Security Analyst II

Posted 3ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Security Analyst monitoring and responding to threats across customer environments for NexusTek, a managed IT and cybersecurity provider. Tuning Rapid7 detections, investigating incidents, and supporting compliance and SOC improvements remotely in the United States.

Responsibilities:

  • Monitor and analyze security events across multiple customer environments using Rapid7 InsightIDR and SIEM/SOAR platforms
  • Investigate phishing, malware, lateral movement, and privilege escalation incidents
  • Respond to alerts and escalations in real time
  • Execute containment, eradication, and recovery playbooks
  • Tune Rapid7 detection rules, correlation logic, and dashboards to reduce false positives and improve visibility
  • Use InsightVM to correlate vulnerabilities with threat intelligence and risk posture
  • Document incident reports and communicate professionally with client stakeholders
  • Collaborate with NOC, Infrastructure, and Application Support teams to ensure secure operations
  • Provide remediation and threat-mitigation recommendations
  • Support compliance reporting and evidence collection for customer audits, including HIPAA, PCI, and ISO
  • Contribute to continuous improvement of SOC processes and runbooks
  • Work a 12-hour shift from 6:00 AM to 6:00 PM every other Wednesday, with a set Thursday through Saturday schedule

Requirements:

  • 2–4+ years of cybersecurity experience, preferably in a SOC or MSP environment
  • Strong experience with Rapid7 InsightIDR, InsightVM, and the broader Rapid7 ecosystem
  • Familiarity with SIEM, SOAR, EDR, vulnerability scanners, and firewalls
  • Deep knowledge of attack techniques, including MITRE ATT&CK, phishing, and ransomware
  • Strong working knowledge of Windows, Linux, AWS, and Azure environments
  • Scripting or automation experience with PowerShell, Python, or Bash is a plus
  • Strong analytical thinking, documentation, and incident-handling skills
  • Experience with ticketing systems such as ConnectWise and ServiceNow
  • Experience with collaboration tools such as Slack and Microsoft Teams
  • Client-facing experience, including status updates and root-cause-analysis calls
  • Experience with multi-tenant SIEM/SOC environments
  • Understanding of NIST, SOC 2, ISO 27001, and other regulatory compliance frameworks
  • Certifications such as Rapid7 InsightIDR Certified Specialist, Security+, CySA+, GCIA, GCIH, CEH, AWS Certified Security, or Azure Security Engineer are preferred but not required
  • Must be able to work the specified 12-hour shift schedule
  • The role is located in the United States
  • Three professional references, including at least one direct supervisor, are requested

Benefits:

  • Four weeks of annual accrued PTO
  • Seven paid national holidays
  • Medical, dental, and vision options
  • Company-paid life insurance
  • Company-paid short- and long-term disability
  • Voluntary critical illness and accident benefits
  • Voluntary Legal Shield and identity theft protection
  • Discretionary annual 401(k) match plan
  • Generous employee referral bonus plan
  • Employee Assistance Program
  • Access to over 90,000+ courses in ADP My Learning
  • StandOut employee engagement tools
  • Eligible to apply for a Pluralsight license
  • Eligible to apply for NexusTek Technical Academy
  • Eligible to apply for NexusTek Leadership Academy
  • Remote work from home
  • No travel required