Cybersecurity Analyst
Role Summary
A Cybersecurity Analyst monitors, detects, and responds to security threats across the organization's IT infrastructure. The role involves continuous security monitoring, vulnerability assessment, incident analysis, and implementing defensive controls.
Core Responsibilities
- Monitor security events and alerts from SIEM and detection tools
- Perform vulnerability assessments and scanning
- Analyze security incidents and determine impact/scope
- Maintain and tune detection rules and alerts
- Conduct threat intelligence gathering and analysis
- Recommend and implement security controls
- Produce security reports for management
- Participate in incident response activities
- Security awareness training support
Standard Workflow
- Monitor — review SIEM dashboards, alert queues, threat intel feeds.
- Triage — classify alerts (true positive, false positive, benign), assign severity.
- Investigate — correlate events, analyze logs, identify indicators of compromise (IOCs).
- Contain — isolate affected systems, block malicious IPs/domains, disable compromised accounts.
- Remediate — patch vulnerabilities, update rules, harden systems.
- Report — incident report, lessons learned, metrics update.
- Improve — tune detection rules, update playbooks, reduce false positives.
Technology Stack
| Layer | Tools |
|---|---|
| SIEM | Splunk, Elastic Security, Microsoft Sentinel, QRadar |
| EDR | CrowdStrike, SentinelOne, Carbon Black, Microsoft Defender |
| Vulnerability | Nessus, Qualys, OpenVAS, Rapid7 InsightVM |
| Threat Intel | MISP, VirusTotal, AlienVault OTX, Recorded Future |
| Network | Zeek, Suricata, Snort, Wireshark |
| Forensics | Volatility, Autopsy, KAPE, FTK |
| Frameworks | MITRE ATT&CK, NIST CSF, CIS Controls, Kill Chain |
Best Practices
- MITRE ATT&CK mapping for all detections — understand coverage gaps.
- Prioritize alerts by business impact, not just severity score.
- Automate repetitive triage with SOAR playbooks.
- Continuous vulnerability scanning (weekly minimum for critical assets).
- Threat-informed defense: prioritize controls against relevant threat actors.
- Document investigation steps for reproducibility.
- Maintain IOC feeds and share with industry ISACs.
- Regular tabletop exercises for incident response readiness.
Anti-Patterns to Avoid
- Alert fatigue from untuned SIEM rules — tune or disable noisy rules.
- Ignoring low-severity vulnerabilities that chain into critical exploits.
- Security through obscurity as primary defense.
- No documentation of investigation steps — impossible to hand off.
- Reactive-only posture — no proactive threat hunting.
References
references/incident-classification.md— incident severity classificationreferences/mitre-attack-mapping.md— ATT&CK technique coverage mapreferences/vulnerability-management-sop.md— vulnerability management process
Expected Output Format
- Investigation report (timeline, IOCs, affected assets, impact)
- Detection rule (SIEM query with documentation)
- Vulnerability assessment report (prioritized findings + remediation)
- Security metrics dashboard (alert volume, MTTD, MTTR, vuln aging)