
Information Security Analyst III
Posted 21 hours ago

Posted 21 hours ago
This is a fully remote position, open to applicants in Alabama, +31 more states.
• Act as the senior lead and primary escalation point for the Security Operations Center team.
• Oversee a vast and complex enterprise technology ecosystem.
• Identify, analyze, investigate, and respond to information security events and incidents.
• Manage incidents in accordance with SNHU's Information Security Incident Response Plan.
• Lead the investigation of complex or high-severity threats and incidents.
• Define and approve incident containment and eradication activities, which include endpoint isolation, malware remediation, forensic analysis, malware analysis, interviews, and network traffic analysis.
• Collaborate across ITS and SNHU business units for triage, containment, remediation, and technical implementation efforts.
• Analyze digital evidence to identify indicators of compromise, adversary activities, root causes, timelines, and attack vectors.
• Create SIEM alerts, reports, and dashboards.
• Develop and maintain monitoring content for academic integrity investigations, financial aid fraud, and system/network administration.
• Analyze, implement, and approve the tuning of alert content and security tools.
• Keep track of emerging threat intelligence.
• Serve as the technical lead for Security Operations within ITS and enterprise-wide projects.
• Formulate strategies and solutions to remediate or mitigate security risks.
• Identify, prioritize, and onboard relevant log data.
• Create and implement logging baselines across operating systems, applications, networks, cloud resources, and security tools.
• Develop and implement log data pipelines to meet retention needs and enhance SIEM efficiency.
• Implement, configure, deploy, and manage security operations tools including Splunk, Cribl, Halcyon, Microsoft Defender XDR, and Tenable.
• Create and maintain automation scripts and tools.
• Enforce compliance standards for vulnerability remediation.
• Review false-positive detections.
• Conduct software vulnerability risk analyses and prioritize remediation efforts.
• Provide technical assistance for vulnerability remediation.
• Report Security Operations metrics to management.
• Document SOPs, incidents, and actions taken during incidents.
• Communicate with stakeholders at all organizational levels in layman's terms.
• Offer customer support and escalate potential issues as necessary.
• Complete other assigned duties.
• A minimum of 5 years of relevant or specialized experience in cybersecurity.
• At least 4 years of experience working in a security operations center, cybersecurity operations center, or a cybersecurity incident response team.
• At least 1 year of experience in a mid to senior-level role in this area.
• Bachelor's degree in cybersecurity, information technology, data analytics, information assurance, computer science, or a related field.
• Equivalent experience may be accepted in lieu of a degree.
• Professional certifications such as ISC2 CISSP, ISACA CISM or CISA, CompTIA CySA+, Security+, Network+, Microsoft AZ-900, SC-100, SC-200, SANS GIAC certifications, or EC Council CEH, CPENT, and CIH.
• Proficient in collecting, organizing, and analyzing data from firewalls, vulnerability scanners, Windows/Linux operating systems, software application logs, Azure cloud resources, email platforms, EDR tools, and other enterprise security monitoring platforms.
• Experience in implementing, writing, deploying, and maintaining scripts for security operations automation.
• Must reside in and work from one of the approved states.
• A reliable internet connection and a dedicated, properly equipped workspace free from distractions are required.
• Ability to work extended hours and/or non-business hours during crisis situations and contingency operations.
• High-quality, low-deductible medical insurance.
• Low to no-cost dental and vision plans.
• 5 weeks of paid time off.
• Nearly a dozen paid holidays.
• Employer-funded retirement plan.
• Free tuition program.
• Parental leave.
• Resources for mental health and wellbeing.
• Remote work from an approved state.
• A reliable internet connection and a dedicated, properly equipped workspace are required for remote employees.
Stefanini Brasil
Stefanini Brasil
Hitss Brasil
Get handpicked remote jobs straight to your inbox weekly.