- Company Name
- Envestnet
- Job Title
- Security Analyst
- Job Description
-
Job title: Security Analyst
Role Summary:
Proactive Security Analyst responsible for monitoring, detecting, and responding to security incidents within a Security Operations Center (SOC). Performs vulnerability assessments, threat hunting, and automation of incident response. Supports continuous improvement of SOC processes, runbooks, and incident playbooks while collaborating with IT, development, and offensive security teams.
Expectations:
- Act as first responder to all security alerts, managing the full incident response lifecycle.
- Conduct routine vulnerability scans, prioritize findings, and coordinate remediation.
- Automate triage and response tasks using SOAR tools and participate in threat hunting and purple teaming exercises.
- Maintain accurate and up‑to‑date SOC documentation and contribute to process enhancements.
- Communicate findings and recommendations clearly to technical and non‑technical stakeholders.
Key Responsibilities:
1. Monitor SIEM, EDR, IDS/IPS, and other security tools for alerts.
2. Triage and analyze security incidents; escale to senior staff as needed.
3. Lead incident response phases: detection, analysis, containment, eradication, recovery, and post‑incident review.
4. Execute vulnerability scanning (network, application, system) and collaborate with IT/development for patching.
5. Document incident details, remediation steps, and configuration changes.
6. Update and refine SOC runbooks, playbooks, and security documentation.
7. Perform proactive threat hunting and automation of response workflows.
8. Engage in purple‑team exercises with offensive security using BAS.
9. Support security awareness training and policy compliance.
Required Skills:
- 4+ years of cybersecurity experience in SOC, incident response, or vulnerability management.
- Proficiency with SIEM platforms, EDR solutions, IDS/IPS, and vulnerability scanners.
- Knowledge of network protocols, operating systems (Windows, Linux), and attack vectors.
- Strong analytical, problem‑solving, and attention‑to‑detail abilities.
- Excellent written and verbal communication.
- Team player with ability to work independently.
- Adaptability to emerging technologies and threat landscapes.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent practical experience).
- Certifications preferred: CompTIA Security+, CySA+, or EC-Council CEH.