Jobs · Kentucky

Analyst, Security

Southern Star Central Gas Pipeline · Owensboro, KY · 2 days ago
HybridFull-time

About the Role

The security analyst monitors, detects, investigates, and responds to cybersecurity threats across the organization’s enterprise IT and operational technology (OT) environments, and maintains and operates the organization’s physical access control systems. This is a converged role: the analyst works fluently across corporate networks, cloud and identity platforms, and industrial control systems, applying a defense-in-depth approach that respects the distinct risk tolerances, availability requirements, and safety considerations of each domain. The analyst will work closely with other teams to ensure security is designed and implemented into new and existing projects.

Company Overview

Since 1904, Southern Star has proudly served as a reliable natural gas transporter to America’s heartland. Southern Star is an innovative, customer-oriented company committed to collaboration in all parts of our business. With over a century of trusted service, we continue to prioritize what sets us apart—our people. At Southern Star, you’ll find a workplace where your growth matters, your voice is heard, and your contributions are recognized. Whether you're just starting out or looking to take the next big step in your career, Southern Star is the employer of choice where you can make a meaningful impact. Will you be the next talented individual to join our team?

Responsibilities

  • Performing installation and maintenance of security infrastructure hardware and software
  • Monitoring security alerts and telemetry across SIEM, EDR/XDR, and OT monitoring platforms, and proactively reviewing internal and external-facing environments for signs of anomalous or malicious activity; triaging, investigating, and escalating per the incident response plan
  • Conducting threat hunting using the MITRE ATT&CK framework and MITRE ATT&CK for ICS as detection and investigation frameworks
  • Performing vulnerability management activities, including scanning, prioritization, remediation tracking, and risk acceptance documentation, across both IT and OT asset inventories
  • Maintaining and tuning access control rules, correlation logic, and alerting to reduce false positives and improve mean-time-to-detect and mean-time-to-respond
  • Facilitating process improvements for more effective threat detection and response
  • Maintaining knowledge of modern network security tools, technologies, and threat landscape
  • Working closely with other teams to ensure network security is designed and implemented into new projects
  • Supporting incident response across the full NIST lifecycle, including preparation, detection and analysis, containment, eradication, recovery, and post-incident review
  • Investigating alerts within cloud and identity platforms, such as Microsoft 365, Entra ID, XDR platforms, conditional access, and privileged access events
  • Analyzing e-mail security verdicts, conducting phishing and business e-mail compromise investigations, and managing quarantine and remediation workflows
  • Authoring and refining detection queries (e.g., KQL, SPL) and dashboards
  • Supporting endpoint, network, and firewall security operations and policy review
  • Regularly research and monitor security-related information sources to aid in the identification of threats
  • Contributing to security awareness initiatives, phishing simulation analysis, and reporting metrics for leadership
  • Develops knowledge of business processes, network protocols, and system architecture
  • Researching and testing updates to existing technology; suggest new technologies
  • Maintaining relationships with customers
  • Participating on IT related projects as well as cross-functional teams
  • Receiving general instructions and ability to work independently
  • Continuous self-improvement and willingness to learn

Qualifications

  • Bachelor's degree or equivalent experience
  • Entry-level experience in security or related area (Will also consider candidates with more experience)
  • Knowledge in IT network security
  • Knowledge of network forensics, data loss prevention, packet analysis, vulnerability management, and security operations
  • Familiarity with the MITRE ATT&CK framework and the cyber kill chain
  • Understanding of TCP/IP networking, segmentation, firewalls, and common attack techniques
  • Strong problem-solving skills
  • Strong communication skills
  • Ability to collaborate with other technical groups to find solutions
  • A desire to expand current knowledge and skills
  • Well organized, willing to take initiative, and work independently

Preferred Qualifications

  • Advanced degree
  • Exposure to OT/ICS environments, or a demonstrated willingness to develop OT competency
  • Scripting or automation familiarity (e.g., PowerShell, Python) for SOAR or remediation workflows
  • Linux competency

License and Insurability

A valid driver's license and insurability under company policy are required.

Similar jobs

Security Analyst

Metro Vein CentersUnited States· 1 mo ago
RemoteInformation Technology$75k/yrapply on grnh.se

Security Analyst

Metro Vein CentersDetroit, MI· 1 mo ago
Information Technology$75k/yrapply on grnh.se

Security Analyst

Upwind SecuritySan Francisco, CA· 2 wk ago
Information Technologyapply on comeet.com

Security Analyst

Upwind SecurityBoston, MA· 2 wk ago
Information Technologyapply on comeet.com

Security Analyst

HighCloud SolutionsSt Paul, MN· 2 wk ago
RemoteInformation Technologyapply on highcloud.oorwin.ai