Cybersecurity Analyst

Role Overview

The Security Analyst plays a critical role in assessing and protecting client security posture across diverse environments. This role combines proactive risk assessment, incident analysis, and customer engagement to identify vulnerabilities, document findings, and guide clients toward stronger security controls. The ideal candidate is detail-oriented, communicates clearly with technical and non-technical stakeholders, and can balance the demands of assessment delivery with rapid escalation support for active security concerns.

Key Responsibilities

Plan and coordinate security risk assessments with clients, including scheduling, stakeholder alignment, and timeline management

Conduct comprehensive security assessments, analyzing controls, policies, and configurations against industry frameworks (NIST, ISO 27001, CIS)

Review and evaluate evidence of control implementation, documenting findings with clarity and supporting documentation

Identify security risks, control gaps, and areas of non-compliance; articulate business impact and remediation priorities

Draft detailed assessment reports and executive summaries tailored to client leadership and technical teams

Conduct kickoff and debrief meetings, explaining assessment methodology, findings, and recommended remediation actions

Manage customer communication throughout assessment lifecycle, providing status updates and addressing questions

Handle escalated security cases from the service desk, including incident analysis, root cause investigation, and remediation guidance

Analyze security incidents and vulnerability findings, documenting technical details and recommended fixes

Maintain detailed case notes, incident reports, and security documentation for client and internal records

Collaborate with IT, engineering, and internal security teams to improve assessment quality and service delivery

Organize client files, policies, and assessment documentation for accurate tracking and reporting

Required Qualifications

Bachelor's degree in Information Security, Computer Science, Information Technology, or related field (or equivalent professional experience)

Strong understanding of security controls and risk management frameworks (NIST, ISO 27001, CIS Benchmarks)

Practical experience conducting or supporting security assessments, audits, or risk evaluations

Working knowledge of common attack techniques, vulnerabilities, and indicators of compromise

Excellent written and verbal communication skills; ability to explain technical concepts to non-technical audiences

Strong organizational and time management abilities; capable of managing multiple assessments and priorities

Proficiency with Microsoft Office (Word, Excel, Outlook) and ability to quickly learn new tools

Attention to detail and strong documentation skills

Ability to work effectively in both independent and collaborative environments

Preferred Qualifications

1-3 years of hands-on experience in information security, risk management, IT audit, or related role

Experience in an MSP or MSSP multi-tenant environment

Familiarity with GRC (Governance, Risk, and Compliance) tools and platforms

Experience with vulnerability scanning tools (Qualys, Nessus, Rapid7)

Basic log analysis or query experience (KQL, SPL, SQL, PowerShell)

Familiarity with the MITRE ATT&CK framework

Relevant certifications: CompTIA Security+, CySA+, or CCSK

What Success Looks Like

Assessments are completed on schedule with clear, actionable findings and evidence

Clients receive well-organized reports that effectively communicate risk, impact, and remediation priorities

Escalated security cases are analyzed thoroughly with detailed investigation notes and remediation recommendations

Customer feedback reflects strong engagement, clarity in assessment communication, and confidence in recommendations

Assessment quality improves over time through consistent documentation, feedback, and process refinement

Strong collaboration with SOC, IT, and senior security teams enhances overall MSSP service delivery

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available