What are the responsibilities and job description for the SECURITY ANALYST position at MSR Technology Group LLC?
- Monitor security platforms including SIEM, EDR, and cloud-native security tools for indicators of compromise,
indicators of attack, and incident response requirements.
- Utilize Microsoft Defender XDR components (Endpoint, Cloud Apps, Identity, Office 365) extensively for
monitoring, analysis, and response.
- Identify, triage, and investigate phishing incidents including those submitted manually by end-users.
- Perform Identity and Access Management activities with a focus on identifying and managing risky users, risky
sign-ins, and sign-in event correlation.
- Conduct in-depth investigations of security alerts, perform triage, and escalate or resolve incidents according to
established procedures.
- Produce thorough documentation including after-action reports and lessons learned, aligned with incident
severity and organizational standards.
- Adhere to strict threat-escalation policies based on incident classification, threat type, and statutory
requirements.
- Support the full incident response lifecycle: detection, containment, eradication, recovery, and post-incident
reporting.
- Maintain, tune, and optimize security detection rules, alerts, and automations to reduce false positives and
improve detection accuracy (with proper approvals).
- Follow established change-management processes for all configuration or detection-control modifications.
- Stay informed on emerging threats, evolving attack techniques, and advancements in security technologies.
- Assist with development and implementation of security policies and procedures.
- Prepare security documentation.
- Develop risk analysis and security reporting.
- Monitor and remediate software or hardware vulnerabilities.
- Evaluate current and future security tools and systems.
- Document hours worked by task(s).
- Follow FWC IT processes and coordinate with other FWC IT staff to ensure compliance with FWC standards.
- Complies with and enforces all agency policies, procedures, and security policies.
- Provide Technical Training (Knowledge Transfer), as required for Office of Information Technology Support Staff as