Information Security Analyst 3 - SOC Analyst
Apex Systems · Charlotte, NC · 1 wk ago
Information TechnologyContract
About the role
The Information Security Analyst 3 supports enterprise information security initiatives through risk analysis, security monitoring, incident response, compliance activities, security assessments, Identity and Access Management (IAM), and stakeholder consultation. This role identifies, assesses, and mitigates cybersecurity risks while ensuring alignment with Enterprise Information Security policies, standards, and regulatory requirements. The ideal candidate partners with technology teams, security operations personnel, risk management partners, and business stakeholders to improve security posture and proactively address cyber threats.
Responsibilities
- Information Security Risk Management
- Provide information security consultation to improve awareness and compliance with policies, standards, and procedures.
- Perform remediation activities related to security assessments, audits, risk reviews, and control testing findings.
- Provide guidance and recommendations regarding mitigating controls and risk reduction strategies.
- Evaluate information security risk exposure through advanced data aggregation, analysis, and reporting.
- Review and interpret security policies, standards, and procedures while recommending improvements.
- Support information asset portfolio reconciliation and certification activities.
- Review proposed control standards for business impact and recommend modifications.
- Support enterprise risk, compliance, governance, audit, and security control programs.
- Security Operations & Incident Response
- Participate in security monitoring, investigation, containment, escalation, and remediation activities.
- Support incident response processes utilizing established procedures, tools, and technologies.
- Perform threat hunting and investigative activities using endpoint, network, identity, and cloud security telemetry.
- Analyze security events and alerts generated by security monitoring platforms.
- Support cyber threat detection and response through security analytics and log analysis.
- Leverage offensive security concepts and adversarial thinking to identify indicators of compromise and emerging threats.
- Conduct vulnerability assessment reviews and support remediation planning.
- Security Monitoring & Analytics
- Utilize Security Information and Event Management (SIEM) platforms to identify, investigate, and respond to security events.
- Leverage Security Orchestration, Automation, and Response (SOAR) tools to improve security operations efficiency.
- Analyze host, endpoint, network, cloud, and identity-related logs to identify suspicious activity.
- Develop reporting, dashboards, and metrics related to security risks, incidents, and operational performance.
- Conduct threat hunting activities using security analytics and event data.
- Support cybersecurity reporting, security metrics development, and risk exposure analysis.
- Identity & Access Management (IAM)
- Support enterprise Identity and Access Management (IAM) programs and security controls.
- Assist with Identity Governance processes, access reviews, certification activities, and entitlement validation.
- Support provisioning and deprovisioning controls and related compliance initiatives.
- Review and analyze identity security risks associated with access management processes.
- Support Privileged Access Management (PAM) initiatives and enterprise access control programs.
- Assist with implementation and validation of identity-related controls including authentication, authorization, and Attribute-Based Access Control (ABAC).
- Security Controls & Compliance
- Conduct security control testing and validation activities.
- Assess effectiveness of security controls and identify opportunities for improvement.
- Support compliance initiatives and regulatory requirements.
- Partner with risk, compliance, audit, and technology teams to ensure effective governance and control coverage.
- Assist with development and delivery of Information Security Awareness and Education programs.
- Support vulnerability management processes, remediation efforts, and enterprise security governance initiatives.
- Participate in security assessments and control reviews to improve overall risk posture.
- Cloud & Endpoint Security
- Support security monitoring and investigative efforts across Microsoft Azure, Office 365, Google Cloud Platform (GCP), and other cloud-based environments.
- Monitor and analyze security events generated from Endpoint Detection and Response (EDR) platforms.
- Support implementation and maintenance of security controls protecting cloud and endpoint technologies.
- Evaluate cloud security risks and recommend mitigation strategies.
- Assist with monitoring cloud security posture and compliance requirements across multi-cloud environments.
- Security Engineering & Automation
- Support security tool integrations and automation initiatives to improve detection and response capabilities.
- Partner with security engineering teams to enhance monitoring, workflow automation, and operational effectiveness.
- Support SOAR implementation efforts and security automation activities.
- Contribute to DevSecOps and security operations modernization initiatives.
- Assist with security analytics and advanced detection engineering efforts.
- Collaboration & Leadership
- Collaborate with peers, technology teams, security engineers, compliance partners, and business stakeholders.
- Provide consultation and security guidance to internal customers.
- Support cross-functional security initiatives and projects.
- Mentor junior analysts and provide knowledge sharing across the team.
- Participate in continuous improvement efforts to strengthen security operations and risk management programs.
- Serve as a trusted advisor on information security risks, controls, and incident response activities.
Requirements
- 4+ years of Information Security Analysis experience or equivalent demonstrated through work experience, military experience, education, or training.
- 2+ years of Information Security Engineering experience.
- 1+ year of Incident Response experience utilizing security monitoring tools and response methodologies.
- 1+ year of experience with:
- Security Information and Event Management (SIEM) platforms
- Security Orchestration, Automation, and Response (SOAR) solutions
- 1+ year of experience supporting:
- Microsoft Azure
- Office 365
- Cloud security technologies
- Experience conducting security investigations and responding to security incidents.
- Knowledge of security analytics, incident response, and digital forensics disciplines.
- Experience developing security reports, dashboards, and risk analysis deliverables.
- Strong analytical, troubleshooting, and problem-solving skills.
- Excellent verbal and written communication skills.
Preferred Qualifications
- 2+ years of experience supporting Endpoint Detection and Response (EDR) solutions.
- Experience with:
- Threat Hunting
- Security Operations
- Incident Response
- Digital Forensics
- Security Analytics
- Experience supporting Identity and Access Management (IAM), Identity Governance, Access Reviews, Provisioning and Deprovisioning, Privileged Access Management (PAM), and enterprise access control programs.
- Experience developing cybersecurity metrics, dashboards, reporting, and operational security analytics.
- Knowledge of offensive security concepts including penetration testing methodologies, adversary tactics, and vulnerability research.
- Experience performing host and network log analysis in support of threat investigations and incident response.
- Experience supporting vulnerability management, remediation planning, security assessments, and enterprise security governance initiatives.
- Experience securing and monitoring cloud environments including Microsoft Azure and Google Cloud Platform (GCP).
- Experience supporting security automation, security tool integrations, SOAR initiatives, and DevSecOps-driven security operations.
- Experience working in banking, financial services, or other highly regulated environments.
- Experience working within a 24x7x365 Security Operations Center (SOC) environment.
Skills
- Security Operations
- Incident Response
- Threat Hunting
- Security Monitoring
- Digital Forensics
- Security Investigations
- Security Analytics
- Threat Detection
- Cyber Threat Analysis
- Security Platforms
- SIEM
- SOAR
- Endpoint Detection & Response (EDR)
- Log Management Solutions
- Security Monitoring Platforms
- Security Automation Tools
- Cloud Security
- Microsoft Azure
- Office 365
- Google Cloud Platform (GCP)
- AWS
- Cloud Security Monitoring
- Cloud Security Controls
- Cloud Risk Management
- Identity & Access Management
- Identity Governance
- Access Reviews
- Privileged Access Management (PAM)
- Authentication & Authorization
- IAM Administration
- Provisioning & Deprovisioning
- Attribute-Based Access Control (ABAC)
- Security Controls & Governance
- Security Assessments
- Security Risk Management
- Security Control Testing
- Information Security Governance
- Regulatory Compliance
- Audit Management
- Vulnerability Management
- Remediation Planning
- Security Technologies
- Firewalls
- Intrusion Detection Systems (IDS)
- Intrusion Prevention Systems (IPS)
- Malware