- Company Name
- Blue Light Card
- Job Title
- Security Analyst
- Job Description
-
**Job title**
Security Analyst
**Role Summary**
Analyze, triage, and respond to security incidents across SIEM, EDR, and cloud platforms. Lead and manage phishing simulations, develop security awareness content, and maintain learning documentation to improve the organization’s security posture.
**Expectations**
* Deliver timely, accurate incident triage and escalation.
* Maintain and grow an effective, measurable phishing simulation program.
* Produce clear, actionable security metrics and reports that inform decision‑making.
* Create, refine, and disseminate SOPs, playbooks, and awareness materials.
**Key Responsibilities**
* Monitor and analyze alerts from SIEM, EDR, and cloud security tools, documenting findings and escalating incidents per response procedures.
* Manage the organization’s simulated phishing program: campaign creation, scheduling, execution, trend analysis, and follow‑up.
* Develop and deliver inclusive security awareness content to reinforce security culture.
* Create, refine, and maintain SOPs, playbooks, and procedural documentation for consistent operations.
* Produce insight‑rich reporting on alert activity, phishing performance, and security metrics.
* Collaborate with cross‑functional teams to embed secure practices into initiatives.
* Continuously improve tooling, detection logic, operational processes, and awareness strategies.
* Stay informed on emerging threats, attack patterns, and industry best practices.
**Required Skills**
* Proven ability to triage security alerts, assess severity, identify root causes, and perform appropriate escalation.
* Hands‑on experience with SIEM, EDR, and cloud security tools; proficiency interpreting signals and validating alerts.
* Experience managing phishing simulation programs and analytics.
* Strong technical communication and documentation abilities (SOPs, playbooks, guidance).
* Foundational security knowledge (common attack vectors, threat behaviors, best practices such as NIST, ISO 27001, Cyber Essentials).
* Ability to translate complex technical concepts into accessible content for both technical and non‑technical audiences.
* Structured, detail‑oriented problem‑solving with sound judgment; capable of autonomous operation within defined processes.
* Collaborative, inclusive mindset that supports a positive security culture.
**Required Education & Certifications**
* Bachelor’s degree in Computer Science, Cybersecurity, or related field (preferred).
* Relevant certifications (CISSP, CISM, CEH, or equivalent) preferred.