Security Analyst

Robert HalfDaytona Beach, United States
Full TimeOn-siteJuniorLimited info disclosed
2 views0 applications

Description

Position Overview We are seeking a Security Analyst to support the monitoring, analysis, and investigation of cybersecurity events across the organization. This is a hands-on analyst role focused on identifying potential threats, reviewing security alerts, conducting initial investigations, and escalating validated incidents to the appropriate internal teams. The ideal candidate has experience working within a Security Operations Center (SOC), security monitoring, or IT security environment and is comfortable using SIEM platforms to investigate alerts and identify suspicious activity. Experience with Microsoft Sentinel is preferred; however, candidates with experience using other SIEM tools are encouraged to apply. This position is focused on monitoring and analysis rather than security engineering or building security infrastructure. Key Responsibilities Monitor security alerts and events through SIEM platforms and other security monitoring tools. Review, analyze, and triage security alerts to determine potential risk, impact, and severity. Investigate suspicious activity, anomalous behavior, and potential security incidents across endpoints, networks, identities, and cloud environments. Differentiate legitimate security events from false positives and document findings appropriately. Escalate confirmed or high-risk security incidents to senior security personnel and technical teams. Perform initial incident analysis and collect relevant information to support containment and remediation efforts. Review security logs and correlate activity across multiple systems and data sources. Document security investigations, incident details, findings, and recommended next steps. Assist with ongoing security monitoring, threat detection, vulnerability management, and incident response activities. Collaborate with infrastructure, networking, systems administration, and IT support teams to investigate and resolve security-related issues. Maintain awareness of emerging cybersecurity threats, attack techniques, and industry security trends. Follow established security policies, incident response procedures, and escalation protocols. Required Qualifications 2+ years of professional experience in cybersecurity, security operations, IT security, or a related technical support environment. Hands-on experience monitoring and investigating security alerts using a SIEM platform. Experience with Microsoft Sentinel is preferred; experience with Splunk, IBM QRadar, LogRhythm, ArcSight, Rapid7 InsightIDR, or similar SIEM tools will also be considered. Understanding of security event monitoring, alert triage, incident investigation, and escalation procedures. Familiarity with common cybersecurity threats, attack methods, indicators of compromise, and security best practices. Experience reviewing and analyzing logs from endpoints, servers, networks, identity platforms, or cloud environments. Working knowledge of Microsoft Windows environments, Active Directory, Microsoft 365, and Microsoft Entra ID. Basic understanding of networking concepts, including TCP/IP, DNS, VPNs, firewalls, and network traffic. Strong analytical and troubleshooting skills with the ability to investigate issues methodically. Ability to clearly document findings and communicate security risks to technical and nontechnical stakeholders. Preferred Qualifications Experience using Microsoft Sentinel in a security monitoring or SOC environment. Experience supporting Microsoft 365, Microsoft Defender, Microsoft Entra ID, or Azure environments. Familiarity with endpoint detection and response (EDR) tools. Exposure to incident response, threat intelligence, vulnerability management, or security compliance activities. Security certifications such as CompTIA Security+, Microsoft SC-900, Microsoft SC-200, or equivalent. Previous experience working in a SOC, managed security services provider (MSSP), or enterprise security operations environment.