NFF, Inc

Sr. Cyber Security Analyst

NFF, Inc$90K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Minimum 5 years in Information Systems.
  • Strong grasp of cybersecurity functions and risk mitigation strategies.
  • Ability to analyze problems and implement solutions.
  • Knowledge of MITRE ATT&CK framework for IT and OT networks.
  • Proficient in programming/scripting languages like PowerShell or Python.
  • Understanding of network protocols and intrusion prevention systems.
  • Familiarity with NIST 800-53 and Cyber Incident Response steps.

Responsibilities

  • Support the Cyber Security Services Director in managing cyber risks.
  • Maintain user access controls for computing resources.
  • Monitor SOC operations for cyber incident detection and response.
  • Analyze security events to investigate causes and coordinate mitigations.
  • Test and manage cybersecurity infrastructure software.
  • Remediate unauthorized activities within the network.
  • Assist in disaster recovery operations to enhance business resilience.
  • Integrate third-party threat intelligence into cyber defense measures.
  • Conduct vulnerability and penetration testing to identify and prioritize risks.
  • Use threat hunting techniques to proactively neutralize threats.
  • Document all security incidents and investigative findings for compliance.
  • Generate reports on cybersecurity metrics for executive visibility.
  • Oversee the management of IT asset life cycles within the organization.
  • Continuously improve cybersecurity practices based on industry trends.

Benefits

  • Medical, Dental and Vision insurance options.
  • Health Savings Account and Flexible Spending Account.
  • Short-term and Long-term Disability insurance, along with life insurance options.
  • Comprehensive 401k retirement plan.
  • Paid Time Off with flexible options.
Full Job Description
About this Position / Responsibilities

Role Description: The Senior Cyber Security Analyst is responsible for the administration of deployed cyber control technologies. The role is part of the Security Operation Center (SOC) which monitors, analyzes, detects, and responds to cyber incidents on both traditional IT and Operational Technology (OT) networks. The role coordinates with both the Information Technology (IT) team and Operational Team (OT) to ensure individuals have the appropriate access to Enterprise Resources, monitor vulnerabilities and threats, collects intelligence, assists in disaster recovery operations, and in updating cyber controls with intelligence obtained from third-party providers. This role is also responsible for the identification of IT assets supporting Enterprise's business processes.
  • Supports the Director, Cyber Security Services, in ensuring Enterprise's preparedness to address cyber risks.
  • Maintains user access controls for computing resources.
  • Monitors SOC operations to detect, analyze, and respond to cyber incidents, including intrusion attempts, malware infections, and other security threats, across IT and OT networks.
  • Analyzes security events and incidents within the Enterprise Computing and Network environment, investigating root causes, assessing impact, and coordinate and document response actions to mitigate risks and minimize operational disruptions.
  • Tests, implements, deploys, maintains, reviews, and administers the infrastructure software required to effectively manage the Enterprise network defenses and resources.
  • Monitors Enterprise's network to actively remediate unauthorized activities.
  • Assists in disaster recovery operations, using preparation, identification, mitigation, remediation, and recovery approaches, as needed to maximize business resilience and information security.
  • Collaborate with the Director, Cyber Security Services, to incorporate threat intelligence obtained from third-party providers into Cyber Controls, enhancing Enterprise's ability to proactively identify and mitigate emerging threats.
  • Conducts and reports outcomes of vulnerability and penetration testing on IT and OT systems, identifying and prioritizing vulnerabilities for remediation to reduce the risk of exploitation by malicious actors.
  • Uses advanced threat hunting techniques and tools to identify and neutralize threats before they escalate.
  • Documents security incidents, investigations, and response activities in accordance with established procedures, ensuring accurate and thorough reporting for compliance, audit, and legal purposes.
  • Determines deviations from acceptable configuration, vendor, or IT Policy.
  • Generates security metrics, dashboards, and reports to provide visibility into key cybersecurity performance indicators, trends, and emerging risks for the senior executive team.
  • Oversee the receipt and distribution of IT assets owned, leased, or subleased by Enterprise to IT and OT, including creation and maintenance of supporting documentation to manage the acquisition and disposal of IT assets.
  • Continuously assesses and improves Enterprise's cybersecurity capabilities, processes, and procedures, leveraging lessons learned, industry best practices, and emerging technologies to enhance overall cyber resilience and readiness.

Key Working Relationships: Works with the Information Technology Solution Center (ITSC) and Infrastructure teams to enable the delivery and disposal of computing and network assets. Maintains and manages Role-Based Access to the Information Technology Asset Management Database. Partners with internal stakeholders to understand and logically document current and future processes.

Qualifications

The qualifications listed below are representative of the knowledge, skill, and ability necessary for an individual to perform each essential responsibility satisfactorily. Reasonable amounts of training are provided.

Required Skills & Qualifications

Required Experience:
  • Minimum 5 years of experience in Information Systems.
  • Strong understanding of the key functions of cybersecurity, cyber risk mitigation strategies, and event and incident flows within a Security Event and Incident (SEIM) system.
  • Ability to define the problem, generate and select alternatives, and implement solutions.
  • Intermediate understanding of MITRE and Adversarial Tactics, Techniques and Common Knowledge (ATT&CK) framework for Information Technology and Operational Technology Networks.
  • Strong understanding of one or more computer programming and/or scripting languages (PowerShell, KQL, Python, etc.).
  • Intermediate understanding of network ports, protocols, and services, host and network-based Intrusion Prevention Systems (IPS).
  • Advanced understanding of system and network logging events.
  • Familiarity with the National Institute of Standards and Technology NIST 800-53 Control Families and the NIST Cyber Incident Response steps.

Minimum Education Requirements:

A Bachelor's degree in Information Systems, Computer Science, or a related technical field from an accredited college or university.

Required Skills:
  • Cybersecurity Tools & Technologies
  • Information Security
  • Access Control
  • Incident Response
  • Adaptable & Agile
  • Attention to Detail
  • Analytical & Problem-Solving Skills
  • Teamwork
  • Communication Skills


NFF Disclosures

NFF offers a competitive salary, comprehensive benefits and flexible paid time off options, for eligible employees:
  • Medical, Dental and Vision, Health Savings Account, Flexible Spending Account
  • STD, LTD, Supplemental life insurance and ADD&D
  • Comprehensive 401k plan
  • Paid Time Off

About NFF, Inc

NFF, Inc. is a technology company that provides IT consulting, integration, and managed services to businesses and government agencies. The company was founded in 1996 and is headquartered in Herndon, Virginia. NFF's services include network infrastructure, data center, cloud computing, cybersecurity, and unified communications. The company has more than 200 employees and serves clients in a variety of industries, including healthcare, finance, and government. NFF is known for its technical expertise and customer service.
Learn more about NFF, Inc
Size
200 employees
Industry
Founded
1996
NASDAQ

Similar Jobs

More Jobs at NFF, Inc

More Information Technology Jobs

Find similar Sr. Cyber Security Analyst jobs: