Summary
DirectDefense is a cybersecurity services company focused on security defense, managed services, and improving clients’ security posture. The Associate Security Analyst will monitor and investigate security events, hunt for threats, support SIEM detection development, document incident response activities, assess vulnerabilities, and provide actionable reporting and remediation guidance.
Responsibilities
- Analyze user behavior, logs, and alerts from a variety of different technologies (NGAV / EDR, Firewall, IDS / IPS, Web Proxy, etc.) for clients from a variety of industries
- Monitor, triage, and investigate SIEM alarms and client support requests
- Assist with developing and tuning new SIEM detection capabilities
- Contribute to and participate in documenting Incident Response activities
- Conduct regular vulnerability scans, analyze the results, and suggest remediations
- Conduct reporting on security threats, metrics, and defense effectiveness and deliver to a variety of client audiences
Skills
- 3-5 years of relevant experience in Cybersecurity, risk management, security operations, network operations, or equivalent knowledge
- Experience with SIEM and EDR tools for monitoring, detection, and response to potential security incidents
- Proven experience investigating potential threats, either through proactive threat hunting or analyzing customer-reported tickets
- Strong ability to triage events, accurately identifying real threats versus false positives
- Proficient in log analysis, interpreting system logs to detect security events and identify root causes
- Familiarity with threat intelligence, applying findings to improve detection and response efforts
- Understanding of network protocols and system vulnerabilities to assess and address security risks effectively
- Knowledge of regulatory compliance and security frameworks (e.g., ISO, NIST, PCI, GDPR) and their application
- Excellent analytical and critical thinking skills, enabling accurate evaluation of complex security data
- Effective communication skills, capable of documenting findings clearly and providing actionable recommendations
Qualifications
Must Haves
- 3-5 years of relevant experience in Cybersecurity, risk management, security operations, network operations, or equivalent knowledge
- Experience with SIEM and EDR tools for monitoring, detection, and response to potential security incidents
- Proven experience investigating potential threats, either through proactive threat hunting or analyzing customer-reported tickets
- Strong ability to triage events, accurately identifying real threats versus false positives
- Proficient in log analysis, interpreting system logs to detect security events and identify root causes
- Familiarity with threat intelligence, applying findings to improve detection and response efforts
- Understanding of network protocols and system vulnerabilities to assess and address security risks effectively
- Knowledge of regulatory compliance and security frameworks (e.g., ISO, NIST, PCI, GDPR) and their application
- Excellent analytical and critical thinking skills, enabling accurate evaluation of complex security data
- Effective communication skills, capable of documenting findings clearly and providing actionable recommendations
Benefits
- Up to 10% annual bonus
- 401(k)
- AD&D Insurance
- Dental Insurance
- Disability insurance
- Health insurance
- Life insurance
- Vision insurance
- Flex PTO program
- Paid certification and continuing education
- Remote in Englewood, CO