Jobs · Iowa

Information Security Analyst II

Federal Home Loan Bank of Des Moines · Des Moines, IA · Yesterday
$81k–$97k/yrFull-time
At FHLB Des Moines, we work each day to develop an inclusive culture that supports and leverages the complexity of a diverse workforce. This enables us to effectively serve the needs of our members and help them succeed. The Information Security Analyst II is responsible for monitoring, analyzing, and responding to cybersecurity events while supporting the organization's overall security operations. As a member of the Information Security team, perform threat detection, incident investigation, vulnerability management, and security administration activities to protect the confidentiality, integrity, and availability of organizational systems and data. Accountabilities: Key Responsibilities: Monitor security alerts and events generated by SIEM, EDR, email security, cloud security, identity, network, and other security technologies.Analyze security events to determine validity, impact, severity, and appropriate response.Investigate suspicious activity and perform triage of security incidents, including containment and remediation efforts, by coordinating with internal technology teamsEscalate confirmed incidents according to established incident response procedures.Participate in containment, eradication, recovery, and post-incident reviews.Document investigations, findings, evidence, and remediation activities.Perform threat hunting activities to identify malicious or abnormal behavior.Correlate events across multiple security platforms to identify emerging threats.Review indicators of compromise (IOCs) and indicators of attack (IOAs).Monitor threat intelligence sources and recommend defensive improvements.Identify trends in alerts and recommend tuning to reduce false positives.Assist with vulnerability management activities including reviewing scan results, validating findings, and tracking remediation.Maintain documentation, runbooks, and standard operating procedures; test security controls and validating operational readiness.Partner with Infrastructure, Cloud, Networking, Application Development, Risk Management, and IT Operations to resolve security issues.Provide recommendations to improve detection capabilities and operational processes; assist in developing and refining incident response playbooks.Participate in security projects and implementation efforts.Stay current on cybersecurity threats, vulnerabilities, attack techniques, and industry best practices.Participate in incident response tabletop exercises to validate response procedures, identify gaps, and improve organizational preparedness.Participate in an on-call incident response rotation to provide after-hours support for cybersecurity incidents and critical security events.Support post-incident reviews by documenting lessons learned and recommending improvements to security controls, processes, and response procedures.Perform initial forensic data collection to support security investigations.Validate remediation activities following security incidents.Support internal and external audits by providing evidence related to security operations.Assist with onboarding new security tools and capabilities and perform routine administration of existing tools.Other duties and projects as assigned. Qualifications: Required 2-4 years of experience in Information Security, Security Operations Center (SOC), Cybersecurity, Information Technology, or a related technical discipline.Experience investigating security alerts and responding to cybersecurity incidents.Experience working with enterprise security technologies.Working knowledge of one or more of the following: SIEM platforms, Endpoint Detection & Response (EDR/XDR), IDS/IPS, Email Security, Network Security Monitoring, Active Directory/Azure AD/Entra ID, Windows and Linux operating systemsStrong analytical and problem-solving abilities.Ability to distinguish false positives from legitimate security events.Understanding of the Cyber Kill Chain, MITRE ATT&CK Framework, or similar threat models.Ability to assess risk and recommend appropriate remediation.Excellent written and verbal communication skills.Ability to prioritize multiple investigations simultaneously.Strong attention to detail with excellent documentation skills.Self-motivated with the ability to work independently and collaboratively.Demonstrates curiosity, integrity, and a commitment to continuous learning. Preferred Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or related field (or equivalent experience).Security+, CySA+, GSEC, GCIA, GCIH, CISSP (Associate), or comparable certifications.Experience with SOAR, threat intelligence platforms, cloud security, or digital forensics is preferred. Compensation Range: Annual Salary: $81,481.00 - $96,758.00 This salary range represents the Bank’s good faith and reasonable estimate of possible compensation at the time of hire. Offer to be determined by selected applicant’s education, experience, knowledge, skills & abilities, as well as internal equity and alignment with market data. This role is also eligible to participate in the Bank’s annual incentive plan. As part of our competitive Total Rewards package, the Bank offers 11 paid holidays, 5 weeks of PTO and a work culture that values work/life balance. Most roles are eligible for our hybrid work schedule. We match 100% of the first 6% you contribute to your 401(k) and provide an additional 4% non-discretionary contribution to your 401(k) at the end of year. More information on our Total Rewards program can be found here. At FHLB Des Moines, we work to create an inclusive culture. This enables us to effectively serve the needs of our members and help them succeed. FHLB Des Moines is proud to be an Equal Opportunity Employer. We prohibit discrimination on the basis of race, color, religion, sex (including pregnancy, sexual orientation or gender identity), national origin, age, disability, veteran status, genetic information (including family medical history), status as a parent or any other characteristic protected by federal, state or local law.

Similar jobs

INFORMATION SECURITY ANALYST II

Marvin Engineering CompanyLos Angeles Metropolitan Area· Yesterday
Information Technology$90k–$120k/yrapply on jobs.marvingroup.com