon Web Services (AWS)
Azure
Cloud Computing Security
Complex Networks
CompTIA Security+
Computer Security
Information Systems
Identity and Access Management
IT Management
Cloud Services
Security Information and Event Management
Firewalls (Computer Science)
Information Technology
CIS Benchmarks

Job description

The Senior Security Analyst - IT serves as a technical leader within Baker Group's cybersecurity function, responsible for advanced threat detection, complex incident response, security architecture input, and the maturation of the organization's security program. This role leads investigations into significant security events, drives improvements to controls and processes, mentors junior analysts and acts as a trusted advisor to IT leadership and business stakeholders on risk-based security decisions. This is an individual contributor role with technical mentorship responsibilities. Performs related work as required., The following duties are typical for this job. These are not to be construed as exclusive or all inclusive. Other duties may be required and assigned.

  • Contribute to complex incident response investigations, including containment, eradication, recovery and post-incident reporting.
  • Design, tune, and continuously improve detection content across SIEM, EDR and other security platforms.
  • Conduct threat hunting based on threat intelligence, attacker tradecraft and environmental telemetry.
  • Provide security architecture input on new systems, applications, cloud service and infrastructure changes.
  • Provide strategic direction for the vulnerability management program - risk-based prioritization and exception review.
  • Serve as a senior point of contact for internal and external audit engagements; review evidence, address complex control inquiries and support assessors.
  • Contribute to the development and maintenance of security policies, standards and procedures aligned to NIST CSF, CIS Controls, and applicable regulatory frameworks.
  • Oversee third-party/vendor risk assessment processes and advise on remediation of identified vendor risks.
  • Mentor and develop Security Analyst I and II team members through coaching, technical reviews and structured knowledge transfer.
  • Support tabletop exercises, incident response drills and disaster recovery testing.
  • Evaluate and recommend new security technologies and process improvements; contribute to implementation of significant changes.
  • Translate technical security risks into business language for technical and non-technical audiences.
  • Stay current on emerging threats, vulnerabilities, and security best practices through ongoing training, conferences and professional development opportunities, sharing knowledge across the team.

Requirements

  • Bachelor's degree in computer science, cybersecurity, information systems, or related field, or equivalent relevant experience required
  • Minimum of five years' experience in information security, with demonstrated progression of responsibility
  • Hands-on experience with incident response across the full lifecycle (detection, containment, eradication, recovery)
  • Deep working knowledge across multiple of the following: SIEM, EDR, firewalls, identity and access management and cloud security (Azure and/or AWS)
  • Working knowledge of NIST CSF or CIS Controls, or SOC2, including practical experience applying controls in a production environment

CERTIFICATES, LICENSES, REGISTRATIONS

  • CompTIA Security+ ,preferred
  • CISSP, preferred
  • CISM, CISA, GCIH, GCIA or GSEC, preferred

MENTAL AND PHYSICAL COMPETENCIES REQUIRED TO PERFORM ESSENTAL FUNCTIONS

  • Demonstrated ability to identify, prioritize, and mitigate complex network and application vulnerabilities, along with the capacity to clearly explain risk and prevention strategies to technical and non-technical audiences
  • Skilled in risk-based decision making, weighing security needs against operational and business impact
  • Excellent verbal and written communication skills, with proven ability to influence without authority
  • Ability to lead under pressure during active security incidents
  • Strong problem-solving skills with a methodical, evidence-based approach to investigation
  • Demonstrated coaching and mentorship ability
  • Passion for technology and strong desire to work with new technologies

ENVIRONMENTAL ADAPTABILITY

  • Prolonged periods of sitting at a desk and working on a computer
  • Must be able to lift 10 pounds occasionally
  • May have occasional visits to a job site which would require periods of standing, walking and/or climbing stairs

About the company

Baker Group is an Equal Opportunity Employer. In compliance with the Americans with Disabilities Act, Baker Group will consider reasonable accommodations for qualified individuals with disabilities and encourage prospective employees and incumbents to discuss potential accommodations with the Employer.

Apply for this position