About the Security Analyst role
A Security Analyst protects an organization's systems and data. They monitor networks and applications for suspicious activity, investigate alerts, respond to incidents, and assess vulnerabilities before attackers can exploit them. They are often the first line of defense when something goes wrong.
The role blends technical depth with judgment under pressure. A strong analyst can read logs and network traffic, separate real threats from noise, and document findings clearly enough to support both remediation and compliance audits. Many analysts also run phishing simulations, manage vulnerability scans, tune detection rules, and help teams across the company follow security policies without slowing them down.
In your posting, describe your environment and where the role sits: SOC monitoring, incident response, vulnerability management, or a generalist mix. Name the tools you use, such as your SIEM and EDR platforms, and mention any compliance frameworks like SOC 2 or ISO 27001 the analyst will support.
Security Analyst job description template
Free download. Use it offline or customize it for your company.
Job brief
We are hiring a Security Analyst to watch our systems and act when something is wrong. You will monitor for suspicious activity, investigate what the alerts are really telling you, respond to incidents, and find the weaknesses before somebody else does.
This suits somebody who can read traffic and logs and separate a genuine threat from noise, write it up clearly enough for both remediation and an audit, and help colleagues work securely without becoming the department that says no.
Responsibilities
- Monitor security alerts and events across networks, endpoints, and cloud environments
- Triage and investigate potential incidents, escalating and containing threats when needed
- Conduct vulnerability scans, prioritize findings by risk, and track remediation with system owners
- Tune SIEM detection rules to reduce false positives and improve coverage
- Perform log analysis and forensics to determine the scope and root cause of incidents
- Document incidents, findings, and response actions for internal review and compliance audits
- Support security awareness efforts, including phishing simulations and employee training
- Assess the security posture of new tools, vendors, and system changes
- Help maintain compliance with frameworks such as SOC 2, ISO 27001, or GDPR
Requirements and skills
- Has worked in security operations, incident response, or vulnerability management
- Reads logs and network traffic and reaches a defensible conclusion
- Has used detection and response tooling in a real environment
- Investigates methodically and documents what was found and why it matters
- Understands the common attack paths well enough to anticipate them
- Scripts in Python or PowerShell to automate the repetitive parts
- Writes clearly for incident reports and audit evidence
- A relevant degree, or the practical experience that replaced one
Nice to have
- Certifications such as Security+, CySA+, GCIH, or CISSP
- Experience securing cloud environments on AWS, Azure, or GCP
- Familiarity with threat intelligence platforms and the MITRE ATT&CK framework
- Experience supporting SOC 2 or ISO 27001 audits
Generate a custom Security Analyst job description
Need a version tailored to your company, seniority level, or industry? Describe the role and our AI job description generator will draft one in seconds.
