Information Security Analyst
SMARTFOX · United States
Apply & track with Apply EdgeWhat you’ll doMonitor, triage, and investigate security alerts across SIEM, EDR, and cloud platformsLead (or support, at earlier levels) incident response from detection to containment to post-incident reviewRun vulnerability scans, prioritize findings by real-world risk, and work with engineering to fix themHunt for threats proactively instead of waiting for the alarmSupport risk assessments, audits, and compliance work (SOC 2, ISO 27001, NIST, HIPAA, PCI-DSS, depending on our needs)Build detections, playbooks, and automation that make the whole team fasterRun phishing simulations and security awareness efforts people don’t dreadFind your levelLevel Typical experience What you’ll ownAnalyst I - 0-2 years: Alert triage, vulnerability tracking, documentation, learning from senior teammatesAnalyst II - 2-5 years: Independent investigations, detection tuning, risk assessments, mentoring newer analystsSenior Analyst - 5+ years: Leading incidents, threat hunting, architecture input, shaping our security roadmapWe’ll place you at the level that fits your background, and you’ll know exactly what it takes to reach the next one.What you bringMust haveA genuine curiosity about how systems break and how to protect themFoundational knowledge of networking, operating systems, and common attack techniques (phishing, malware, privilege escalation, lateral movement)Familiarity with security concepts such as the CIA triad, least privilege, and defense in depthClear written and verbal communicationBachelor’s degree in Cybersecurity, Computer Science, IT, or equivalent hands-on experience. We value skills over pedigree.Nice to have (not required)Certifications: Security+, CySA+, GCIH, CEH, CISSP, CISM, or cloud security certs (AWS, Azure, GCP)Experience with tools such as Splunk, Microsoft Sentinel, CrowdStrike, Tenable/Qualys, or similarScripting in Python, PowerShell, or BashKnowledge of MITRE ATT&CK or the NIST Cybersecurity FrameworkHome lab, CTF, bug bounty, or open-source contributions. We love seeing what you build on your own time.