Analyst, Information Security Job Description
Analyst, Information Security Duties & Responsibilities
To write an effective analyst, information security job description, begin by listing detailed duties, responsibilities and expectations. We have included analyst, information security job description templates that you can modify and use.
Sample responsibilities for this position include:
Analyst, Information Security Qualifications
Qualifications for a job description may include education, certification, and experience.
Licensing or Certifications for Analyst, Information Security
List any licenses or certifications required by the position: CISSP, CEH, GSEC, GIAC, SSCP, OSCE, OSWP, OSCP, ISACA, ISSA
Education for Analyst, Information Security
Typically a job would require a certain level of education.
Employers hiring for the analyst, information security job most commonly would prefer for their future employee to have a relevant degree such as Bachelor's and University Degree in Computer Science, Information Security, Education, Technical, Information Technology, Information Systems, Business, Engineering, Management, Cyber Security
Skills for Analyst, Information Security
Desired skills for analyst, information security include:
Desired experience for analyst, information security includes:
Analyst, Information Security Examples
Analyst, Information Security Job Description
- Perform tracking of all reported security events/incidents and their resolution
- Develop assessments and reports, weekly trends of incidents, and security events
- Utilize forensic tools to collect, search, recover, sort and organize large amounts of electronic information in all phases of incident response, investigation or litigation matter
- Participate in emergency response team activities for responding to various security incidents
- Provide on-call support for end users for all in-place security solutions that are partially or wholly operated by the Information Security team
- Maintaining and expanding the organization's cyber security infrastructure to provide the highest levels of security, while maintaining a balance between security and the collaboration required in research and educational endeavors
- Maintaining a high level of trust and confidentiality in working with the information security team
- Continuously maintaining an intimate knowledge of the rapidly changing cyber-security landscape by synthesizing information about cyber-security from various sources
- Performing digital forensics examinations, including malware analysis, utilizing a variety of tools
- Conduct data classification assessment and security audits and manage remediation plans as directed by senior security personnel
- Broad work experience that spans of the information security functions - policy development, education, vendor security assessments, application vulnerability assessments, risk analysis and compliance testing
- CISSP, CISA, CISM or CRISC
- Broad knowledge of industry-standard techniques and practices
- Adept at working in a fast pace, dynamic, multi-channel environment
- Strong sense of team and support of culture
- Ability to manage multiple projects and support functions
Analyst, Information Security Job Description
- Monitors the organization’s network/infrastructure and endpoints for security breaches, infections, and other malicious activity
- Analyze daily/periodic security reports for potentially unauthorized activities, researches events, and documents findings
- Gathers cyber threat intelligence information from various internal, external, and other authorized sources and analyzes the data for consumption within the organization
- Researches the latest information technology (IT) security and cyber threat trends
- Perform Security code review, including code scan, manual confirmation and communication with product team
- Perform Penetration testing
- Provide Security training for development and QA team
- Provide technical support for product team
- Identify network and middleware security vulnerabilities and offer resolution advice
- Monitor and manage security alerts from key information security dashboards (IDS, antivirus, centralized logging, etc)
- Experience using security vulnerability assessment tools and techniques
- Experience using Malware Remediation Tools
- Solid understanding of operating systems and platforms (Windows, iOS, Unix, Linux)
- Experience with Directory Services and LDAP
- Fundamental knowledge of network infrastructures including firewalls, VPN's, Intrusion Detection Systems, vulnerability assessment strategies, web application and device security
- Fundamental knowledge of the security requirements for HIPAA, HITECH, ISO 27001/27002 and SOX regulations
Analyst, Information Security Job Description
- Assess threats, risks and vulnerabilities relating to emerging security issues
- Experience in eDiscovery, Incident Response, and Digital Forensics
- Manage client security questionnaires, client audits, and regulatory audits
- Develop and manage audits by designated deadlines
- Interface with all levels of management to assess operations and communicate results of audits, assessments, and controls review
- Work with various groups to follow-up on remediation tasks until appropriately resolved
- Assess and provide ongoing training to IT team members
- Maintain open communications with all client areas
- Assist with the analysis and interpretation of regulatory compliance requirements
- Perform duties associated with preparing company responses to client and agency compliance audits
- Knowledge of security tools, technical security concepts, and security monitoring
- Understanding of computing vulnerabilities, exploits, attacks, and TTPs
- Experience scripting in Python, Perl, or PHP
- CISSP/Security+/GSEC preferred
- PMP/CAPM a plus
- Knowledge of Security standards (NIST/PCI DSS/ISO)
Analyst, Information Security Job Description
- Participate – in conjunction with management and HR – in the development of the core security awareness and training requirements across the company
- Perform analysis of security incidents to include source of attack, what happened, how the attack occurred, timeline and impact
- Execute incident response processes to respond to security threats and attacks such as viruses, malware, phishing and distributed denial-of-service attacks
- Creation of detection rules based on indicators of compromise that align with industry threats
- Monitoring Threat Intelligence Feeds and other sources of threat data to identify and apply countermeasure to combat threats
- Analyzing and assessing vulnerabilities in the infrastructure using automated tools
- Assisting in the evaluation, design and implementation of new technologies to enhance security capabilities
- Reviewing Identity and Access Management
- File Integrity Monitoring with integration with change management and configuration management
- Level 2 incident response and oversight of the Level 1 incident responders
- Functional knowledge and experience with text and data representation and manipulation (XML, HTML, Regular Expressions, Scripting, SQL)
- Proficiency with common program language used in information security
- Experience working as a member of an information security incident response team, conducting computer forensics analyses and performing investigative duties related to security policy violations
- Demonstrated knowledge of regulatory compliance requirements including PCI-DSS, HIPAA
- Demonstrated initiative, customer orientation and team work competencies
- Adaptability, flexibility and ability to work as part of a team or in an individual capacity
Analyst, Information Security Job Description
- Research new and upcoming security solutions to protect company and client data
- Support information security inquiries and audits
- Security monitoring and administration tasks to support new security tools and platforms
- Implement automated detection and alerting for potential security events
- Perform information security incident handling and respond to customer inquiries
- Support information security initiatives from creation to delivery
- Monitors and analyses attempted efforts to compromise security protocols
- Reviews SEIM logs and messages to identify and report possible violations of security
- Participate in knowledge sharing with other team members and industry collaboration organizations to advance the security monitoring program
- Performing quality assurance of recertification information
- Experience with file integrity monitoring solutions
- Experience with malware protection technologies
- Experience with enterprise log aggregation technologies
- Knowledge and experience assessing and implementing internal control concepts and IT General Controls
- Ability to solve problems, while navigating a diverse technology environment
- Effective in communicating factual needs or concerns on behalf of stakeholders