Unknown Company

Cybersecurity Operations Specialist

new york, ny • Posted 1 weeks ago
Onsite Full Time General

Cybersecurity Operations SpecialistClient is a FINRA-registered broker-dealer committed to safeguarding client data and maintaining the integrity of our trading and infrastructure systems. We are seeking a Cybersecurity Operations Specialist to join our security operations team and play a hands-on role in monitoring, protecting, and improving the firm's cybersecurity posture. This position focuses on day-to-day security operations, vulnerability management, and incident response across our on-premise and cloud environments (AWS and Microsoft 365).

The ideal candidate has strong technical knowledge of endpoint protection, identity management, and network security, combined with an analytical mindset and attention to detail suitable for a regulated financial environment.Key ResponsibilitiesSecurity Operations & MonitoringMonitor and investigate alerts from CrowdStrike Falcon XDR, Microsoft Defender, and Intune.Conduct triage and escalation of suspicious activities in coordination with infrastructure and IT teams.Maintain visibility and reporting through Tenable Security Center and Nessus vulnerability scans.Support log analysis, correlation, and event tracking through integrated dashboards or SIEM platforms.Vulnerability & Patch ManagementPerform routine vulnerability assessments and track remediation status.Collaborate with system administrators to ensure timely patching of Windows, Linux, and network devices.Validate risk reduction and patch compliance before closing findings.Endpoint & Identity SecurityAdminister and monitor Symantec Endpoint Protection Manager (EPM) and Microsoft Intune policies.Enforce endpoint encryption (Corporate Laptop), application control, and posture management.Manage Microsoft Entra (Azure AD) identity policies, MFA enforcement, and conditional access rules.Review privileged account usage and assist in quarterly access recertification.Network & Cloud ProtectionSupport network segmentation, VPN access, and firewall change reviews on Juniper platforms.Monitor ZScaler logs for anomalous web traffic or policy violations.Assist with AWS and Microsoft 365 security baselines, configuration hardening, and identity governance.Security Awareness & ComplianceAdminister and report on employee phishing and training campaigns via KnowBe4.Support audit requests (FINRA, SEC, SOC1/2) by preparing evidence and log samples.Maintain documentation of incidents, vulnerabilities, and security control tests.Incident Response & ReportingParticipate in incident containment, investigation, and remediation.Collect forensic artifacts (logs, screenshots, binaries) as directed by the CISO.Prepare post-incident summaries and lessons-learned documentation.QualificationsRequiredBachelor's degree in Information Security, Computer Science, or related field (or equivalent experience).8+ years of experience in security operations, SOC, or IT security support.Working knowledge of EDR/XDR platforms (CrowdStrike, Defender), vulnerability scanners (Nessus), and firewall/IDS systems.Understanding of Windows/Linux administration, TCP/IP networking, and cloud identity management.Strong analytical, documentation, and communication skills.PreferredExperience with regulated financial institutions (FINRA, SEC, NFA, CFTC).Certifications such as CompTIA Security+, CySA+, Microsoft Certified: Security Operations Analyst, or GIAC GSEC.Familiarity with scripting or automation (PowerShell, Python) for security tasks.Personal AttributesDetail-oriented and disciplined in log review and documentation.Strong sense of responsibility and urgency during security incidents.Collaborative mindset to work with DevOps, IT, and compliance teams.Committed to continuous learning in cybersecurity best practices.

Back to Job Search