- Company Name
- AlixPartners
- Job Title
- Security Operations Analyst
- Job Description
-
**Job title:** Security Operations Analyst
**Role Summary:**
Monitors, detects, and responds to cybersecurity incidents, analyses logs and alerts, and maintains security tooling to protect enterprise information assets.
**Expectations:**
- Analyze security events, determine appropriate actions, and liaise with internal stakeholders.
- Stay current on threats, attack techniques, and emerging security technologies.
- Collaborate with IT and business units on security projects and SOP development.
- Maintain incident response readiness and support critical investigations.
- Perform automated process improvements and scripting for security tool integration.
- Be willing to work outside standard U.S. business hours for incident response and projects.
**Key Responsibilities:**
- Continuous monitoring of security tools (SIEM, EDR, IDS/IPS).
- Log and data source analysis to identify attacks, abnormal activity, and trend detection.
- Incident response: containment, investigation, mitigation, and evidence handling.
- Administration of endpoint protection, firewall, IDS/IPS, and physical security systems.
- Design, tune, and update detection rules and alert correlation.
- Generate formal reports, presentations, and documentation for incidents and projects.
- Assist in evaluating security products and recommend enhancements.
- Automate security workflows via scripting and API integration.
- Participate in critical incident reviews and post‑mortem processes.
**Required Skills:**
- 1+ year in information security or related IT role (service desk, server admin, network engineering).
- Proficient with SIEM, EDR, firewalls, IDS/IPS, and anti‑malware solutions.
- Experience in log analysis, correlation, and threat hunting.
- Basic scripting/automation (Python, PowerShell, etc.) and API usage.
- Knowledge of OS hardening, network security monitoring, and cloud security fundamentals.
- Incident response, forensic analysis, or malware analysis exposure preferred.
- Strong analytical, detail‑oriented mindset; organized and able to prioritize.
- Excellent written and verbal communication in English.
- Collaborative team player with independent work capability.
- Willingness to work flexible hours and handle urgent security events.
**Required Education & Certifications:**
- Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or related field preferred; equivalent work experience considered.
- Certifications such as CompTIA Security+, Security+, or related credentials are a plus but not mandatory.