- Continuously monitor security events and alerts, performing triage, analysis, investigation, classification, and handling
- Investigate suspicious behavior by correlating data from SIEM, EDR/XDR, firewalls, email security, identity, network, and other security controls
- Execute and track vulnerability management activities, including identification, classification, prioritization, assignment, remediation tracking, and remediation validation
- Prioritize vulnerabilities based on technical severity, exposure, exploitability, business relevance, and known exploits
- Operate, administer, and maintain security tools, monitoring availability, configurations, integrations, policies, rules, versions, and agents
- Create and review security rules, policies, alerts, exceptions, and configurations
- Support the hardening of servers, workstations, systems, devices, and other technology components
- Assess adherence to security baselines and best practices, identifying deviations and tracking remediation
- Support incident response, including investigation, containment, eradication, recovery, and evidence collection
- Support root-cause analyses and post-incident activities, defining corrective and preventive actions
- Develop and maintain technical documentation, procedures, playbooks, workflows, standards, baselines, evidence, inventories, and records
- Prepare reports and metrics on vulnerabilities, alerts, incidents, tools, hardening, and security controls
- Collaborate with Infrastructure, Networks, Cloud, Workplace, Systems, Architecture, Service Desk, and vendor teams
- Support infrastructure and systems projects and changes by assessing security and recommending controls
- Monitor information on vulnerabilities, threats, attack techniques, and indicators of compromise
- Contribute to automation, improved coverage, and operational efficiency across Cybersecurity processes
- Support audits, security assessments, and compliance processes by providing technical evidence
Requirements
- Bachelor’s degree in Computer Science, Information Systems, Software Engineering, Systems Analysis and Development, Information Security, or a related field
- Hands-on experience in security operations, alert investigation, and incident response support
- Experience with SIEM, EDR/XDR, and vulnerability management tools
- Experience with the vulnerability management lifecycle, including risk-based prioritization and remediation validation
- Knowledge of networks, protocols, Windows, Linux, and Active Directory, applied to security analysis
- Experience administering security tools, tuning rules and policies, and applying secure configurations (hardening)
- Ability to prepare technical documentation, playbooks, and metrics and collaborate with technology teams
- Experience automating routines using Artificial Intelligence, Python, PowerShell, APIs, or SOAR
- Experience with cloud security and identity solutions such as Entra ID and SOC environments
- Experience creating and improving detection rules and conducting proactive threat investigations (threat hunting)
- Experience working in regulated environments, preferably in the pharmaceutical industry
- Certifications related to security operations or the tools used by the organization are a plus
Core Competencies
Demonstrates expertise in security operations, incident response, and vulnerability management, with a strong focus on technical documentation and collaboration across technology teams. Proficient in utilizing security tools and automating processes to enhance operational efficiency and compliance.
Highest-signal resume keywords
- Security Operations
- Incident Response Support
- Vulnerability Management
- SIEM/EDR/XDR Tools
- Cloud Security
Hard Skills
- Vulnerability Management Lifecycle
- Security Analysis
- Technical Documentation
- Threat Hunting
- Risk-Based Prioritization
- Secure Configurations
- Automation with Python
- Automation with PowerShell
- Network Protocols
- Active Directory
Soft Skills
- Collaboration
- Analytical Thinking
- Problem Solving
Industry Keywords
- Pharmaceutical Industry
- Regulated Environments
- Security Assessments
- Compliance Processes
Tools & Technologies
- SIEM
- EDR/XDR
- Vulnerability Management Tools
- Cloud Security Solutions
- Identity Solutions
#J-18808-Ljbffr
Mid-Level Cybersecurity Analyst Arbeitgeber: Jobtailor
Als Front Office Supervisor in unserem dynamischen Team bieten wir Ihnen die Möglichkeit, in einem unterstützenden und freundlichen Arbeitsumfeld zu wachsen. Wir legen großen Wert auf die berufliche Entwicklung unserer Mitarbeiter und bieten regelmäßige Schulungen sowie die Chance, Verantwortung zu übernehmen. Unsere Lage ermöglicht es Ihnen, Teil einer lebendigen Gemeinschaft zu sein, während Sie gleichzeitig die Standards unseres Franchise-Partners einhalten und unseren Gästen einen unvergesslichen Aufenthalt bieten.