Summary
Momentum is a respected collection of independent companies serving as a premier global business transformation partner. They are seeking a dynamic individual for the role of Associate Cybersecurity Analyst, where the candidate will support monitoring, vulnerability tracking, audit activities, and compliance support as part of the IT team.
Responsibilities
- Review alerts in MDR/SOC tooling. Identify false positives and escalate suspicious activity to the Cybersecurity Operations Engineer per defined runbooks
- Monitor security dashboards during assigned windows. Document findings clearly for handoff and maintain accurate alert disposition records
- Support the development and refinement of triage runbooks as you build environment familiarity
- Run scheduled vulnerability scans across defined asset groups. Validate and categorize findings under guidance
- Track remediation progress and update the vulnerability register. Flag overdue patch management SLAs for escalation and help generate leadership reports
- During active incidents, gather requested evidence, document timelines, and support investigation tasks under direct guidance
- Maintain IR documentation: logs, timelines, and post-incident notes. Participate in tabletop exercises as observer and note-taker
- Collect and organize audit evidence for SOC 2 and ITGC activities. Complete control checklists accurately and on schedule under GRC Analyst direction
- Support client security questionnaire responses by gathering documentation and evidence from internal systems
- Assist with policy attestation tracking, vendor risk register updates, and NIST CSF remediation documentation
- Support KnowBe4 campaign administration: track completion rates, pull reporting data, and flag non-completion for follow-up
- Maintain accurate documentation of completed tasks, findings, and escalations. Use AI tools to accelerate documentation and draft initial content for senior review
Skills
- Graduates in Winter 2026 or Spring 2027 with a Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field
- Foundational understanding of cybersecurity concepts: CIA triad, common attack types, network fundamentals, and basic security controls
- Exposure to GRC concepts - SOC 2, NIST CSF, or compliance frameworks - through coursework, certification study, or internship
- Strong written communication. You document clearly and completely
- Active daily use of AI tools - at Momentum, we have 100% internal AI adoption
- Genuine curiosity about security: threat news, home labs, security blogs
- Security+ or equivalent entry-level certification: CompTIA Security+, Google Cybersecurity Certificate, or similar
- Hands-on experience with SIEM platforms, vulnerability scanners, or MDR tooling through coursework, labs, or CTF competitions
- Exposure to CrowdStrike, Okta, Jamf, or similar enterprise security tooling
- Basic scripting or automation in Python, Bash, or PowerShell applied to a security or IT task
- Internship or co-op experience in IT, security operations, or GRC
Qualifications
Must Haves
- Graduates in Winter 2026 or Spring 2027 with a Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field
- Foundational understanding of cybersecurity concepts: CIA triad, common attack types, network fundamentals, and basic security controls
- Exposure to GRC concepts - SOC 2, NIST CSF, or compliance frameworks - through coursework, certification study, or internship
- Strong written communication. You document clearly and completely
- Active daily use of AI tools - at Momentum, we have 100% internal AI adoption
- Genuine curiosity about security: threat news, home labs, security blogs
Nice to Haves
- Security+ or equivalent entry-level certification: CompTIA Security+, Google Cybersecurity Certificate, or similar
- Hands-on experience with SIEM platforms, vulnerability scanners, or MDR tooling through coursework, labs, or CTF competitions
- Exposure to CrowdStrike, Okta, Jamf, or similar enterprise security tooling
- Basic scripting or automation in Python, Bash, or PowerShell applied to a security or IT task
- Internship or co-op experience in IT, security operations, or GRC
Benefits
- Discretionary annual bonus, determined based on both the company's business performance and individual contributions
- Healthcare benefits
- A 401(k) plan with an employer match
- Short-term and long-term disability coverage
- Life insurance
- Paid time off
- Parental leave
- Various paid holidays