IT Security Analyst
Employment Type
: Full-Time Industry
: Miscellaneous
The IT Security Analyst will help to plan, implement, and upgrade the current security measures and controls and define the future of security at Musco.
Principal Duties and Responsibilities:
* Investigate security breaches as they occur and provide a report on future mitigation
* Manage network, intrusion detection and prevention systems to prevent data leakage, prevent data destruction, or unauthorized access.
* Analyze and assess vulnerabilities in the infrastructure (software, hardware, networks) collaborating with Development and Network Teams to review security design
* Analyze security breaches to determine their root cause
* Recommend and install appropriate security tools and countermeasures
* Work with Development & Network Teams to review security design
* Communicate with end-users and other IT team members to address security issues
* Perform vulnerability testing, risk analyses, security audits, and security assessments
* Define, implement and maintain corporate security policies
* Train fellow team members in security awareness and procedures, providing written documentation when needed
Education & Experience Requirements:
* 4-year degree from an accredited college or university in Computer Science, Management Information Systems, Cybersecurity, or a related field, preferred
* 3+ years of experience working with complex large-scale networking technologies and data security
Job Specifications:
* Understanding of passwordless technologies like MFA, PKI, and Fido keys
* Understanding of encryption technologies and digital certificates
* Knowledge in securing an Office 365 environment
* Knowledge in mitigating deficiencies in cloud environments
* Knowledge in endpoint security technologies to provide flexibility to team while maintaining a secure environment
* Knowledge in secure application design
* Understanding of TCP/IP networking, web infrastructure applications, tools and processes used in security incident detection and response
* Demonstrated experience and knowledge of security-related technologies such as intrusion prevention and detection systems, web proxies, SIEM, SOAR, EDR, firewalls, web application scanner, vulnerability scanners, and forensics tools