Vanasse Hangen Brustlin Inc

Cyber Security Operations Analyst

Vanasse Hangen Brustlin Inc$80K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, IT, Computer Science, or related field, or equivalent experience.
  • 3-5+ years in IT roles like system/nw administration or cybersecurity.
  • Strong understanding of Windows systems and networking fundamentals.
  • Ability to investigate technical issues using various logs and alerts.
  • Proficient written communication and documentation skills.
  • Collaborative team player with diverse IT support experience.
  • Interest in incident response and risk reduction.

Responsibilities

  • Monitor alerts and security tools to identify threats across the enterprise.
  • Investigate security events via comprehensive analysis to determine root causes.
  • Support incident response through investigation, documentation, and IT coordination.
  • Conduct threat hunting and manage vulnerabilities by tracking remediation progress.
  • Develop and fine-tune SIEM detections and security operation workflows.
  • Create and maintain incident response protocols and investigation records.
  • Collaborate with various IT teams to resolve security issues and enhance coverage.
  • Support security awareness initiatives and continuous improvement projects.

Benefits

  • Opportunity to contribute to maturing VHB's security operations.
  • Collaborative and growth-oriented work environment.
  • Potential for after-hours engagement during significant incidents.
Full Job Description
Overview

ABOUT THE POSITION

Cyber Security Operations Analyst

VHB is seeking a Cyber Security Operations Analyst to join our IT Security team. This role reports to the Cyber Security Operations Manager and works closely with infrastructure, systems, network, endpoint, and cloud teams to help monitor, investigate, and respond to security events across the enterprise.

This is a hands-on operational role suited for someone with a strong background in IT systems, networking, infrastructure, or security operations who is interested in growing deeper into cybersecurity. The ideal candidate is naturally curious, organized, and enjoys digging into system behavior, logs, alerts, and technical details to understand what happened, why it happened, how to prevent recurrence, and how to improve security visibility and response.

This role will contribute to the continued maturity of VHB's security operations program by helping improve monitoring, detection logic, documentation, response procedures, vulnerability management, and automation.

Please note: applicants must be legally authorized to work for VHB in the U.S. without employer sponsorship.

Responsibilities
  • Monitor security alerts, SIEM tools, dashboards, and endpoint platforms to identify threats and suspicious activity across the enterprise.
  • Investigate security events through log, endpoint, authentication, cloud, email, and network analysis to determine root cause, scope, and impact.
  • Support incident response activities, including investigation, containment, escalation, documentation, and coordination with IT teams.
  • Perform threat hunting and vulnerability management by analyzing suspicious behavior, reviewing scan results, prioritizing findings, and tracking remediation.
  • Develop and tune SIEM detections, alert logic, monitoring use cases, and security operations workflows.
  • Create and maintain incident response procedures, alert triage playbooks, investigation documentation, and case management records.
  • Collaborate with infrastructure, network, cloud, endpoint, and support teams to resolve security-related issues and improve monitoring coverage.
  • Support phishing simulations, security awareness initiatives, reporting, automation, and continuous improvement efforts.

Skills and Attributes
  • Strong troubleshooting, analytical, and investigative skills with the ability to identify abnormal system behavior and security risks.
  • Solid understanding of enterprise IT environments, including Windows systems, networking, endpoints, cloud services, and authentication technologies.
  • Ability to correlate logs, alerts, endpoint activity, identity events, and network behavior to assess potential incidents.
  • Strong written and verbal communication skills with the ability to clearly document findings and explain issues to technical and non-technical audiences.
  • Calm, organized, and methodical approach to handling alerts, incidents, remediation efforts, and shifting priorities.
  • Sound judgment and ability to determine when to escalate issues or engage cross-functional teams.
  • Curious, adaptable learner with interest in cybersecurity threats, tools, investigation techniques, and process improvement.
  • Comfortable working in a collaborative, fast-paced security environment with evolving priorities and responsibilities.

Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent professional experience.
  • 3-5+ years of experience in IT roles such as system administration, network administration, infrastructure support, endpoint support, cloud administration, IT operations, or cybersecurity.
  • Strong understanding of Windows systems, networking fundamentals, authentication, and enterprise IT environments.
  • Ability to investigate technical issues using logs, alerts, system data, and user activity.
  • Strong written communication and documentation skills.
  • Ability to work collaboratively with infrastructure, network, endpoint, and support teams.
  • Interest in cybersecurity operations, incident response, detection, and risk reduction.

Preferred Qualifications
  • 1-2+ years of security operations, SOC, incident response, vulnerability management, or security monitoring experience.
  • Experience with Microsoft security technologies such as Microsoft Defender, Microsoft 365 security tools, Microsoft Entra ID, Microsoft Sentinel, or Azure security services.
  • Familiarity with security monitoring tools such as SIEM platforms, endpoint detection and response tools, email security tools, vulnerability scanners, or security dashboards.
  • Experience with scripting, query, or automation tools such as PowerShell or Kusto Query Language (KQL).
  • Working knowledge of networking fundamentals including TCP/IP, DNS, routing, firewalls, VPNs, and authentication protocols.
  • Security certifications such as Security+, CySA+, SC-200, AZ-500, GCIH, or similar.

Additional Information
  • This role is primarily business-hours focused, with occasional after-hours support for significant security incidents as needed.
  • This position offers an opportunity to help build and mature VHB's security operations capabilities in a collaborative, growth-oriented environment.
  • Examples of work product/samples may be requested

Shortlisted candidates will be asked to complete a practical assessment.

#LI-KW1

#LI-Hybrid

About Vanasse Hangen Brustlin Inc

Vanasse Hangen Brustlin, Inc. (VHB) is a multidisciplinary engineering firm headquartered in Watertown, Massachusetts. The company was founded in 1979 and provides a wide range of services, including transportation planning and design, environmental planning and permitting, land development, and surveying. VHB has completed projects in a variety of industries, including transportation, real estate, and energy. The company is known for its expertise in sustainable design and has been recognized for its efforts in this area. VHB is a privately held company and has offices throughout the United States.
Learn more about Vanasse Hangen Brustlin Inc
Size
1,200 employees
Industry

Similar Jobs

More Jobs at Vanasse Hangen Brustlin Inc

More Information Technology Jobs

Find similar Cyber Security Operations Analyst jobs: