Cybersecurity Operations Analyst
Spaulding Ridge is an advisory and IT implementation firm. We help global organizations get financial clarity into the complex, daily sales, and operational decisions that impact profitable revenue generations, efficient operational performance, and reliable financial management.
At Spaulding Ridge, we believe all business is personal. Core to our values is our relationships with our clients, our business partners, our team, and the global community. Our employees dedicate their time to helping our clients transform their business, from strategy through implementation and business transformation.
What You Will Do and Learn:
The Cybersecurity Operations Analyst will support the Cybersecurity Manager in maintaining and improving Spaulding Ridge's security posture. This entry-level role is ideal for someone looking to develop a career in cybersecurity while gaining hands-on experience across security operations, vulnerability management, identity and access management, cloud security, and compliance.
The analyst will assist in monitoring security events, responding to security alerts, supporting security projects, and maintaining security documentation while learning from senior members of the Technology & Security team.
Security Operations
- Monitor and analyze security alerts from SIEM, EDR, Firewall, WAF, IDS/IPS, email security, and cloud security platforms.
- Conduct and Support threat hunting and detection of tuning activities.
- Monitors open-source and proprietary threat intelligence feeds daily to research threat actor tactics, techniques, and procedures (TTPs).
- Support the investigation and triage of security alerts and incidents under the guidance of the Cybersecurity Manager.
- Assist with incident response activities, including documentation, evidence collection, and follow-up actions.
- Help maintain security playbooks and operational procedures.
Vulnerability Management
- Assist with vulnerability scanning across endpoints, servers, and cloud environments.
- Track remediation activities and follow up with system owners.
- Help prepare vulnerability reports and dashboards.
- Support penetration testing and remediation validation.
Identity & Access Management
- Support user provisioning, deprovisioning, and access reviews.
- Assist with periodic access recertification activities.
- Help maintain least-privilege and role-based access controls.
- Support MFA, Conditional Access, SSO, and Privileged Access Management.
Cloud & Infrastructure Security
- Assist with security reviews of Microsoft 365, Azure, and other cloud platforms.
- Support implementation of security best practices and configuration reviews.
- Help monitor cloud security recommendations and remediation activities.
- Monitor Azure, Microsoft 365, AWS, and SaaS platform security posture and Assist with Zero Trust security initiatives.
Security Governance & Compliance
- Support ISO 27001 activities, including policy reviews, evidence collection, internal audits, and corrective actions.
- Assist with third-party security assessments and vendor reviews.
- Help maintain security documentation and records.
Security Awareness
- Support security awareness campaigns and phishing simulations.
- Assist in developing security communications and training materials.
- Help answer security-related questions from employees.
Security Tool Administration
- Assist with the administration, maintenance, and integration of security tools.
- Support security monitoring improvements and automation initiatives.
- Help troubleshoot issues related to security technologies.
Education and Work Experience Requirements:
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent experience).
- 1-2 years of experience in cybersecurity, systems administration, cloud administration, or related technical roles.
- Good to have: Knowledge of security frameworks and best practices, including ISO 27001, NIST Cybersecurity Framework (CSF), and CIS Controls.
- One or more of the following certifications are preferred: Microsoft SC-900: Security, Compliance, and Identity Fundamentals, CompTIA Security+, eJPT (eLearnSecurity Junior Penetration Tester)
- Strong analytical and problem-solving skills.
- Basic understanding of: Microsoft 365, Azure fundamentals, Networking concepts, Active Directory / Entra ID, SIEM and EDR concepts, Vulnerability management, MFA and Identity & Access Management, Windows administration, Information security principles.
- Strong willingness to learn and develop technical skills.
- Analytical mindset and attention to detail.
- Good communication and documentation skills.
- Ability to manage multiple tasks and priorities.
Spaulding Ridge’s Commitment to an Inclusive Workplace
When we engage the expertise, insights, and creativity of people from all walks of life, we become a better organization, we deliver superior services to clients, and we transform our communities and world for the better.
At Spaulding Ridge, we believe our team should reflect the rich diversity of society and we take seriously the responsibility to cultivate a workplace where every bandmate feels accepted, respected, and valued for who they are. We do this by creating a culture of trust and belonging, through practices and policies that support inclusion, and through our employee led Employee Resource Groups (ERGs): CRE (Cultural Race and Ethnicity), Women Elevate, PROUD and Mental Wellness Alliance.
The company is committed to offering Equal Employment Opportunity and to providing reasonable accommodation to applicants with physical and/or mental disabilities. If you are interested in applying for employment with Spaulding Ridge and are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to our VP of Human Resources, Cara Halladay ([email protected]). Requests for reasonable accommodation will be considered on a case-by-case basis.
Qualified applicants will receive consideration for employment without regard to their age, race, religion, national origin, gender, sexual orientation, gender identity, protected veteran status or disability.
Job Details
Experience
Entry · 1–2 yrs