Department: Charlotte Area Transit System Department
Salary: $81,226.00 - $116,762.94 Commensurate with Experience
SUMMARYThe Cyber Security Analyst supports cybersecurity operations for the Charlotte Area Transit System (CATS) by monitoring systems, analyzing potential threats, and assisting with protection of enterprise and operational technology environments. This position helps maintain secure and reliable technology services supporting a 24/7 transit organization.
The role investigates security alerts, assists with incident response activities, and supports vulnerability management and compliance efforts. The Cyber Security Analyst collaborates with infrastructure, applications, and service desk teams to identify risks and strengthen organizational security practices.
Working under general direction, this position applies professional judgment while performing technical security analysis and operational support activities.
Major Duties and Responsibilities:The following duties are standard for this position. The omission of specific statements of duties does not exclude them from the classification if the work is similar, related, or a logical assignment for this classification.
Security Monitoring and Analysis- Monitor systems and security tools for suspicious activity.
- Review alerts generated by security monitoring platforms.
- Investigate anomalies and potential threats.
- Escalate incidents according to established procedures.
- Maintain awareness of evolving threat conditions.
Incident Response Support- Assist with investigation of cybersecurity incidents.
- Collect and analyze system and event data.
- Support containment and remediation activities.
- Document investigative findings.
- Participate in post-incident reviews.
Vulnerability Management Support- Assist with vulnerability scanning activities.
- Track remediation efforts across technology teams.
- Verify corrective actions.
- Support risk tracking and reporting.
Security Operations Support- Assist with implementation of security controls.
- Support access reviews and account security practices.
- Help maintain monitoring and detection tools.
- Promote secure operational practices.
Compliance and Documentation- Maintain security documentation and operational records.
- Support audits and compliance reviews.
- Document procedures and investigation activities.
- Contribute to security knowledge resources.
Collaboration and Awareness- Coordinate with infrastructure and application teams.
- Provide input on potential security improvements.
- Support organizational cybersecurity awareness efforts.
- Communicate findings clearly to technical staff.
Core Competencies:The position requires demonstrated competency in the following areas:
Security AnalysisApplies analytical thinking to identify and evaluate potential cybersecurity risks.
- Reviews data methodically.
- Recognizes suspicious patterns.
- Supports accurate investigations.
Attention to DetailMaintains accuracy when reviewing technical information and documentation.
- Follows procedures carefully.
- Produces reliable analysis.
- Reduces oversight risk.
Operational DisciplineSupports consistent execution of security processes.
- Adheres to standards.
- Maintains documentation.
- Supports organizational readiness.
CollaborationWorks effectively within multidisciplinary technology teams.
- Shares information appropriately.
- Supports coordinated responses.
- Builds cooperative relationships.
Minimum Qualifications- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field; or equivalent combination of education and experience.
- Two (2) years experience in information technology or cybersecurity-related work.
Preferred Qualifications:- Experience with security monitoring or incident response activities.
- Familiarity with network or infrastructure environments.
- Entry-level cybersecurity certifications (Security+, or similar).
- Experience supporting public-sector or operational environments.
Knowledge, Skills and Abilities:Knowledge of:- Cybersecurity fundamentals and threat concepts.
- Security monitoring and alerting tools.
- Basic networking and system administration concepts.
- Incident response processes.
- Vulnerability management practices.
Skill in:- Analyzing technical alerts and logs.
- Documenting investigative activities.
- Communicating technical findings clearly.
- Using security monitoring platforms.
Ability to:- Apply analytical reasoning to technical problems.
- Follow structured procedures accurately.
- Learn evolving cybersecurity tools and threats.
- Work independently within defined operational frameworks.
- Maintain confidentiality and professional discretion.
Working Environment and Physical Demands:- Work performed primarily in office environments.
- Participation in incident response outside normal business hours may occasionally be required.
- Requires prolonged computer use and analytical work.