ChatGPT said:Information Security Analyst - Job Description Job Title: Information Security Analyst
Job Summary: The Information Security Analyst is responsible for protecting an organization's information systems, networks, applications, and data from security threats. The role involves monitoring security events, investigating incidents, identifying vulnerabilities, implementing security controls, and supporting compliance with information-security policies and standards.
Key Responsibilities - Monitor security alerts, logs, and events using SIEM and other security tools.
- Investigate and respond to cybersecurity incidents, including malware, phishing, unauthorized access, and data-security events.
- Perform vulnerability assessments and coordinate remediation of identified security weaknesses.
- Analyze network traffic, endpoint activity, authentication logs, and other security data.
- Support incident response, root-cause analysis, and post-incident reporting.
- Manage and monitor endpoint security, antivirus/EDR, firewalls, IDS/IPS, and related security technologies.
- Conduct security assessments and support penetration-testing activities.
- Assist with identity and access management, including user access reviews and privileged-access monitoring.
- Develop and maintain security policies, procedures, standards, and documentation.
- Support security awareness and phishing-awareness programs.
- Assist with compliance requirements and audits such as ISO 27001, SOC 2, PCI DSS, or applicable regulatory requirements.
- Track security vulnerabilities, risks, incidents, and remediation activities.
- Stay current with emerging threats, vulnerabilities, attack techniques, and cybersecurity best practices.
Required Qualifications - Bachelor's degree in Cybersecurity, Information Security, Computer Science, IT, or a related field.
- 2-5 years of experience in information security, cybersecurity, SOC, or a related IT role.
- Strong understanding of networking concepts, TCP/IP, DNS, HTTP/HTTPS, VPNs, and firewalls.
- Experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or similar.
- Knowledge of endpoint security/EDR technologies.
- Familiarity with vulnerability-management tools and methodologies.
- Understanding of incident-response and security-investigation processes.
- Knowledge of common cyber threats, attack vectors, and security controls.
- Good analytical, troubleshooting, documentation, and communication skills.
Preferred Certifications - CompTIA Security+
- CompTIA CySA+
- Certified Ethical Hacker (CEH)
- Certified Information Systems Security Professional (CISSP)
- GIAC certifications
- Microsoft security certifications
Technical Skills Security: SIEM, EDR/XDR, IDS/IPS, vulnerability management, incident response, threat intelligence
Networking: TCP/IP, DNS, DHCP, VPN, firewalls, proxies
Operating Systems: Windows, Linux
Cloud: AWS, Microsoft Azure, or Google Cloud security fundamentals
Tools: Splunk, Microsoft Sentinel, Defender, CrowdStrike, Nessus, Qualys, Wireshark, ServiceNow/Jira
Scripting: PowerShell, Python, Bash - desirable
Key Competencies - Security monitoring and analysis
- Incident detection and response
- Vulnerability and risk management
- Threat analysis
- Problem-solving and critical thinking
- Attention to detail
- Strong written and verbal communication
- Ability to work effectively under pressure
Employment Type: Full-time
Experience: 2-5 years
Department: Information Security / Cybersecurity
Reports To: Information Security Manager / SOC Manager