Apply Edge Start your job search

Security Analyst

CHAMP · Cleveland, OH

Apply & track with Apply Edge

At CHAMP, we are redefining the technology used by Motor Vehicle Agencies and their stakeholders. We do so with innovative, cloud-based software that enhances efficiency, security, and interoperability. Our solutions replace outdated processes with modern, scalable platforms, enabling organizations to operate with greater speed and accuracy in an increasingly digital world.Security Analyst (Level I / Level II)Location: Cleveland (Onsite – 4 days in office)Department: SecurityReports To: Director of SecurityTravel: Up to 10%Sponsorship: This position is not eligible for Visa SponsorshipRelocation: This position is not eligible for Relocation AssistanceYour ImpactWe are seeking a motivated Security Analyst to join our Security team. This position is responsible for supporting Security Operations Center (SOC) activities, Detection & Response, Security Compliance, and General Security initiatives across the organization.The ideal candidate has a strong cybersecurity foundation, excellent analytical skills, and a passion for continuous improvement. Preference will be given to candidates with hands-on Security Operations Center experience, particularly with DataDog Cloud SIEM, although experience with Splunk, Microsoft Sentinel, CrowdStrike Falcon Complete, QRadar, LogRhythm, Elastic, or similar SIEM/SOC platforms is also valuable.This position requires a hands-on engineer who can balance strategic program development with day-to-day operational execution across multiple security domains.This role is ideal for a cybersecurity professional who wants broad exposure across threat detection, incident response, cloud security, compliance, vulnerability management, and security automation while helping mature CHAMP's overall security posture.Every Security Analyst, regardless of level, is expected to own something, improve something, automate something, and challenge existing assumptions. The difference between levels is not whether they contribute and demonstrate an ownership mentality, but the size and impact of what they contribute.What You Will DoSecurity Monitoring and SIEM Operations SupportSupport the implementation, administration, and ongoing operation of the enterprise SIEM platformMaintain onboarding, validation, and maintenance of security log sources across cloud, application, infrastructure, identity, endpoint, and network environments.Monitor the health, availability, and effectiveness of security logging pipelines and ingestion processes.Continuously evaluate enterprise systems and identify opportunities to onboard additional data sources that improve organizational visibility and threat detection capabilities.Develop and maintain dashboards, reports, operational metrics, and monitoring views supporting security operations, leadership reporting, and program maturity initiatives.Assist with development, testing, validation, and tuning of detection rules, alerts, correlation logic, and security monitoring content.Review false positives, detection gaps, and monitoring deficiencies and recommend improvements to increase detection effectiveness.Security Operations and Incident Response CoordinationServe as an internal point of contact for the organization's third-party Security Operations Center and managed detection and response providers.Review, validate, and oversee investigations performed by third-party Security Operations Center analysts.Coordinate incident escalations between the Security Operations Center provider and internal engineering, infrastructure, and business stakeholders.Assist with determining appropriate response actions and escalation paths for security incidents.Support incident response activities including investigation, containment, eradication, recovery, and lessons learned activities.Participate in post-incident reviews and help drive corrective actions and long-term improvements.Assist with forensic evidence collection, incident documentation, and response tracking.Develop and maintain incident response playbooks, escalation procedures, and Secruity Operations Center operational runbooks.Maintain awareness of emerging threats, vulnerabilities, attack techniques, and detection opportunities that may impact the organization.Security Programs MaturityEstablish and measure key performance indicators related to security monitoring, incident response, detection effectiveness, and SOC service delivery.Monitor the effectiveness of third-party SOC services and identify opportunities for operational improvements.Partner with compliance to ensure security monitoring supports regulatory, audit, and organizational requirements.Drive continuous improvement initiatives that enhance visibility, detection capabilities, operational efficiency, and overall security posture.Promote automation opportunities that improve investigation workflows, reporting, alert triage, and security operations efficiency.Participate in security projects and initiatives that improve overall organizational security posture.Support Security Programs and InitiativesSupport continuous monitoring objectives for regulatory compliance requirements.Support evidence collection efforts for major audits such as SOC2 and GovRAMP frameworks.Assist with vulnerability scan results, triage, and remediation tracking.Participate in automation development and identifying opportunities to reduce manual efforts.Support daily operations of endpoint security including security event investigations, findings review, remediation tracking, and identifying/implementing improvements for endpoint security.Assist with cloud security findings and identity security solutions.Review identity-related alerts, suspicious sign-in activity, privileged account events, guest user activity, and data-sharing risks in Microsoft EntraID environment.Requirements and QualificationsBachelor's or Associate’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or related discipline (or equivalent experience).Level I: 1-3 years of cybersecurity, SOC, IT operations, systems administration, or related experience.Level II: 3-5 years of cybersecurity, SOC, incident response, threat detection, or related experience.Experience working with SIEM, EDR, security monitoring, or security operations platforms.Understanding of common cyber-attack techniques, indicators of compromise, and threat actor behaviors.Familiarity with incident response processes and security investigations.Ability to analyze logs, alerts, and security telemetry.Strong analytical, troubleshooting, and problem-solving skills.Strong analytical, troubleshooting, and problem-solving skills.A high level of organization and attention to detail is requiredExcellent communication and interpersonal skillsStrategic thinkerDemonstrated curiosity and desire to continuously learn.Flexible approach, able to operate effectively with uncertainty and changeDriven, self-motivated, and enthusiastic with the ability to build and maintain positive relationshipsPreferred RequirementsHands-on DataDog Security Monitoring or Cloud SIEM experience.Previous Security Operations Center (SOC) experience.Experience with tools such as CrowdStrike, Microsoft Sentinel, Splunk, AWS Security Hub, GuardDuty, OktaExperience with vulnerability management programs and tooling.Experience writing Python or other scripting language.Understanding of cloud security concepts within AWS.Familiarity with MITRE ATT&CK Framework.Security certifications such as CySA+, Security+, SSCP, GSEC, GCIH, GCIA, or GMONExperience supporting regulated environments and compliance frameworks.Perks + BenefitsCompetitive SalaryAnnual Bonus PotentialHealth, Dental & Vision InsuranceUnlimited PTO PolicyMatching 401K with immediate vestingSubsidized Lunches at our Cleveland HeadquartersFast Paced work environment in a growth companyNewly Renovated Office SpaceSalary RangeLevel I - Associate Security Analyst: $80,000 - $100,000Level II - Security Analyst: $95,000 - $115,000This is a good faith estimate, and final compensation may vary based on experience and skills.We celebrate diversity and are committed to creating an inclusive environment for all employees. We welcome applicants of all backgrounds, including veterans and individuals with disabilities. If you need accommodations during the application or interview process, please let us know. We are here to help.By joining CHAMP, you will be an integral member of our team with many opportunities for personal growth and upward mobility in a growing organization. We have a great culture that is flexible, collaborative and welcoming.