Search

Sr. Security Analyst - I.T.

Baker Group
locationAnkeny, IA, USA
PublishedPublished: 6/14/2022
Technology
Full Time

Job Description

Job Description


PURPOSE

The Senior Security Analyst – IT serves as a technical leader within Baker Group's cybersecurity function, responsible for advanced threat detection, complex incident response, security architecture input, and the maturation of the organization's security program. This role leads investigations into significant security events, drives improvements to controls and processes, mentors junior analysts and acts as a trusted advisor to IT leadership and business stakeholders on risk-based security decisions. This is an individual contributor role with technical mentorship responsibilities. Performs related work as required.

ESSENTIAL FUNCTIONS AND RESPONSIBILITIES

The following duties are typical for this job. These are not to be construed as exclusive or all inclusive. Other duties may be required and assigned.

  • Contribute to complex incident response investigations, including containment, eradication, recovery and post-incident reporting.
  • Design, tune, and continuously improve detection content across SIEM, EDR and other security platforms.
  • Conduct threat hunting based on threat intelligence, attacker tradecraft and environmental telemetry.
  • Provide security architecture input on new systems, applications, cloud service and infrastructure changes.
  • Provide strategic direction for the vulnerability management program — risk-based prioritization and exception review.
  • Serve as a senior point of contact for internal and external audit engagements; review evidence, address complex control inquiries and support assessors.
  • Contribute to the development and maintenance of security policies, standards and procedures aligned to NIST CSF, CIS Controls, and applicable regulatory frameworks.
  • Oversee third-party/vendor risk assessment processes and advise on remediation of identified vendor risks.
  • Mentor and develop Security Analyst I and II team members through coaching, technical reviews and structured knowledge transfer.
  • Support tabletop exercises, incident response drills and disaster recovery testing.
  • Evaluate and recommend new security technologies and process improvements; contribute to implementation of significant changes.
  • Translate technical security risks into business language for technical and non-technical audiences.
  • Stay current on emerging threats, vulnerabilities, and security best practices through ongoing training, conferences and professional development opportunities, sharing knowledge across the team.


MINIMUM EDUCATION & EXPERIENCE REQUIRED TO PERFORM ESSENTIAL FUNCTIONS

  • Bachelor's degree in computer science, cybersecurity, information systems, or related field, or equivalent relevant experience required
  • Minimum of five years' experience in information security, with demonstrated progression of responsibility
  • Hands-on experience with incident response across the full lifecycle (detection, containment, eradication, recovery)
  • Deep working knowledge across multiple of the following: SIEM, EDR, firewalls, identity and access management and cloud security (Azure and/or AWS)
  • Working knowledge of NIST CSF or CIS Controls, or SOC2, including practical experience applying controls in a production environment

CERTIFICATES, LICENSES, REGISTRATIONS

  • CompTIA Security+ ,preferred
  • CISSP, preferred
  • CISM, CISA, GCIH, GCIA or GSEC, preferred

MENTAL AND PHYSICAL COMPETENCIES REQUIRED TO PERFORM ESSENTAL FUNCTIONS

  1. Demonstrated ability to identify, prioritize, and mitigate complex network and application vulnerabilities, along with the capacity to clearly explain risk and prevention strategies to technical and non-technical audiences
  2. Skilled in risk-based decision making, weighing security needs against operational and business impact
  3. Excellent verbal and written communication skills, with proven ability to influence without authority
  4. Ability to lead under pressure during active security incidents
  5. Strong problem-solving skills with a methodical, evidence-based approach to investigation
  6. Demonstrated coaching and mentorship ability
  7. Passion for technology and strong desire to work with new technologies

ENVIRONMENTAL ADAPTABILITY

  • Prolonged periods of sitting at a desk and working on a computer
  • Must be able to lift 10 pounds occasionally
  • May have occasional visits to a job site which would require periods of standing, walking and/or climbing stairs


EQUIPMENT/TOOLS

  • Laptop Computer

Baker Group is an Equal Opportunity Employer. In compliance with the Americans with Disabilities Act, Baker Group will consider reasonable accommodations for qualified individuals with disabilities and encourage prospective employees and incumbents to discuss potential accommodations with the Employer.


Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...