- Company Name
- WorkForce Unlimited
- Job Title
- Cyber Security Analyst
- Job Description
-
Job Title: Cyber Security Analyst
Role Summary:
Independent specialist responsible for managing third‑party vulnerability data, executing scans with proprietary and commercial tools, and collaborating with IT teams to prioritize and mitigate security risks. Generates metrics, reports, and recommendations to strengthen overall security posture.
Expectations:
- Deliver timely vulnerability assessments and remediation plans.
- Proactively identify mass‑mitigation opportunities and AI‑driven improvements.
- Communicate risk findings clearly to cross‑functional stakeholders.
- Maintain up‑to‑date knowledge of security frameworks, tools, and emerging threats.
Key Responsibilities:
- Import and manage vulnerability data in the vulnerability management platform.
- Configure and schedule scans with tools such as Nessus, Nmap, ZAP, BurpSuite, Invicti, Nuclei.
- Evaluate vulnerabilities, prioritize remediation based on risk and time‑to‑resolve thresholds.
- Escalate critical findings and coordinate with relevant teams.
- Collect, analyze, and report departmental KPIs and metrics.
- Review project scopes to recommend security benchmarks and hardening standards (CIS, STIGs).
- Optimize alert rules, policies, and tool integrations.
- Integrate logs and large datasets from WAFs, SIEMs, and EDR/XDR systems into existing security workflows.
- Identify and prototype AI applications to enhance vulnerability management processes.
Required Skills:
- Deep knowledge of HTTP, PKI, digital signatures, encryption, SMTP, DNS, CWEs, CVEs, and security frameworks.
- Proficiency with vulnerability scanning tools (Nessus, Nmap, ZAP, BurpSuite, Invicti, Nuclei).
- Experience with web application scanning, WAFs, container security.
- Familiarity with CIS Benchmarks, STIGs, and hardening standards.
- Understanding of authentication/identity protocols (SAML, Kerberos, OAuth, OIDC, LDAP).
- Scripting in PowerShell and Python; automation in CI/CD pipelines (Jenkins).
- Experience onboarding logs into Splunk, using Azure Event Hubs, Kafka, syslog.
- Knowledge of EDR/XDR tools (Microsoft Sentinel, Defender, CrowdStrike).
- Strong analytical, troubleshooting, documentation, and communication abilities.
Required Education & Certifications:
- Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or related field preferred (not mandatory).
- Relevant certifications such as CompTIA Security+, CEH, CISSP, or equivalent security credentials are advantageous.