Booz Allen Hamilton logo
Booz Allen Hamilton

Booz Allen Hamilton is an award-winning provider of strategic innovation, management consulting, technology, and engineering services. Founded in 1914, the comp

Cyber Security Analyst

Location

Texas

Posted

5 days ago

Salary

$77.5K - $176K / year

Seniority

Senior

Bachelor Degree

Job Description

Cyber Security Analyst

Booz Allen Hamilton

ISSO and Cyber Security Analyst Location: San Antonio United States Full time Job Description: The Opportunity: Provide expert information security support for an Air Force contract, ensuring compliance with Department of Defense standards and maintaining a secure operational environment. Leverage analytical skills, deep technical knowledge, and the ability to communicate effectively with both technical and non-technical stakeholders. Design, implement, and manage policies and procedures to ensure database and software security. You Have: - 6+ years of experience in cyber security or information assurance - Secret clearance - Bachelor's degree in a Computer Science, Cyber Security, or Information Technology field - DoD 8570.01-M IAT II certification, such as Security+, CCNA Security, or GSEC Nice If You Have: - Experience supporting Air Force or other DoD contracts - Experience with NIST RMF, DIACAP, and FISMA compliance frameworks - Experience with STIGs and security hardening of systems - Experience with incident response and digital forensics - Knowledge of vulnerability assessment tools such as Nessus or Qualys - Knowledge of cloud security such as AWS, Azure or DoD Cloud - Ability to lead security audits and assessments - Possession of strong documentation and technical writing skills - Advanced certifications such as CISSP, CASP+, or CEH Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Secret clearance is required. Compensation At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page. Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $77,500.00 to $176,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date. Identity Statement As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Candidate AI Usage Policy AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided. Work Model Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings. - Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility. - Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility. - Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role. Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.

Related Job Pages

More Security Analyst Jobs

Associate Security Analyst

Hornblower Group Inc.

Hornblower Group is a global leader in experience and transportation. Spanning a 100-year history, Hornblower Group’s portfolio of international offerings includes water- and land-based experiences and ferry and transportation services. City Experiences, Hornblower Group’s premier experience division, offers dining and sightseeing cruises and walking and food tours through the City Cruises, Walks, and Devour brands. City Ferry, part of Hornblower Group’s Ferry and Transportation Division, is the largest private operator of high-speed passenger and vehicle ferries in the United States, carrying more than 10 million passengers annually. Hornblower Group’s subsidiaries include Hornblower Marine, which provides vessel outhaul and maintenance services, and Seaward Services, Inc., a full-service shipping, waterfront logistics, and management company. Anchor Operating System, LLC, provides reservation, ticketing, and website integration services for clients in the transportation, tourism, and entertainment industries. Hornblower Group’s global portfolio covers over 10 countries, over 50 U.S. cities, and serves more than 20 million guests annually. Headquartered in Orlando, Florida, with additional corporate offices in various locations including San Francisco, Boston, Chicago, London, New York, Dublin, and Ontario.

Role Description Cybersecurity at Hornblower is responsible for protecting the business. We do so by establishing, maintaining, and enforcing policies to meet and exceed industry standards for security and compliance. We are seeking a motivated Junior Security Analyst to join our information security team. In this role, you will help defend our organization against cyber threats by: - Monitoring security tools - Investigating alerts - Supporting incident response efforts This is an excellent opportunity for an early-career professional to develop hands-on experience across a broad range of security disciplines while working alongside experienced practitioners. Responsibilities - Monitor security information and event management (SIEM) platforms, intrusion detection systems, and other security tools for suspicious activity. - Triage and investigate security alerts, escalating confirmed incidents to senior analysts according to established playbooks. - Assist in incident response activities, including evidence collection, containment, and post-incident documentation. - Conduct regular vulnerability scans and help track remediation efforts with system owners. - Review logs from firewalls, endpoint protection, identity providers, and cloud platforms to identify anomalies. - Support phishing investigations, including analysis of suspicious emails, URLs, and attachments in a sandboxed environment. - Contribute to the maintenance of security documentation, runbooks, and knowledge base articles. - Assist with user access reviews, security awareness initiatives, and routine compliance tasks. - Stay current on emerging threats, vulnerabilities, and attacker techniques, sharing relevant findings with the team. Qualifications - Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field — or equivalent practical experience (internships, home labs, military, or self-directed study). - Foundational understanding of networking concepts (TCP/IP, DNS, HTTP/S, VPNs) and common operating systems (Windows and Linux). - Familiarity with core security concepts: the CIA triad, common attack types (phishing, malware, brute force, privilege escalation), and basic defensive controls. - Hands-on exposure to SIEM platforms (Microsoft Sentinel, Elastic, etc.), EDR tools, or vulnerability scanners. - Basic scripting ability in Python, PowerShell, or Bash for log parsing or task automation. - Familiarity with frameworks such as MITRE ATT&CK, NIST CSF, or the Cyber Kill Chain. - Experience with cloud environments (AWS, Azure, or Google Cloud) and their native security services. - Strong analytical and problem-solving skills, with attention to detail. - Clear written and verbal communication, including the ability to document findings for both technical and non-technical audiences. - Eagerness to learn and a methodical, curious approach to investigation. Requirements - None specified. Benefits - None specified. Company Description Hornblower Group is a global leader in experience and transportation. Spanning a 100-year history, Hornblower Group’s portfolio of international offerings includes water- and land-based experiences and ferry and transportation services. - City Experiences, Hornblower Group’s premier experience division, offers dining and sightseeing cruises and walking and food tours through the City Cruises, Walks, and Devour brands. - City Ferry, part of Hornblower Group’s Ferry and Transportation Division, is the largest private operator of high-speed passenger and vehicle ferries in the United States, carrying more than 10 million passengers annually. - Hornblower Group’s subsidiaries include Hornblower Marine, which provides vessel outhaul and maintenance services, and Seaward Services, Inc., a full-service shipping, waterfront logistics, and management company. - Anchor Operating System, LLC, provides reservation, ticketing, and website integration services for clients in the transportation, tourism, and entertainment industries. - Hornblower Group’s global portfolio covers over 10 countries, over 50 U.S. cities, and serves more than 20 million guests annually. - Headquartered in Orlando, Florida, with additional corporate offices in various locations including San Francisco, Boston, Chicago, London, New York, Dublin, and Ontario.

United States
Job Closed
EisnerAmper logo

Senior SOC Analyst

EisnerAmper

Solutions that help you transform, build, innovate, connect.

Full TimeRemoteTeam 1,001-5,000Since 1963H1B Sponsor

Role Description At EisnerAmper, we look for individuals who welcome new ideas, encourage innovation, and are eager to make an impact. EisnerAmper is seeking a Senior SOC Analyst to join our global cybersecurity team and play a critical role in safeguarding the firm’s technology ecosystem and client data. This position offers the opportunity to lead incident response efforts, mentor junior analysts, and continuously improve our SOC capabilities in a fast-paced, professional environment. This is an exciting opportunity to join a firm where cybersecurity is a strategic priority. You’ll work with a forward-thinking team dedicated to protecting our systems, data, and client trust—while continuing to grow your leadership and technical expertise in an enterprise environment. What Work You Will be Responsible For: - Lead threat detection and incident response efforts, including containment, recovery, and root cause analysis for high-severity incidents. - Monitor SIEM, EDR, cloud platforms, and other tools to identify, triage, and investigate potential security threats. - Proactively hunt for threats using threat intelligence and MITRE ATT&CK framework to surface risks and enhance monitoring. - Develop and optimize SOC use cases, detection rules, and response playbooks. - Act as a point of escalation for junior analysts and ensure efficient alert handling and incident escalation. - Mentor SOC team members, review investigation reports, and lead by example in documentation and best practices. - Collaborate with IT, audit, compliance, and business teams to remediate issues and improve defenses. - Support audit, compliance, and regulatory needs with detailed and accurate incident documentation. Qualifications - 5+ years of experience in information security, with at least 2–3 years in a SOC analyst role (Tier 2 or above) with hands-on experience with Google SecOps SIEM, Microsoft Defender for Endpoint (EDR), ReliaQuest GreyMatter, and log analysis from network, endpoint, and cloud sources. - Bachelor's degree in Cybersecurity, Computer Science, or related field (or equivalent work experience). Preferred/Desired Skills - Strong understanding of cloud security (Azure, AWS), using tools like Microsoft Defender for Cloud, and AWS GuardDuty. - Demonstrated ability to lead incident response end-to-end, including forensics and root cause analysis. - Familiarity with scripting/automation (Python, PowerShell, Bash) and SOAR platforms. - Working knowledge of frameworks such as MITRE ATT&CK and NIST CSF. - Excellent written and verbal communication skills, with the ability to convey technical details to various stakeholders. - Certifications relevant to cybersecurity and enterprise IT systems. - Experience with IDS/IPS, DLP, IAM, or vulnerability management tools in large-scale environments. - Knowledge of DevSecOps, container security (e.g., Kubernetes), and SaaS/cloud application protection. - Prior experience in a regulated or professional services environment (e.g., finance, audit, advisory). Company Description EisnerAmper is one of the largest accounting, tax, and business advisory firms, with approximately 500 partners and 5,500 employees across the world. We combine responsiveness with a long-range perspective; to help clients meet the pressing issues they face today and position them for success tomorrow. - Our clients are enterprises as diverse as sophisticated financial institutions and start-ups, global public firms, and middle-market companies, as well as high net worth individuals, family offices, not-for-profit organizations, and entrepreneurial ventures across a variety of industries. - We are also engaged by the attorneys, financial professionals, bankers, and investors who serve these clients.

United States
Job Closed
BMC Software logo

Senior Cybersecurity Analyst

BMC Software

Founded in 1980, BMC Software is a privately-held, business-to-business (B2B) software firm serving companies in the healthcare, financial services, retail, tel

Role Description The Senior Cybersecurity Analyst (Governance, Risk, and Compliance) plays an important role in building and maturing Boston Medical Center Health System’s GRC program. This role will be key to developing and improving human-driven processes before enterprise tooling is in place, and will make that work visible, auditable, and ready to scale. - Lead execution of GRC program initiatives, contributing design input on processes, workflows, and work products as the program matures toward enterprise tooling adoption. - Maintain and operationalize risk registers, control frameworks, and maturity assessments aligned to NIST CSF 2.0, HIPAA/HITECH, and applicable federal and state security and privacy regulations. - Drive compliance monitoring activities and recommend updates to security policies, standards, and procedures that balance regulatory rigor with operational practicality. - Coordinate the third-party risk management process, including vendor risk assessments and ongoing vendor risk workflows. - Apply risk scoring methodologies to support framework maturity tracking and quantified risk metrics, incorporating business continuity and disaster recovery considerations. - Manage structured GRC work products in spreadsheet and document-based environments (e.g., Excel, SharePoint), keeping them accurate, accessible, and audit-ready on an ongoing basis. - Translate technical findings into clear, actionable written and verbal reporting for executive and non-technical audiences. - Partner with stakeholders across IT and non-IT business functions to advance new standards and workflows, influencing adoption without direct authority. - Prioritize multiple concurrent workstreams to deliver accurate results on schedule in a fast-paced, evolving environment. Qualifications - Bachelor's degree in Cybersecurity, Computer Science, Information Management, or a related field preferred. - A minimum of six years of experience in information security or related discipline, with a strong focus on governance, risk, and compliance programs in complex or regulated environments. - Or equivalent combination of education and experience. - Demonstrated experience building or significantly maturing a GRC function, including the design of processes and workflows prior to enterprise tooling adoption. Requirements - Professional certifications such as CISA, CRISC, CISSP, or equivalent are highly desirable. - Demonstrated experience in data mining, analysis and report development required. - Strong knowledge of information systems security concepts and current information security/privacy trends and practices. - Knowledge of Federal and State security and privacy-related regulatory requirements. - Excellent written and oral communication skills, interpersonal skills, and effective leadership skills to support privacy programs. - Must be able to prepare formal reports and presentations as needed. - Must be detail-oriented and possess the ability to prioritize tasks so work is completed in an accurate, timely manner. - Strong business and technical skills in the planning, administration, and management of information systems, operational and technical security controls; and security risk analysis and management. - Self-starter with the ability to work independently, prioritize, multi-task, and maintain flexibility in fast-paced, changing environment. - Ability to confront conflict and difficult issues in a professional, assertive, and proactive manner. - Ability to build strong working relationships at all levels, internal and/or external to the organization. - Knowledge about medical records and other medical information, patient privacy and confidentiality, and release of information. Academic medical center and/or health care consulting experience preferred. Benefits - Compensation Range: $89,500.00 - $130,000.00 - Generous total compensation that includes benefits (medical, dental, vision, pharmacy). - Discretionary annual bonuses and merit increases. - Flexible Spending Accounts. - 403(b) savings matches. - Paid time off. - Career advancement opportunities. - Resources to support employee and family well-being.

United States
$89.5K - $130K / year
Job Closed

Security Analyst

Darkshield

Darkshield is an expert cybersecurity agency based in York, UK. We help organisations navigate an increasingly complex digital landscape by providing expert services in penetration testing, vulnerability assessment, managed security, and more. Our mission is to protect businesses by delivering tailored, cutting-edge cybersecurity solutions that keep them resilient and ahead of cyber threats.

Role Description We are seeking a Security Analyst to join our team and play a key role in threat detection, incident response, and security monitoring. The ideal candidate will have a strong analytical mindset, an understanding of cyber threats and attack techniques, and the ability to implement effective security controls to mitigate risks. This role involves proactively monitoring security events, investigating potential breaches, and supporting clients with vulnerability management and security best practices. Key Responsibilities - Threat Detection & Security Monitoring - Continuously monitor SIEM, IDS/IPS, firewalls, and endpoint security tools to identify suspicious activity. - Analyze and correlate security alerts to detect potential cyber threats and data breaches. - Perform log analysis and anomaly detection to identify patterns indicative of compromise. - Incident Response & Threat Investigation - Investigate security incidents, phishing attempts, malware infections, and unauthorized access events. - Develop and implement remediation strategies to mitigate security risks. - Conduct digital forensics and root cause analysis on security breaches. - Work closely with internal teams and clients to ensure swift containment and resolution of threats. - Vulnerability Management & Security Operations - Perform regular vulnerability scans and assessments, identifying security gaps and misconfigurations. - Recommend and implement security improvements based on assessment findings. - Optimize security configurations and policies across cloud and on-premise environments. - Assist in security patch management and tracking remediation efforts. - Security Policy & Awareness - Assist in the development and enforcement of security policies, procedures, and best practices. - Provide security awareness training to employees and clients to mitigate human-related risks. - Stay informed on emerging cyber threats, attack techniques, and security technologies. Qualifications - Experience in security monitoring, threat detection, or incident response. - Strong understanding of security tools including SIEM, IDS/IPS, firewalls, and endpoint security platforms. - Familiarity with log analysis, malware analysis, and digital forensics techniques. - Knowledge of threat intelligence platforms and cyber threat hunting techniques. - Experience with vulnerability assessment tools such as Nessus, Qualys, or OpenVAS. - Understanding of network security, cloud security, and endpoint protection. Requirements - Scripting & Automation (Preferred, Not Required) - Basic proficiency in Python, PowerShell, or Bash for security automation. - Ability to write scripts for log analysis, threat hunting, or security automation is a plus. - Certifications (Preferred, Not Required) - CompTIA Security+, CEH (Certified Ethical Hacker), GCIH (GIAC Certified Incident Handler), or similar certifications are desirable. - Soft Skills & Work Environment - Strong problem-solving skills and ability to think like an attacker. - Ability to work both independently and collaboratively within a security team. - Effective communication and reporting skills to convey security findings to technical and non-technical stakeholders. - Strong attention to detail with a methodical approach to security investigations. - A passion for learning and keeping up with the latest security threats and technologies. Benefits - Work on real-world cybersecurity threats and gain experience in high-impact security operations. - Opportunity to develop and implement security controls across various industries. - Career growth opportunities in a fast-growing cybersecurity agency. - Flexible work environment – remote and hybrid options available. - Competitive salary and performance-based incentives.

United Kingdom
£40K - £60K / year