- Company Name
- Aspira
- Job Title
- Security Analyst
- Job Description
-
**Job Title**
Security Analyst
**Role Summary**
Responsible for monitoring, detecting, and responding to security incidents across AWS and on‑premises environments. Utilizes AWS native tools (CloudWatch, CloudTrail, GuardDuty, Security Hub) and SIEM platforms (Rapid7 InsightIDR, LogRhythm, Splunk) to correlate events, establish detection rules, and conduct log analysis. Works closely with IT, DevOps, and Network teams to remediate vulnerabilities and maintain compliance with PCI, SOC, NIST, and CIS standards.
**Expectations**
- Deliver real‑time threat detection and incident response with minimal escalation.
- Maintain accurate incident documentation and compliance evidence.
- Continuously improve security tooling and processes.
- Automate monitoring, alerting, and remediation where possible.
**Key Responsibilities**
- Monitor and correlate events in AWS CloudWatch, CloudTrail, GuardDuty, Security Hub, and SIEMs.
- Develop and tune detection rules, alerts, dashboards, and runbooks.
- Perform Tier 1/Tier 2 alert triage and coordinate escalation.
- Investigate indicators of compromise, assess impact, and recommend containment actions.
- Collaborate with IT Ops, Network Engineering, and DevOps on remediation and hardening.
- Support compliance initiatives: maintain evidence, document incidents, and assist audit requests.
- Implement zero‑trust controls (MFA, IAM policies, endpoint protection) under direction.
- Script and automate log ingestion, enrichment, and reporting using Python, PowerShell, Bash, or Terraform.
- Track and report on security KPIs: SIEM coverage, response times, remediation metrics.
**Required Skills**
- 5+ years in Security Operations, Threat Monitoring, or Incident Response.
- In‑depth experience with AWS security/monitoring services (CloudWatch, CloudTrail, GuardDuty, Security Hub).
- Hands‑on SIEM expertise: Rapid7 InsightIDR, LogRhythm, or Splunk.
- Knowledge of NIST 800‑53, CIS Benchmarks, PCI DSS, SOC frameworks.
- Strong networking fundamentals (TCP/IP, firewalls, VPNs).
- Operating‑system hardening for Windows and Linux.
- Analytical log analysis, event correlation, packet capture skills.
- Scripting/automation: Python, PowerShell, Bash; Terraform for IaC.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related field (preferred).
- Relevant certifications: CompTIA Security+, GSEC, AWS Security Specialty, CEH, or equivalent (preferred).