- Company Name
- Cambridge Savings Bank
- Job Title
- Security Operations Analyst
- Job Description
-
Job Title: Security Operations Analyst
Role Summary: Support the detection, investigation, and remediation of security incidents across key enterprise security tools—including firewalls, IDS/IPS, NGAV, SIEM, and Active Directory. Contribute to patch management, vulnerability scanning, and compliance documentation.
Expectations: 1–3+ years in IT/Infosec/Operations; associate degree in Information Security/IT (preferred); self‑motivated, independent worker comfortable working flexible hours. Ability to lift up to 40 lb and travel for on‑site tasks as needed.
Key Responsibilities:
- Investigate and respond to alerts from firewalls, IDS/IPS, NGAV, and SIEM; escalates incidents to senior staff or vendors.
- Install, troubleshoot, and monitor NGAV clients; produce weekly/monthly status reports and address real‑time alerts.
- Schedule and conduct internal/external vulnerability scans; review findings, perform basic investigations, and document remediation.
- Manage audit log programs and file data monitoring; analyze security tool logs for abnormal activity and report to leadership.
- Maintain and update IT compliance policies and procedures for security tools and systems.
- Provide end‑user security support (e.g., password resets, minor access issues).
- Collaborate with colleagues, vendors, and customers to resolve issues; actively stay current with security technologies and best practices.
Required Skills:
- Network security operations, patch management, firewall, IDS/IPS, vulnerability scanning, and log management.
- Familiarity with Windows Server, Active Directory and PC/LAN technologies from a compliance perspective.
- Basic experience with SIEM, NGAV, and monitoring tools.
- Strong analytical, threat-hunting, and anomaly‑investigation abilities.
- Excellent organizational, communication, and interpersonal skills.
- Proficiency in Microsoft Office suite.
Required Education & Certifications:
- Associate degree in Information Security, Information Technology, or related field (preferred).
- Industry certifications such as Microsoft, Security+, CISSP, or equivalent are a plus but not mandatory.