- Company Name
- Flexjet
- Job Title
- Information Security Analyst
- Job Description
-
**Job Title:** Information Security Analyst
**Role Summary:**
Collaborate with the SOC to investigate incidents, conduct threat hunting, and manage threat intelligence in a hybrid on‑premise and cloud environment. Develop playbooks, automate responses, and support security monitoring and compliance audits.
**Expectations:**
- 1–3 years of Information Security experience, plus 1+ year in programming, networking, system administration, or DevOps.
- Must work outside normal hours as part of an on‑call rotation.
- Proactive in recommending and tuning security controls and incident response processes.
**Key Responsibilities:**
- Serve as primary escalation point for SOC‑raised incidents, conducting deeper analysis.
- Investigate, respond to, and document security events; perform forensics to identify root causes.
- Design and implement threat‑intelligence integrations, procedures, and automations.
- Develop and maintain playbooks using EDR and other security tools.
- Recommend improvements to alerting, monitoring, and incident response.
- Perform risk assessments of IT vendors, hardware, software, and services.
- Assist with evidence gathering for audits and reviews of technical and administrative controls.
- Consolidate data into accurate reports and metrics to measure control efficacy.
- Participate in an on‑call rotation and perform additional duties as required.
**Required Skills:**
- Knowledge of MITRE ATT&CK, Kill Chain, IOC extraction, forensics, and malware analysis.
- Expert TCP/UDP, routing, VLANs, subnetting, DNS, DHCP; IPv6 optional.
- Ability to identify and validate vulnerabilities.
- Strong verbal and written communication to peers and management.
- Solid understanding of Windows Server, Active Directory, group policies, file permissions, and clustering.
- Experience with EDR, SIEM (LogRhythm, Splunk, Azure Sentinel, AlienVault, Rapid7), and Microsoft 365 E5 tools (Intune, Security, Purview, Entra).
- In‑depth experience securing hybrid infrastructures and operating AWS, Azure, or GCP environments.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science or related field (preferred).
- Cybersecurity certifications: GCIH, GCFA, CySA+, or CASP+.