- Company Name
- Tyto Athene, LLC
- Job Title
- Security Analyst
- Job Description
-
**Job Title:** Security Analyst
**Role Summary:**
Perform hands‑on security operations and continuous monitoring for multi‑cloud (AWS, Azure, GCP) environments to ensure compliance with FedRAMP, FISMA, and client‑specific requirements. Act as a liaison between technical teams and non‑technical stakeholders, drive remediation efforts, and support security authorization documentation.
**Expectations:**
- US citizen eligible for Public Trust or DoD Secret clearance.
- Work independently with minimal supervision.
- Communicate clearly through tickets, reports, and meetings.
- Proactively address security findings in regulated, compliance‑driven settings.
**Key Responsibilities:**
- Enforce and maintain security baselines across AWS, Azure, and GCP.
- Review daily vulnerability scans, compliance dashboards, and security tool alerts (SIEM, endpoint, container, vulnerability platforms).
- Produce regular security and compliance reports.
- Manage and update System Security Plans, Contingency Plans, Incident Response Plans, POA&Ms, CMPs, and remediation plans.
- Coordinate remediation with Security Engineers, DevOps, system owners, and clients.
- Keep accurate hardware, software, and cloud asset inventories.
- Support contingency‑plan and incident‑response testing, documentation, and training.
- Conduct risk analyses and security impact assessments for system changes.
- Participate in Change Control Board reviews for security impact.
- Contribute to Continuous Monitoring processes and internal procedure improvements.
**Required Skills:**
- Experience securing AWS, Azure, and/or GCP environments.
- Strong systems administration and vulnerability‑management background in cloud.
- Hands‑on with tools such as Palo Alto firewalls, Splunk, Tenable/Nessus, Trend Micro Deep Security, Anchore/Twistlock, Terraform, CloudFormation, Ansible.
- Ability to analyze and respond to alerts from SIEM, endpoint, and container security tools.
- Effective written and verbal communication; stakeholder collaboration.
- Strategic thinking and proactive problem‑solving in compliance contexts.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field preferred (or equivalent experience).
- Relevant security certifications (e.g., CISSP, CISM, AWS/Azure/GCP Security Specialty) are advantageous.
- Ability to obtain and maintain a Public Trust or DoD Secret clearance.