
Cybersecurity Analyst
Restorasi Ekosistem Riau (RER)
full-time
Posted on:
Location Type: Remote
Location: United States
Visit company websiteExplore more
Tech Stack
About the role
- Partner closely with IT, compliance, and business stakeholders, as well as external partners, to validate training and control activities.
- Escalate security concerns to management and any designated security lead to help ensure follow-through on corrective actions.
- Escalate findings to appropriate stakeholders and partners to ensure timely remediation and consistent security practices.
- Monitor and triage cybersecurity notifications and threat intelligence (e.g., CISA alerts); document analysis, perform research, and escalate items requiring action.
- Conduct periodic reviews of secure communications/access logs (e.g., Preveil) to identify anomalies; document findings, investigate indicators, and escalate as required.
- Review end-user security awareness training reports for completion and effectiveness; document results and escalate non-participation or high failure rates to management.
- Coordinate with partner organizations to validate equivalent end-user training is occurring; obtain, organize, and retain supporting documentation.
- Initiate and document periodic reviews of security policies and procedures; update policy documentation to reflect current controls, processes, and requirements.
- Plan, facilitate, and document periodic cybersecurity tabletop exercises; track lessons learned and follow-up actions.
- Organize and maintain evidence/artifacts supporting cybersecurity policy implementation and ongoing operational procedures (e.g., audit-ready documentation and process records).
Requirements
- 2+ years of experience in cybersecurity operations, GRC support, IT audit support, or a related security role.
- Hands-on experience reviewing logs and alerts, documenting investigations, and escalating issues through defined channels.
- Working knowledge of security awareness training programs and tracking/reporting compliance metrics.
- Ability to create and maintain clear, audit-ready documentation (policies, procedures, evidence, and exercise artifacts).
- Familiarity with common security frameworks and concepts (e.g., NIST CSF/800-171, CIS Controls) and basic risk management principles.
- Familiarity with ticketing/workflow systems and producing metrics for leadership reporting.
- Familiarity with threat advisories/feeds: CISA notifications and related vulnerability advisories.
- Experience with log review and reporting tools (platform-dependent), including secure communications access logs (e.g., Preveil).
- Familiarity with security awareness training platforms and reporting dashboards.
- Experience with documentation and evidence repositories (e.g., SharePoint/Teams/knowledge base), spreadsheets, and templates.
- Strong written communication skills and attention to detail; comfortable coordinating across internal teams and external partners.
Benefits
- Competitive wages
- Paid holidays
- Vacation
- Sick leave
- 401k matching
- Life insurance
- Health and dental benefits
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
cybersecurity operationsGRC supportIT audit supportlog reviewsecurity awareness trainingaudit-ready documentationsecurity frameworksrisk management principlesmetrics reportingdocumentation repositories
Soft Skills
written communicationattention to detailcoordinationstakeholder engagementescalation managementinvestigationanalysisorganizationfacilitationtracking lessons learned