Security Analyst
Description
Neptune Technology Group Inc. is a technology company serving water utilities across North America. Since 1892, we have continually focused on the evolving needs of water utilities – revenue optimization, operational efficiencies, and improved customer service. With our portfolio of smart water meters, data collection systems and software, we make data actionable for our customers – so they can remain focused on the business of water . For additional information, please visit the company website at www.neptunetg.com . Position Summary: Security Anal yst As a Security Analyst within Neptune's Security Operations Center (SOC), you will be responsible for monitoring, investigating, and responding to cybersecurity threats across Neptune's enterprise environment. You will investigate escalated alerts and detections, support incident response activities, coordinate with IT Operations and Engineering teams, and assist with the administration, configuration, and tuning of security to ols.The Security Analyst plays a critical role in protecting Neptune's systems, users, data, and business operations by identifying, containing, and mitigating cyber threats while supporting the continuous improvement of Neptune's security monitoring and response capabilit ies. Responsibili ties: Security Monitoring & Threat Det ectionMonitor security events, alerts, and detections across Neptune's security pla tformsInvestigate escalated alerts and suspicious activity identified through security monitoring toolsAnalyze security events to determine legitimacy, impact, and required response a ctionsIdentify indicators of compromise, malicious activity, and emerging t hreatsPerform threat hunting activities to proactively identify potential security risksMonitor security dashboards and ensure timely response to security events Incident Response & Invest igationParticipate in cybersecurity incident response activities, including investigation, containment, eradication, and r ecoveryPerform initial triage and analysis of security in cidentsCollect and analyze forensic artifacts, logs, and endpoint telemetry during investi gationsDocument findings, response actions, and lessons learnedEscalate incidents appropriately based on severity and impactSupport root cause analysis and post-incident reviews Security Operations & Colla borationCoordinate with IT Operations, Infrastructure, Engineering, and Application teams during investigations and remediation ac tivitiesSupport vulnerability management efforts by identifying and tracking remediation ac tivitiesAssist with security reviews of systems, applications, and infras tructureParticipate in security projects and operational ini tiativesSupport security awareness and operational readiness effortsCollaborate with Neptune's MSSP and third-party security partners during invest igations Security Tool Administration & En gineeringSupport the configuration, administration, maintenance, and tuning of secur ity toolsAssist with detection rule creation, tuning, and opt imizationValidate security telemetry and log ingestion across monitoring platformsSupport security automation and orchestration in itiativesParticipate in the deployment and implementation of new security tec hnologiesAssist with dashboard creation, reporting, and security metrics de velopment Compliance & Governan ce SupportSupport compliance initiatives aligned with NIST, CIS Controls, ISO 27001, and Roper Cybersecurity re quirementsAssist with audit requests, evidence collection, and security doc umentationMaintain incident records, procedures, and operationa l runbooksSupport continuous improvement of SOC processes and procedures Relevant Platforms (experience with several expected):CrowdSt rike FalconGoogle SecOps (Chronicle)Microso ft DefenderSIE M PlatformsEndpoint Detection and Response (EDR ) PlatformsSecurity Orchestration, Automation, and Resp onse (SOAR) Minimum Qua lifications:Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience)2+ years of experience in cybersecurity, security operations, IT operations, or related tec hnical fieldExperience investigating security alerts, detections, a nd incidentsUnderstanding of security concepts including malware, phishing, identity attacks, vulnerabilities, and netw ork securityFamiliarity with SIEM, EDR, and security monitori ng platformsStrong analytical and problem-so lving skillsExcellent written and verbal communic ation skillsAbility to work independently and collaboratively within a team environment Preferred Qu alifications:3+ years of Security Operations Center (SO C) experienceExperience with CrowdStrike Falcon, Google SecOps, Microsoft Defender, or simi lar platformsExperience with incident response and digital forensics i nvestigationsExperience with vulnerability manage ment programsFamiliarity with MITRE ATT& ;CK FrameworkExperience with cloud security technologies and environmentsKnowledge of NIST Cybersecurity Framework and CIS ControlsExperience with scripting or automation (PowerS hell, Python) Certifications (One or Mo re Prefer red): Secu rity +CyS A+GSECGCIHGCIACISSP (Asso ciate or Ful l)SC-200SC-900CrowdStrike CertificationsGoogle SecOps Certifications Years of Experience (IT, Security &a mp; Compliance)2–5 years of Information Technology, Cybersecurity, Security Operations, Compliance, or Incident Resp onse expe rience EducationBachelor's Degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related field preferredEquivalent military, technical, or professional experience wi ll be considered