Security Analyst II

Professional Search Group, Inc.

Security Analyst II

Cleveland, OH
Full Time
Paid
  • Responsibilities

    Our client is strengthening its security operations as its network and business systems grow across multiple states. They are seeking an experienced Security Analyst II to investigate and
    respond to security events across email, identity, endpoint, and network systems. This role works directly under the Senior Network Security Engineer. The person is expected to handle
    first-line investigation and response independently, help close configuration and detection gaps, and cover security operations when the senior engineer is unavailable. It suits someone with a few years of hands-on security experience who is ready to own daily security operations and grow into a senior role.

    Key Responsibilities

    Security Monitoring & Incident Response

    • Investigate security alerts across email security, identity, endpoint, firewall, VPN, and
      wireless systems.
    • Run first-line incident response, including initial scoping, evidence gathering, and
      containment under established runbooks.
    • Triage user-reported phishing through the Proofpoint reporting workflow and reply to the
      reporters.
    • Escalate confirmed incidents with clear, documented findings.

    Detection & Hardening

    • Help build, tune, and maintain detection rules and alert notification policies so that valid
      detections reach the team.
    • Assist with security configuration reviews and close identified gaps in email, identity, and
      endpoint controls.
    • Help maintain and extend the CrowdStrike Fusion SOAR triage automation.
    • Track hardening tasks through to completion and keep their status visible.

    Network & Infrastructure Support

    • Assist with firewall rule reviews, change preparation, and documentation.
    • Support VPN operations and access-related tasks.
    • Maintain network diagrams, inventory, and monitoring.
    • Assist with configuration backups, health checks, and routine maintenance

    Process & Documentation

    • Maintain runbooks, SOPs, and troubleshooting guides.
    • Document incidents, investigations, and changes accurately for later reference and
      reporting.
    • Use approved AI tooling to speed analysis, drafting, and research.

    Tools & Systems
    The person in this role will work with:

    • Proofpoint email security (TAP, TRAP, reporting workflow)
    • Microsoft 365, Entra ID, and Okta for identity and access
    • CrowdStrike Falcon (NG-SIEM, EDR, Fusion SOAR)
    • Palo Alto firewalls and GlobalProtect VPN
    • Arista switches and Ruckus wireless
    • Zabbix monitoring, syslog, and Oxidized configuration backups
    • An AI assistant such as Claude for analysis, documentation, and workflow automation

    Required Qualifications

    • Two to four years of hands-on experience in security operations, IT security, or a closely
      related role.
    • Working knowledge of IP addressing, subnets, routing, VLANs, and how firewalls and VPNs fit into an enterprise network.
    • Hands-on experience investigating security alerts and reading logs from email, identity,
      endpoint, or firewall systems.
    • Familiarity with SIEM and EDR concepts and with the phases of incident response.
    • Ability to run first-line investigation and response with limited supervision.
    • Strong written communication for incident documentation and reporting.
    • Ability to use AI tools such as Claude for analysis, research, and documentation.

    Preferred (Not Required)

    • Direct experience with Proofpoint, Okta, Microsoft 365 security, CrowdStrike, or Palo Alto
      Networks.
    • Scripting with Python or PowerShell.
    • Exposure to SOAR or other security automation.
    • Linux and command-line familiarity.
    • Security certifications such as Security+, CySA+, or equivalent.

    Growth Path

    This position is designed to grow into:

    • Senior Security Analyst
    • Security Engineer