Cybersecurity Support Analyst
Listed on 2026-07-01
-
IT/Tech
Cybersecurity, IT Support, Network Security, Systems Administrator
Location: New York
Cybersecurity Support Analyst I
Build a long-term career in cybersecurity while contributing immediately through your technical support, endpoint, Microsoft
365, Active Directory, email, networking, or security support experience.
The Security Operations Support Analyst works onsite in Brooklyn, NY and assists with endpoint security, email security, vulnerability remediation, security alert review, and incident documentation. The role collaborates with security, infrastructure, desktop, application, and business teams to investigate suspicious activity, coordinate remediation, and support operational security controls. Over time, the analyst will expand into deeper cybersecurity operations responsibilities, including EDR investigation, vulnerability management, SIEM/log review, phishing/BEC investigation, incident response, and security metrics reporting.
IdealCandidate Profile
- An early‑career cybersecurity professional looking to deepen their security operations experience.
- An experienced Level 2 desktop, field services, endpoint, or technical support professional ready to move into security.
- Curious, resourceful, coachable, and comfortable learning new tools.
- Enjoys troubleshooting, documenting findings, working with users and IT teams, and researching unfamiliar issues.
- Review, triage, and document security alerts from endpoint, email, vulnerability, and monitoring tools.
- Assist with endpoint investigations involving malware concerns, suspicious activity, unauthorized access, or account compromise.
- Support phishing and suspicious email investigations, including message trace, header review, user follow‑up, and remediation tracking.
- Help coordinate vulnerability remediation with desktop, infrastructure, and application teams.
- Support patching, endpoint remediation, access review, and secure configuration activities.
- Assist with investigation and documentation of incidents, technical findings, troubleshooting steps, and response actions.
- Learn and support security tools such as EDR, SIEM, vulnerability scanning platforms, Microsoft Defender, Exchange Online, and related technologies.
- Work with IT teams to address security gaps and operational risks.
- Maintain accurate tickets, incident notes, reports, and process documentation.
- Participate in security improvement activities, training, and mentoring.
- Experience in one or more of the following areas:
- Security operations, SOC support, cybersecurity support, incident response support, vulnerability remediation, or endpoint/email security.
- Desktop support, field services, endpoint support, systems support, technical support, or a similar hands‑on IT support role.
- Strong troubleshooting skills across Windows endpoints, user access, business applications, and common IT issues.
- Experience with Active Directory user, group, password, permission, and access support.
- Familiarity with Microsoft 365, Exchange Online, email troubleshooting, mailbox support, or user support.
- Basic networking knowledge, including TCP/IP, DNS, DHCP, VPN, firewalls, and subnetting.
- Exposure to endpoint protection, antivirus, EDR, phishing tickets, security alerts, patching, or vulnerability remediation.
- Strong interest in cybersecurity operations and willingness to continue building security skills.
- Strong documentation, communication, follow‑up, and problem‑solving skills.
- Ability to research unfamiliar issues, learn quickly, and work independently when needed.
- Positive attitude, adaptability, resourcefulness, and willingness to be coached.
- CompTIA Security+, Network+, CySA+, A+, ISC2 CC, or similar certification.
- Cybersecurity degree, certificate program, bootcamp, or active security training.
- Exposure to Crowd Strike Falcon, Microsoft Defender, Sentinel, Splunk, Rapid7, Tenable, Qualys, or similar security tools.
- Experience investigating phishing emails, suspicious links, malware alerts, compromised accounts, or security tickets.
- Experience with Exchange Online message trace, mail flow rules, Microsoft Defender for Office 365, or similar email security tools.
- Experience with Intune, SCCM, endpoint management, device…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).