Associate Security Analyst
Job description
Associate Security Analyst at Bamboohr.
About the role
As an Associate Security Analyst at Bamboohr, you will play a crucial role in safeguarding our digital assets and ensuring the integrity of our information systems. This position is ideal for individuals who are about cybersecurity and eager to develop their skills in a dynamic and supportive environment. You will work closely with senior security professionals to identify vulnerabilities, monitor security incidents, and implement effective security measures. Your contributions will be vital in maintaining the security posture of our organization and protecting our clients' sensitive information.
Key facts
What you'll do
- Assist in the identification and assessment of security vulnerabilities across various systems and applications to ensure compliance with industry standards and best practices.
- Monitor security alerts and incidents, analyzing logs and reports to detect potential threats or breaches in real-time.
- Collaborate with IT teams to implement security controls and measures that mitigate risks and enhance the overall security framework.
- Conduct regular security assessments, including penetration testing and vulnerability scanning, to evaluate the effectiveness of existing security protocols.
- Develop and maintain documentation related to security policies, procedures, and incident response plans to ensure clarity and compliance.
- Participate in security awareness training programs for employees, promoting a culture of security consciousness within the organization.
- Assist in the investigation of security incidents, gathering evidence, and providing detailed reports on findings and recommendations for remediation.
- Stay updated on the latest cybersecurity trends, threats, and technologies to continuously improve the security posture of the organization.
- Support the implementation of security tools and technologies, including firewalls, intrusion detection systems, and antivirus solutions.
- Work closely with external vendors and partners to ensure that third-party services comply with our security standards and requirements.
- Participate in regular security audits and assessments to ensure adherence to regulatory requirements and internal policies.
- Contribute to the development of incident response strategies and participate in tabletop exercises to prepare for potential security incidents.
Requirements
- A bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- A minimum of 1-2 years of experience in a cybersecurity or information security role, preferably in a corporate environment.
- Familiarity with security frameworks and standards such as ISO 27001, NIST, or CIS.
- Basic understanding of network protocols, firewalls, and intrusion detection/prevention systems.
- Experience with security tools such as SIEM, vulnerability scanners, and endpoint protection solutions.
- Strong analytical and problem-solving skills, with the ability to think critically under pressure.
- Excellent communication skills, both written and verbal, to effectively convey security concepts to technical and non-technical stakeholders.
- Ability to work independently as well as collaboratively within a team environment.
- A commitment to ongoing professional development and staying current with industry trends and best practices.
Nice to have
- Relevant certifications such as CompTIA Security+, Certified Ethical Hacker (CEH), or Certified Information Systems Security Professional (CISSP).
- Experience with cloud security principles and practices, particularly in environments such as AWS or Azure.
- Knowledge of programming or scripting languages (e.g., Python, PowerShell) to automate security tasks and processes.
Skills & tools
- Proficient in using security information and event management (SIEM) tools for monitoring and analysis.
- Familiarity with vulnerability assessment tools and methodologies to identify and remediate security weaknesses.
- Understanding of incident response processes and best practices for managing security incidents.
- Knowledge of data protection regulations and compliance requirements, such as GDPR or HIPAA.
Practical notes
- This position is based in Nugegoda, Western, and requires a full-time commitment.
- Candidates must be eligible to work in Sri Lanka; visa sponsorship is available for qualified individuals.
- The role may involve occasional on-call responsibilities or after-hours work in response to security incidents.
- Interested applicants can apply through the following link: [Bamboohr Careers](https://codimitepvt.bamboohr.com/careers/107).
META
Company: Bamboohr
Title: Associate Security Analyst
Listed
location: Nugegoda, Western
Job type: Full-time