Sigma Software Group logo
Sigma Software Group

We support enterprises, product houses, and startups with custom software solutions development and IT consulting.

Cyber Security Analyst – US Time Zone

Security AnalystSecurity AnalystFull TimeRemoteSeniorTeam 1,001-5,000Since 2002H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

2 days ago

Salary

0

Seniority

Senior

Job Description

Cyber Security Analyst – US Time Zone

Sigma Software Group

• Investigate advanced and persistent attacks using data analysis and data science tools • Analyze customers' web traffic to detect unidentified threats and reduce false positives using Elasticsearch and BigQuery • Research, design, and continuously enhance detection mechanisms to stay ahead of evolving threats • Provide real-time technical support to global customers, delivering professional and timely incident responses • Produce clear, insightful incident reports • Collaborate cross-functionally with R&D and Research teams to optimize the company's detection and mitigation capabilities • Design, plan, and implement internal automation projects to improve team efficiency • Work in a shift-based schedule, including weekends

Job Requirements

  • At least 4 years of experience in data analysis in cybersecurity or fraud detection domains, including experience with logs and dashboards
  • Strong SQL skills: complex queries, aggregations, GROUP BY, ORDER BY, filters, window functions (e.g., RANK()), CTEs, and subqueries
  • Technical understanding of web technologies and client–server architecture (APIs, HTTP, basic HTML/JavaScript)
  • Experience with SIEM systems (experience with the Elastic Stack would be an advantage)
  • Strong troubleshooting and problem-solving skills
  • Experience in customer support, including direct communication with clients; professionalism and politeness are essential
  • Strong English communication skills
  • Experience in a Cybersecurity Analyst/Researcher role, ideally supporting external customers in threat detection and response WOULD BE A PLUS
  • Experience in web security and security research: web application security, bot management, fraud detection
  • Experience with research methodologies (hypothesis testing, verification and research plan)
  • Python and JavaScript knowledge
  • Experience with BigQuery/Snowflake
  • Proficiency in building dashboards using BI tools (Snowflake, Looker, Kibana, JSM)

Benefits

  • Employees can work remotely

Related Job Pages

More Security Analyst Jobs

Cohu, Inc. logo

Oracle Security Analyst

Cohu, Inc.

We deliver leading-edge solutions to enable a smarter, safer, and more connected future.

Full TimeRemoteTeam 1,001-5,000H1B No Sponsor

Role Description The Oracle Security Analyst position provides technical, functional support and security for Oracle Fusion Cloud and related applications. This is a remote-work position and will be based in the US in one of these states: Washington, Oregon, Texas or Arizona. - Manage Oracle access request tickets (Oracle Fusion ERP, HCM, SCM, CX, OAC, Customer Portal, etc.) to support Oracle access provisioning and deprovisioning. - Troubleshoot and resolve Oracle access (roles and data security) issues and requests. - Maintain Oracle service accounts password database. - Maintain Oracle role master and global process owner documents. - Support and maintain Oracle BI report folder permissions. - Support Oracle user access requirements for assigned projects (integrations, new module implementations, etc.). - Interact with users and business owners to understand and educate them regarding access requests and access issues. - Facilitate knowledge transfer and sharing within the Oracle security team. - Manage all consultant user access/account requests. - Support Oracle access related requirements as part of our environment refresh process. - Support Sox requirements and controls for Oracle access related functions and ensure no deficiencies during a Sox Audit related to access. Qualifications - A minimum of 5 years of experience in IT services or other application/ERP support, with at least three years of experience leading an IT service and support team for a global company. - Interaction with a global team is preferred. - Experience and proficiency with customizing Oracle Fusion roles. - Experience and proficiency with Oracle Fusion Security Console, Oracle IAM, Oracle IDCS. - Ability to lead geographically dispersed teams and team members. - Experience building and developing processes. - Excellent communication, written and verbal, and interpersonal skills. - Strong analytical skills. - Proven troubleshooting skills. - Experience streamlining, implementing, and globalizing policies and procedures. - Experience with Sox audits as it relates to application security. - Knowledge of Oracle Fusion ERP, SCM, CX, HCM modules/processes a plus. Education & Training - Bachelor’s degree in IT field or equivalent combination of education, training, and experience. Job Conditions/Physical Demands - Work from home office environment. - Ability to sit for prolonged period at desk, use computer keyboard; minimal exertion. Protective Devices Required - In designated areas. Hiring Salary Range - $85-$105K

United States
$85K - $105K / year
Metro Vein Centers logo

Security Analyst

Metro Vein Centers

Metro Vein Centers is a rapidly growing healthcare practice specializing in state-of-the-art vein treatments. Our board-certified physicians and expert staff are on a mission to improve people’s quality of life by relieving the painful, yet highly treatable symptoms of vein disease—such as varicose veins and heavy, aching legs. With over 60 clinics across 7 states, and still growing, we’re building the future of vein care—delivering compassionate, results-driven care in a modern, patient-first environment. We proudly maintain a Net Promoter Score (NPS) of 93, the highest patient satisfaction in the industry.

Full TimeRemoteTeam 501-1,000

Role Description Metro Vein Centers is hiring a Security Analyst to own and mature our information security program across a 70+ clinic, cloud-first healthcare environment. This is a newly created role that reflects our commitment to proactive security, HIPAA compliance, and a zero trust approach to identity and access management. You will be responsible for day-to-day security operations, including: - Alert monitoring - Access reviews - Endpoint security - Email security - MDM policy enforcement - MFA administration - Phishing simulation programs What You'll Do - Monitor security alerts and events across the environment; investigate, triage, and respond to incidents in a timely manner - Administer and maintain Google Workspace security controls, including DLP policies, Gmail security settings, Drive sharing policies, and audit log review - Manage endpoint detection and response operations - Oversee device compliance policies, conditional access rules, and endpoint security baselines - Administer and enforce MFA policies and password complexity standards across all user populations - Conduct quarterly role-based access audits across critical systems including Athena, Luma, Google Workspace, and BigQuery - Own and maintain least-privilege access model across enterprise applications and identity platforms - Manage email security controls including phishing protection, spam filtering, and DMARC/DKIM configuration - Design and execute phishing simulation campaigns; deliver user security awareness training - Support HIPAA security compliance, including contributing to risk assessments, policy updates, and audit readiness - Assist with identity and access management (IAM) administration, including SSO, Google Identity - Collaborate with the network team on ZTNA policy enforcement and Zscaler security configurations - Contribute to incident response plans, disaster recovery documentation, and security runbooks - Track and report on key security KPIs including MFA adoption, device compliance rates, open vulnerabilities, and audit findings - Other related security duties as assigned - Occasional travel for critical issues or growth - Being on call rotation Qualifications - 3–5 years of experience in an information security, security analyst, or IT security operations role - Hands-on experience administering Google Workspace security features (admin console, audit logs, DLP, OAuth app controls) - Experience with endpoint security platforms; CrowdStrike Falcon preferred, Microsoft Defender for Endpoint also considered - Familiarity with Microsoft security products including Intune, Microsoft Defender, and Entra ID - Solid understanding of identity and access management concepts: SSO, MFA, RBAC, least privilege - Experience conducting access reviews, user provisioning audits, and policy enforcement - Working knowledge of email security protocols (SPF, DKIM, DMARC) and email threat landscape - Strong analytical skills with the ability to investigate alerts and identify indicators of compromise - Excellent written and verbal communication skills; ability to explain security concepts to non-technical users - Familiarity with HIPAA Security Rule requirements and healthcare data protection obligations Preferred Skills - CrowdStrike certification (CCFA, CCFH, or equivalent) preferred - Microsoft security certifications (SC-200, MS-500, or equivalent) a strong plus - Experience with Zscaler ZIA security policy management or cloud-native security platforms - Familiarity with SIEM platforms and log management tools - Experience running security awareness programs and phishing simulations (KnowBe4, Proofpoint, or similar) - Prior experience in healthcare IT security or compliance roles - Knowledge of NIST CSF or CIS Controls frameworks Benefits - Medical, Dental, and Vision Insurance - 401(k) with Company Match - Generous Paid Time Off (PTO) + Paid Company Holidays - Company-Paid Life Insurance - Short-Term & Long-Term Disability Insurance - Employee Assistance Program (EAP) - Career Growth & Development Opportunities - A collaborative, mission-driven culture focused on delivering exceptional patient care Compensation $75,000 — $85,000 USD

United States
$75K - $85K / year
AttainX, Inc. logo

Telecommunications, Cybersecurity Analyst

AttainX, Inc.

SBA Certified 8(a), EDWOSB/WOSB and CMMI L3, ISO 9001:2015 Certified QMS

Full TimeRemoteTeam 51-200Since 2008H1B No Sponsor

• Assist with the development and execution of test plans and procedures for telecommunications priority services • Support testing in wireline, wireless, IP, LTE, and emerging 5G environments under senior engineer guidance • Document test results, observations, and issues for review by senior technical staff • Help prepare technical reports and engineering documentation • Participate in meetings and technical discussions with internal and external stakeholders • Assist with Operations, Administration, Maintenance, and Provisioning (OAM&P) documentation and coordination activities • Support review and analysis of proposed carrier implementations and operational processes • Help prepare program documentation, presentations, and technical summaries • Assist with cybersecurity documentation and compliance requirements for telecommunications systems • Support the development and maintenance of security controls and cybersecurity artifacts • Participate in security assessments, vulnerability reviews, and risk documentation activities under supervision • Help maintain Interconnection Security Agreements (ISAs) and ATO-related materials

Alabama + 20 moreAll locations: Alabama | Arizona | Colorado | Florida | Idaho | Kansas | Kentucky | Nevada | New Mexico | North Carolina | Ohio | Michigan | Minnesota | Mississippi | Missouri | Pennsylvania | Texas | Virginia | Washington | Wisconsin | Wyoming
$70K - $80K / year
iT1 logo

Security Analyst

iT1

Everybody works better together!

Full TimeRemoteTeam 51-200Since 2003H1B No Sponsor

• Monitor security tools and platforms for suspicious activity and potential threats. • Investigate and triage alerts, respond to incidents, and document findings, root cause, and remediation actions. • Serve as the primary operational interface between customers, MDR providers, and internal teams for security events and escalations. • Coordinate incident response activities across MDR partners and internal teams. • Communicate security incidents, risks, and remediation status to customers. • Participate in incident reviews, RCA discussions, and customer meetings. • Ensure MDR services align with customer SLAs and contractual requirements. • Escalate critical risks and ensure timely resolution across stakeholders. • Perform vulnerability assessments and coordinate remediation activities across environments. • Identify and prioritize risks and recommend mitigation strategies to internal leadership and customers. • Maintain and tune security tools including SIEM, EDR, firewalls, and intrusion detection/prevention systems. • Analyze logs and telemetry to identify threats and improve detection capabilities. • Develop and maintain security operations processes, SOPs, and incident response runbooks to support consistent and scalable service delivery. • Create repeatable workflows for incident detection, escalation, and remediation. • Continuously refine playbooks based on lessons learned and threat intelligence. • Support onboarding of new customers by defining operational procedures. • Partner with Help Desk and Infrastructure teams to build security awareness and operational readiness. • Deliver training on security tools, processes, and escalation procedures. • Enable teams to identify, triage, and escalate security events appropriately. • Provide ongoing guidance to improve cross-team collaboration and response effectiveness. • Support development and enforcement of security policies, standards, and procedures. • Participate in audits and maintain documentation aligned to frameworks such as ISO 27001, NIST, SOC 2, and CMMC. • Stay current with emerging threats, vulnerabilities, and industry trends. • Recommend and implement improvements to strengthen security posture across internal and customer environments.

United States