Match score not available

Information Security Analyst

Remote: 
Full Remote
Contract: 
Salary: 
90 - 130K yearly
Experience: 
Senior (5-10 years)
Work from: 

Offer summary

Qualifications:

Bachelor's degree in computer science or related field, or equivalent experience, Minimum two years IT experience, six years if non-degreed, Knowledge of vulnerability and threat management concepts, Experience with network monitoring and incident response, Preferred knowledge of cloud security platforms like GCP or AWS.

Key responsabilities:

  • Identify and mitigate threats and vulnerabilities
  • Conduct security testing before implementing new assets
  • Manage and respond to security incidents
  • Work with IT teams on risk remediation
  • Stay updated with the evolving threat landscape
FFF Enterprises logo
FFF Enterprises SME https://www.FFFenterprises.com/
501 - 1000 Employees
See more FFF Enterprises offers

Job description

Logo Jobgether

Your missions

Job Details
Job Location:    Temecula, CA
Salary Range:    $90,000.00 - $130,000.00 Salary
Description

Position Summary

Information security analysts are responsible for improving the overall security posture of the organization. They will identify, assess, and mitigate threats and vulnerabilities across our systems and networks to enhance our cybersecurity posture. They will evaluate, test and document security controls, and respond to incidents as needed. They will work closely with the CISO, IT team members, and system owners to remediate risk while ensuring the business is able to innovate.

Essential Functions and Duties

Threat and Vulnerability Management

  • Perform security standards testing against our current environment as well as before implementation of new assets and applications to ensure security standards are met
  • Identify potential weaknesses and vulnerabilities on assets (i.e., end points, applications, users, and cloud), validate them via exploitation, and report their findings
  • Work closely with the IT Infrastructure and Applications teams to prioritize and remediate vulnerabilities and weaknesses
  • Stay current with the evolving threat landscape

Security Event and Incident Response

  • Conduct network monitoring and intrusion detection analysis as well as log-based and endpoint-based threat detection to detect and protect against threats
  • Correlate network, cloud and endpoint activity across environments to identify attacks and unauthorized use
  • Research emerging threats and vulnerabilities to aid in the identification of incidents
  • Work with both external and internal incident response teammates to manage, contain and report security incidents. This may include involvement outside of regular work hours
  • Evaluate the effectiveness of current MDR solutions and propose improvements

General Duties

  • Adheres specifically to all company policies and procedures, Federal and State regulations and laws. 
  • Display dedication to position responsibilities and achieve assigned goals and objectives.
  • Represent the Company in a professional manner and appearance at all times.
  • Understand and internalize the Company’s purpose; Display loyalty to the Company and its organizational values.
  • Display enthusiasm and dedication to learning how to be more effective on the job and share knowledge with others.
  • Work effectively with co-workers, internal and external customers and others by sharing ideas in a constructive and positive manner; listen to and objectively consider ideas and suggestions from others; keep commitments; keep others informed of work progress, timetables, and issues; address problems and issues constructively to find mutually acceptable and practical business solutions; address others by name, title, or other respectful identifier, and; respect the diversity of our work force in actions, words, and deeds.
  • Comply with the policies and procedures stated in the Injury and Illness Prevention Program by always working in a safe manner and immediately reporting any injury, safety hazard, or program violation.
  • Ensure conduct is consistent with all Compliance Program Policies and procedures when engaging in any activity on behalf of the company. Immediately report any concerns or violations.
  • Other duties as assigned.
  • Up to 10% travel required
Qualifications

Education, Knowledge, Skills and Experience

Required Education:

  • Bachelor’s degree in computer science or a related field of study, or four (4) years of relevant experience in lieu of degree. 

Required Knowledge:

  • Knowledge of concepts, practices and procedures related to Vulnerability and Threat management including risk analysis
  • Knowledge of concepts, practices and procedures related to penetration testing
  • General knowledge of securing multiple computing platforms with a focus on Windows and Linux for both cloud and on-premises
  • General knowledge of concepts, practices and procedures related to Incident Response including expertise in system monitoring and analysis
  • Experience with change and project management

Preferred Knowledge:

  • General knowledge of concepts, practices and procedures related to cloud platform security; Google Cloud Platform (preferred), Amazon Web Services, or Microsoft Azure
  • Experience working with DevOps and application teams
  • Knowledge of serverless and container-based solutions
  • Experience with network and web application and API penetration testing
  • Experience translating IT risk to business risk
  • Experience working with SIEM systems, threat intelligence platforms, security automation and orchestration solutions, and other network and system monitoring tools
  • Experience with security compliance audits such as HITRUST, ISO27001, SOC2, or PCI

Required Experience:

  • Minimum two (2) years’ experience [six (6) for non-degreed candidates] in the Information Technology field outside of helpdesk; or combination of five (5) years [six (6) for non-degreed candidates] of experience Information Technology, including helpdesk. 

Preferred Experience:

  • Two (2) or more years’ experience in cybersecurity.

Required Skills:

  • Must have strong organizational skills.
  • Must have a detail orientation and the proven ability to prioritize work.
  • Must have effective verbal and written communication skills.
  • Must have the ability to work with limited supervision and with a team.
  • Must have effective decision-making abilities.
  • Must leverage both strategic and tactical thinking.
  • Must work calmly under pressure even with tight deadlines.
  • Must act with integrity, take pride in one’s work, and seek to excel.

Preferred Professional Certifications:

  • Comptia Security+, Network+, or PentTest+
  • SANS GSEC or GISF
  • ISACA Cybersecurity Fundamentals
  • ISC2 Associate or SSCP
  • Any cloud certifications

Physical requirements

Vision, hearing, speech, movements requiring the use of wrists, hands and/or fingers. Must have the ability to view a computer screen for long periods and the ability to sit for extended periods. Must have the ability to work the hours and days required to complete the essential functions of the position, as scheduled.  The employee occasionally lifts up to 20 lbs. and occasionally kneels and bends. Must have the ability to travel occasionally. Working condition include normal office setting.

Mental Demands

Learning, thinking, concentration and the ability to work under pressure, particularly during busy times.  Must be able to pay close attention to detail and be able to work as a member of a team to ensure excellent customer service.  Must have the ability to interact effectively with co-workers and customers, and exercise self-control and diplomacy in customer and employee relations’ situations. Must have the ability to exercise discretion as well as appropriate judgments when necessary. Must be proactive in finding solutions.

Direct Reports

No

EEO/AAP Statement

FFF Enterprises/ NuFactor is an equal opportunity employer to all and prohibits discrimination and harassment based on the following characteristics: race, color, caste, religion, religious creed (including religious dress and grooming practices), national origin, ancestry, citizenship, physical or mental disability, medical condition (including cancer and genetic conditions), genetic information, marital status, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), gender, gender identity, gender expression, age (40 years and over), sexual orientation, veteran or military status, medical leave or other types of protected leave (requesting or approved for leave under the Family and Medical Leave Act or any state protected leaves), domestic violence victim status, political affiliation, reproductive health decision-making, and any other characteristic protected by state or federal anti-discrimination law covering employment. These categories are defined according to Government Code section 12920. The Company prohibits unlawful discrimination based on the perception that anyone has any of those characteristics or is associated with a person who has or is perceived as having any of those characteristics.

Required profile

Experience

Level of experience: Senior (5-10 years)
Spoken language(s):
Check out the description to know which languages are mandatory.

Soft Skills

  • Calmness Under Pressure
  • Decision Making
  • Teamwork
  • Detail Oriented
  • Organizational Skills
  • Strategic Thinking

Information Security Analyst Related jobs