Security Analyst
Robert Half · San Francisco, CA · 2 wk ago
On-siteInformation TechnologyTemporary
This contract opportunity is ideal for a hands-on, detail-oriented individual who can assess security events, investigate suspicious activity, and strengthen detection capabilities across cloud-based environments. The role focuses on protecting sensitive information, improving response workflows, and partnering with technical teams to reduce risk across the organization. This role requires 3 days a week on-site.
Responsibilities
- Investigate security alerts from identity platforms, cloud applications, collaboration tools, and related systems to determine scope, severity, and required response actions.
- Lead incident handling activities from initial review through containment, documentation, and post-event analysis while separating legitimate threats from routine or expected activity.
- Design, refine, and optimize detection logic within SIEM and related monitoring tools to improve visibility and reduce unnecessary alert volume.
- Analyze behavioral patterns across users and systems to identify suspicious activity and strengthen anomaly-based monitoring.
- Review data protection alerts tied to file sharing, cloud storage, and collaboration platforms, and evaluate potential data exposure or exfiltration risks.
- Apply relevant threat intelligence indicators across available telemetry sources and convert findings into actionable detections or investigative steps.
- Conduct proactive threat hunts focused on emerging attack techniques affecting cloud identity, authentication, and financial technology environments.
- Work closely with engineering, platform, and IT teams to address control gaps, improve defensive measures, and support scalable response processes.
- Contribute to automation, enrichment, and playbook development that improves efficiency within security operations.
- Support the evolution of security policies and operational practices by identifying trends, documenting findings, and recommending practical improvements.
Requirements
- At least 2 years of experience in security analysis, security operations, incident response, or a closely related cybersecurity function.
- Working knowledge of SIEM platforms, alert investigation practices, and log analysis across cloud, identity, and endpoint sources.
- Understanding of cybersecurity principles including authentication, network fundamentals, threat detection, and incident handling.
- Familiarity with data security controls, cyber security policies, and techniques used to detect unauthorized access or data loss.
- Ability to interpret raw security logs, connect findings across multiple systems, and make evidence-based decisions during investigations.
- Strong communication skills with the ability to explain technical issues clearly to both technical and non-technical audiences.
- Bachelor’s degree in Computer Science, Information Security, Computer Engineering, or equivalent practical experience.
- Relevant certifications such as CompTIA Security+ are valued, and exposure to application security or regulated environments is a plus.
Benefits
- Medical, vision, dental, and life and disability insurance.
- Eligibility to enroll in the company 401(k) plan.