
Information Security Analyst
Full Job Description
Job Summary
Monitor security alerts and incidents, responding promptly to potential threats. Conduct threat hunting, vulnerability assessments, and penetration testing to identify security weaknesses. Perform regular security audits and risk assessments. Analyze security breaches to determine root causes and implement corrective actions. Assist or lead efforts to isolate, contain, respond to, and recover from security incidents. Identify, review, prioritize, plan, coordinate, and follow up on vulnerability remediation.
Manage security alerts from the Group-Wide CSIRT team and various security tools and technologies including endpoint security, network security, IDR, DLP, and SIEM. Configure and maintain security technologies such as SIEM, endpoint security, and intrusion detection/prevention systems, potentially involving scripting, automation, and orchestration across different platforms.
Develop and implement security policies, procedures, and protocols. Review systems and configurations, reporting on compliance with ION standards, client requirements, audit controls, regulations, and industry best practices. Respond to information security-related inquiries and requests.
Collaborate with Engineering teams and other functions to ensure security measures are integrated into all aspects of product delivery and the organization. Provide training and best practice security recommendations to Engineering and other teams within ION. Stay updated with the latest security trends, technologies, and threats. Prepare and present reports on security incidents and mitigation efforts to management.
Required Skills, Experience and Education
- Bachelor's degree in Computer Science, Information Technology with a specialization in Information Security.
- 3+ years of proven experience as a Security Analyst or in a similar role.
- Strong knowledge of security protocols, systems, and methodologies.
- Fundamental programming/scripting capabilities (e.g., Python, PowerShell, Bash).
- Experience with security tools such as firewalls, intrusion detection systems, and antivirus software.
- Familiarity with regulatory requirements and industry standards (e.g., GDPR, ISO 27001).
- Excellent analytical and problem-solving skills.
- Strong communication and interpersonal skills.
- Relevant certifications (e.g., CISSP, CISM, CEH) are a plus.