Cybersecurity Analyst
Listed on 2026-07-01
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Cybersecurity Analyst About the Role
We are hiring a Cybersecurity Analyst to own the day‑to‑day security monitoring function and produce the evidence required to achieve and maintain our cybersecurity certification. This operational core role manages alert triage across our cybersecurity tool stack, coordinates with our managed SOC partner, documents security events, and keeps our monitoring and incident response activities continuously evidenced and ready for review.
This hands‑on, high‑accountability role reports directly to the CISO. You will work closely with our Info Sec Engineer, Compliance Program Manager, and our managed security operations partner. You will help set up and monitor our security tool stack, spanning endpoint protection, network detection, secure web access, application control, and identity management. You establish the monitoring cadence that keeps our security posture visible and our compliance evidence current.
TheImmediate Mission
- Take ownership of daily alert triage across our security tool stack, reviewing and dispositioning alerts before they age without review.
- Serve as the internal liaison to our managed SOC partner, receiving their monitoring reports, validating their outputs, and integrating their work into our compliance evidence.
- Build and maintain the incident log, ensuring every security event is captured, classified, and closed with supporting documentation.
- Produce audit log evidence demonstrating that our systems are monitored, logs are retained, and events are reviewed on a consistent schedule.
- Deliver regular monitoring reports to our compliance tracking platform, ensuring up‑to‑date evidence flows into our central repository.
- Coordinate with the Compliance Program Manager to ensure monitoring and incident response evidence is organized and ready for assessor review.
- Own daily triage of alerts from our network detection platform and other security tools, reviewing, classifying, escalating, and documenting dispositions.
- Serve as the primary internal point of contact for our managed security operations partner, receiving daily and weekly alert summaries, validating completeness, and tracking open items to closure.
- Maintain the security event log, a running record of alerts, dispositions, escalations, and outcomes that serve as core compliance evidence.
- Identify patterns in alert data and surface recurring issues to the Info Sec Engineer for remediation.
- Ensure continuous monitoring coverage is documented and demonstrable, a direct requirement of the cybersecurity framework we are certifying against.
- Own the incident log, documenting every security event from detection through closure, including timeline, classification, containment actions, and resolution.
- Coordinate with our managed security operations partner on incident triage, escalation, and post‑incident reporting, ensuring their outputs are captured and integrated into our internal records.
- Maintain the Incident Response Plan as a living document, updating it based on lessons learned and ensuring it reflects actual operational procedures.
- Produce incident response evidence for our compliance assessment, including incident logs, escalation records, containment documentation, and post‑incident reviews.
- Support the Compliance Program Manager in mapping incident documentation to the applicable compliance controls.
- Pull and organize log samples from our endpoint protection, network security, web access, application control, and identity management platforms, demonstrating that logging is active and coverage is comprehensive.
- Document log configuration, including retention settings, coverage scope, and alert thresholds, as evidence that our monitoring posture meets compliance requirements.
- Produce regular monitoring reports to our compliance tracking platform, ensuring the system reflects the current operational status.
- Coordinate with the Info Sec Engineer to ensure logging is enabled and configured correctly across all systems in scope.
- Maintain organized evidence packages, including log samples, triage records, and monitoring…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).