Job Description
Title: SECURITY ANALYST
Visas: USC/GC
Need LinkedIn, VISA DL
9-12 years of profiles
Greenwich, CT OR Palm Beach, FL – Local
Hybrid 2 days in the office
I would say its a solid mid level role.
This is a hands-on operational role centered on keeping our tools healthy, well-tuned, and well-documented. We are looking for someone organized, detail-oriented, and reliable, with a foundational security background (Security+ and/or CySA+) and the discipline to own recurring tasks and keep them on track with minimal oversight.
Core Responsibilities
Tool health monitoring & maintenance
·Proactively watch for and resolve (or escalate) tool-health issues, such as:
o Servers or endpoints that stop reporting into Sumo Logic and our other security tools.
o Tenable Vulnerability Scans and Maintenance
o Defender, ThreatLocker, or other agents going offline, outdated, or missing.
o Fortinet / FortiSASE health and connectivity issues.
·Run routine configuration and policy reviews to catch drift and gaps.
Documentation
·Document recurring issues, their causes, and how they were resolved.
·Build and maintain runbooks, SOPs, and asset inventories, keeping them current as things change — supporting our ISO 27001:2022 ISMS.
·Keep clean records of configuration changes and exceptions.
·Gather and organize evidence for our Internal Audit team — configurations, logs, reports, and records — to support ISMS and audit activities.
Staying current
·Keep up with new features and capabilities across our tools (release notes, vendor updates) and flag/document anything worth adopting.
Routine operations
·Tune alerts to reduce false positives and noise, under direction.
·Maintain allowlists, exceptions, and approval requests.
·Review and clean up email quarantines (Mimecast, Abnormal AI, Defender for Office 365).
·Administer KnowBe4 — run security awareness training and phishing-simulation campaigns, track completion, and report results.
Reporting
·Generate recurring reports across the stack — tool health and coverage, alert volumes and trends, vulnerability status, email security metrics, and phishing/training results.
·Produce summary reports for management and metrics/KPIs that feed our ISMS reviews.
·Build standardized, reusable report templates so recurring reports are consistent and efficient to produce each cycle.
What to Look For in a Candidate
Required
·CompTIA Security+ and/or CySA+ (or actively pursuing).
·Foundational security knowledge: CIA triad, common attack types, networking fundamentals (TCP/IP, DNS, ports), basic log review.
·Familiarity with Windows and the Microsoft 365 / Entra / Azure ecosystem.
·Strong attention to detail and a methodical, organized approach.
·Reliability and follow-through on recurring tasks; comfortable following procedures and asking questions.
·Clear written communication for documentation and reporting.
Nice to have
·Hands-on exposure to any of our tools (listed below) — we don't expect all of them.
·Experience working alongside an MDR/MSSP or managed SOC.
·Labs or coursework showing practical skills (TryHackMe, Hack The Box, etc.).
·Familiarity with ISO/IEC 27001:2022 — our ISMS is built on it, and this role's documentation directly supports it.
Our Environment
·SIEM: Sumo Logic
·Endpoint / XDR: Microsoft Defender XDR suite (E5) — Defender for Endpoint, Office 365, Identity, and Cloud Apps; plus ThreatLocker
·Data / compliance: Microsoft Purview
·Email security: Mimecast, Abnormal AI, Defender for Office 365
·Network: Fortinet firewalls, FortiSASE
·Vulnerability mgmt: Tenable (managed by eSentire)
·MDR / 24×7 SOC: eSentire
·PAM: Delinea
·Security awareness: KnowBe4
Kind Regards,
Deep Patel
Sr. Technical Recruiter
ZealHire Inc.
14 Wall Street 20th Floor | New York, NY 10005
