- Company Name
- Longo's
- Job Title
- Senior Security Analyst
- Job Description
-
Job Title: Senior Security Analyst
Role Summary:
Lead the design, deployment, and management of security controls, driving technical incident response, vulnerability management, and PCI‑DSS compliance, while mentoring junior analysts and serving as a key liaison between security operations and senior leadership.
Expectations:
- 4–7 years of professional cybersecurity experience, including hands‑on security operations and compliance leadership.
- Proven ability to manage multi‑tiered security tools and coordinate with external MSSPs, auditors, and vendors.
- Strong analytic, communication, and documentation skills; capable of presenting technical findings to leadership.
Key Responsibilities:
1. **Threat Detection & Response** – Monitor, investigate, and contain security alerts from SIEM, EDR, WAF, and other tools; act as escalation lead for high‑severity incidents.
2. **Incident Management & On‑Call Support** – Provide technical direction during critical incidents, coordinate response, perform root‑cause analysis, and maintain incident documentation.
3. **Security Tool Deployment & Ops** – Lead configuration, optimization, and integration of PAM, SIEM, EDR, micro‑segmentation, and other security solutions; collaborate with IT and infrastructure teams.
4. **Vulnerability & Patch Management** – Conduct vulnerability scans, analyze findings, and coordinate remediation with relevant stakeholders.
5. **PCI‑DSS Compliance Operations** – Coordinate evidence collection, control validation, audit readiness, and remediation of gaps.
6. **Governance, Risk, & Policy Management** – Own GRC tooling, maintain risk register, draft and update security policies and SOPs aligned with industry frameworks.
7. **Third‑Party Risk Assessments** – Lead vendor security evaluations, track findings, and ensure remediation.
8. **Security Awareness & Education** – Plan and execute phishing simulations, track awareness metrics, and recommend improvements.
9. **Reporting & Leadership Support** – Prepare threat, compliance, and incident reports; present updates to the Senior Manager.
10. **Mentorship & Knowledge Sharing** – Coach junior analysts and foster continuous improvement within the team.
Required Skills:
- Advanced knowledge of cybersecurity frameworks (NIST CSF 2.0, CIS Controls, ISO 27001).
- Hands‑on expertise with SIEM, EDR, PAM, WAF, vulnerability management, and micro‑segmentation.
- Proficiency in Windows, Active Directory, and cloud security controls.
- Understanding of PCI‑DSS controls, evidence management, and audit processes.
- Strong communication, documentation, and presentation abilities.
- Ability to collaborate across technical and non‑technical stakeholders.
Required Education & Certifications:
- Bachelor’s degree (or equivalent experience) in IT, Computer Science, Engineering, Cybersecurity, or related field.
- Relevant certifications (e.g., CISSP, CISM, CEH, CompTIA Security+, or PCI‑DSS Lead Implementer) are highly desirable.