Fortress Information Security logo
Fortress Information Security
Posted 5 days agoVerified live 1d ago

Cyber Data Analyst

Brief overview

Remote
UndergradOr in progress
$55k–$63k/yrStated range
1+ yrsMinimum
4 H-1B approvalsDept. of Labor
2 green cardsCertified filings
Data AnalysisData ModelingData ReconciliationMicrosoft ExcelAI-Assisted Data Analysis and Prompt DesignCybersecurity Vulnerability ManagementCVSS ScoringVulnerability Scanning PlatformsServiceNow or JiraConfiguration Management and Asset Inventory DataStatistical AnalysisGitWritten and Verbal Communication

About the company

Fortress Information Security logo
Fortress Information Securityfortressinfosec.com

Fortress protects governments, critical infrastructure, supply chains, and digital assets from advanced cyber threats.

Visa sponsorship history

3 years sponsoring, last filed FY2025

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
4H-1B approved
100%approval rate
1new H-1B hires
2PERM certified
$105,341median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
20231
20242
20251
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20231
20241
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
20252
Top sponsored roles
Software EngineerDeveloper

Job description

Summary

Fortress Information Security is building a pipeline for an upcoming Cyber Data Analyst opening focused on vulnerability management analytics and reporting. The role transforms scan, asset, and remediation data into trusted metrics, designs AI-assisted data-quality workflows, builds dashboards and scoring algorithms, and supports audit-ready reporting and operational improvements.

Responsibilities

  • Own the recurring monthly data-quality reporting cycle: identify, quantify, and trend data-integrity defects across vulnerability, asset, product, and remediation records; report volume, aging, root cause, and downstream operational impact to program leadership on a fixed cadence
  • Design, test, and refine AI-assisted workflows, including prompt libraries, structured extraction patterns, and batch review routines, to detect, classify, and correct data-quality defects at scale, maintaining human review and documented validation of all AI-generated output
  • Maintain and version the prompt, script, and workflow library supporting AI-assisted data remediation so that methods are reproducible, auditable, and transferable to other analysts and other client programs
  • Perform the monthly reconciliation between the business intelligence reporting layer and authoritative scan data from the enterprise vulnerability scanning platform; investigate and resolve record-level variances before publication and document the reconciliation result
  • Research and confirm vulnerability and asset ownership following report publication: resolve unassigned, stale, or mis-assigned owners against configuration management and organizational data sources, coordinate corrections with the responsible operating teams, and certify ownership accuracy for the reporting period
  • Scope, build, and deliver net-new reporting and ad hoc analytical research at the request of program and client leadership, clarifying the underlying question, identifying available and missing data, and stating the confidence and limitations of the result
  • Design and build new metrics, scoring algorithms, and dashboards from scratch, defining the measure, sourcing and modeling the data, validating against known cases, and iterating with stakeholders until the output is trusted and stable
  • Transition mature analytics products to the owning operational team once rapid iteration has ended: document the data sources, logic, refresh process, and failure modes; train the receiving team; and provide defined post-transition support
  • Partner with operations teams across the vulnerability lifecycle, including identification, disposition, tracking, analysis, exceptions, and asset and configuration management, to trace data defects to their process origin and recommend upstream corrections rather than recurring downstream cleanup
  • Produce audit-ready documentation of analytical methods, data lineage, and reporting definitions sufficient for regulatory review and for client questions on how a published number was derived
  • Support additional analytical, reporting, and program improvement projects as assigned
  • Other duties as assigned

Skills

  • At least 1 year of experience in data analysis, data science, business intelligence, security analytics, IT operations reporting, or a related field
  • Recent graduates and candidates with relevant internship experience, coursework, or completion of a data analytics or cybersecurity boot camp will also be considered
  • Demonstrated ability to work with large, imperfect data sets, joining across sources, identifying duplicates and gaps, and reconciling records between systems that do not agree
  • Proficiency building reports and dashboards, including data modeling and calculated measures
  • Advanced proficiency with Excel for data comparison and analysis, including lookups, pivot tables, and conditional logic
  • Ability to leverage AI tools and independently design, test, and refine prompts to enhance the quality, efficiency, and insight of analytical and data-remediation work, including judgment about when AI output requires human verification
  • Familiarity with cybersecurity concepts including vulnerabilities, patching, CVEs, CVSS scoring, and risk fundamentals; formal training or self-study accepted
  • Strong written and verbal communication skills, including the ability to explain analytical methods and findings to non-technical and leadership audiences
  • Proficiency with Microsoft Office tools including Word, Excel, PowerPoint, Outlook, and SharePoint
  • Strong organizational habits with attention to detail, reliable follow-through, and the ability to manage multiple concurrent workstreams against a fixed reporting calendar
  • Associate's degree or equivalent professional work experience required
  • Hands-on exposure to enterprise vulnerability scanning platforms (Tenable, Qualys, Rapid7, or similar), including how scan results, plugin behavior, and credentialed coverage affect data reliability
  • Experience with enterprise ITSM or ticketing platforms (ServiceNow, Jira, or similar) and with configuration management or asset inventory data as a reporting source
  • Experience designing metrics or scoring models from scratch, including defining the measure, validating it against known outcomes, and defending it to stakeholders
  • Experience handing off a report, dashboard, or automated process to an operating team, including documentation and training
  • Familiarity with statistical fundamentals, including distributions, sampling, trend analysis, and outlier detection, applied to operational rather than research data
  • Experience with version control (Git or similar) and with documenting analytical work for reuse
  • Exposure to regulated industries such as utilities, energy, defense, healthcare, or financial services, including NERC CIP environments
  • Exposure to evidence handling for regulatory audit (NERC CIP, BCSI), including timestamped artifacts, non-editable formats, and controlled storage locations
  • Cybersecurity-related or data platform certifications (CompTIA Security+, CySA+, Microsoft Power BI Data Analyst, or equivalent)
  • Bachelor's degree preferred, in data science, statistics, mathematics, computer science, information systems, cybersecurity, or a related field

Qualifications

Must Haves

  • At least 1 year of experience in data analysis, data science, business intelligence, security analytics, IT operations reporting, or a related field
  • Recent graduates and candidates with relevant internship experience, coursework, or completion of a data analytics or cybersecurity boot camp will also be considered
  • Demonstrated ability to work with large, imperfect data sets, joining across sources, identifying duplicates and gaps, and reconciling records between systems that do not agree
  • Proficiency building reports and dashboards, including data modeling and calculated measures
  • Advanced proficiency with Excel for data comparison and analysis, including lookups, pivot tables, and conditional logic
  • Ability to leverage AI tools and independently design, test, and refine prompts to enhance the quality, efficiency, and insight of analytical and data-remediation work, including judgment about when AI output requires human verification
  • Familiarity with cybersecurity concepts including vulnerabilities, patching, CVEs, CVSS scoring, and risk fundamentals; formal training or self-study accepted
  • Strong written and verbal communication skills, including the ability to explain analytical methods and findings to non-technical and leadership audiences
  • Proficiency with Microsoft Office tools including Word, Excel, PowerPoint, Outlook, and SharePoint
  • Strong organizational habits with attention to detail, reliable follow-through, and the ability to manage multiple concurrent workstreams against a fixed reporting calendar
  • Associate's degree or equivalent professional work experience required

Nice to Haves

  • Hands-on exposure to enterprise vulnerability scanning platforms (Tenable, Qualys, Rapid7, or similar), including how scan results, plugin behavior, and credentialed coverage affect data reliability
  • Experience with enterprise ITSM or ticketing platforms (ServiceNow, Jira, or similar) and with configuration management or asset inventory data as a reporting source
  • Experience designing metrics or scoring models from scratch, including defining the measure, validating it against known outcomes, and defending it to stakeholders
  • Experience handing off a report, dashboard, or automated process to an operating team, including documentation and training
  • Familiarity with statistical fundamentals, including distributions, sampling, trend analysis, and outlier detection, applied to operational rather than research data
  • Experience with version control (Git or similar) and with documenting analytical work for reuse
  • Exposure to regulated industries such as utilities, energy, defense, healthcare, or financial services, including NERC CIP environments
  • Exposure to evidence handling for regulatory audit (NERC CIP, BCSI), including timestamped artifacts, non-editable formats, and controlled storage locations
  • Cybersecurity-related or data platform certifications (CompTIA Security+, CySA+, Microsoft Power BI Data Analyst, or equivalent)
  • Bachelor's degree preferred, in data science, statistics, mathematics, computer science, information systems, cybersecurity, or a related field

Benefits

  • Remote and Hybrid working environment
  • Medical, dental, vision plans with employees covered up to 90% with highly progressive options for dependents and families
  • Company paid life, short- and long-term disability insurance
  • Employee Assistance Program
  • 401(k) match
  • Flexible Paid Time Off
  • Parental Leave
  • Professional growth opportunities through succession planning, up-skilling, and certifications
  • Tuition and certification reimbursement
  • Employee Referral Programs
  • Company Sponsored Events

More jobs like this