Cybersecurity Analyst – Job Description Job Title: Cybersecurity Analyst
Experience: 2–6 years
Location: [Location / Remote]
Employment Type: Full-time Job Summary We are seeking a skilled Cybersecurity Analyst to monitor, detect, investigate, and respond to security threats across the organization's IT environment. The ideal candidate will have hands-on experience with SIEM, endpoint security, vulnerability management, incident response, and security monitoring. Key Responsibilities Monitor security alerts and events using SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or similar tools. Investigate and respond to security incidents, alerts, and potential threats. Perform security event analysis, threat detection, and incident triage. Analyze logs from firewalls, endpoints, servers, applications, network devices, and cloud environments. Conduct incident investigations and perform root-cause analysis. Create and maintain incident reports, investigation documentation, and security metrics. Perform vulnerability assessments and coordinate remediation of identified vulnerabilities. Monitor endpoint security solutions such as Microsoft Defender, CrowdStrike, SentinelOne, or similar platforms. Assist with threat hunting and identification of Indicators of Compromise (IOCs). Support phishing investigations, malware analysis, and suspicious-user activity investigations. Implement and monitor security controls based on organizational security policies. Collaborate with IT, network, cloud, application, and infrastructure teams during security incidents. Participate in security audits, compliance activities, and risk assessments. Stay updated on emerging cyber threats, vulnerabilities, attack techniques, and security trends. Required Technical Skills Strong understanding of cybersecurity fundamentals. Hands-on experience with SIEM tools such as: Microsoft Sentinel Splunk IBM QRadar Knowledge of Security Operations Center (SOC) processes. Experience with Incident Response and Threat Detection. Good understanding of networking concepts: TCP/IP DNS HTTP/HTTPS VPN Firewalls Proxies Knowledge of Windows and Linux security. Experience analyzing security logs and events. Knowledge of MITRE Telecommunication&CK, IOC, TTPs, and threat intelligence. Familiarity with vulnerability-management tools such as Tenable, Qualys, or Rapid7. Basic scripting knowledge in Python, PowerShell, or Bash is preferred. Understanding of endpoint detection and response (EDR) technologies. Cloud Security Basic to intermediate knowledge of Azure, AWS, or GCP security. Experience monitoring cloud security events and logs. Knowledge of Microsoft Entra ID/Azure AD, IAM, MFA, and RBAC. Familiarity with cloud security monitoring and security best practices. Preferred Certifications CompTIA Security+ CompTIA CySA+ Certified SOC Analyst (CSA) CEH GIAC certifications Microsoft SC-200 CISSP – preferred for senior-level roles Soft Skills Strong analytical and problem-solving skills. Good communication and documentation skills. Ability to work effectively under pressure during security incidents. Strong attention to detail. Ability to work in a 24×7 SOC environment when required. Typical Tools SIEM: Microsoft Sentinel, Splunk, QRadar
EDR: Microsoft Defender, CrowdStrike, SentinelOne
Vulnerability Management: Qualys, Tenable, Rapid7
Network Security: Palo Alto, Fortinet, Cisco
Threat Intelligence: VirusTotal, MISP, Recorded Future
Cloud: Azure, AWS, Microsoft Entra ID
Ticketing: ServiceNow, Jira Experience Levels Junior Cybersecurity Analyst (1–3 years):
Focus on alert monitoring, incident triage, log analysis, ticket management, and basic investigation. Cybersecurity Analyst (3–6 years):
Focus on incident investigation, threat hunting, vulnerability management, SIEM administration, and security improvements. Senior Cybersecurity Analyst (6+ years):
Focus on advanced threat hunting, incident response leadership, detection engineering, security architecture, automation, and mentoring analysts.