About the Role
The Information Security Analyst I supports the organization’s cybersecurity posture through monitoring, detection, response, and continuous improvement. This role protects enterprise systems, data, and users by assisting with threat detection, vulnerability management, and control validation across hybrid environments. The analyst operates within the Security Operations function, working closely with IT and security teams to operationalize security controls, support incident response, and ensure alignment with industry frameworks and regulatory requirements.
Responsibilities
- Monitor and analyze security events from SIEM, endpoint, network, email, and cloud security platforms to identify potential threats and anomalous activity.
- Triage security alerts and escalate or respond in accordance with defined incident response procedures.
- Support incident response activities including investigation, containment, eradication, and recovery, with appropriate documentation and evidence handling.
- Perform vulnerability scanning and assist with risk-based prioritization and remediation tracking.
- Maintain and improve security documentation, including runbooks, standard operating procedures (SOPs), and knowledge base articles.
- Assist in the implementation, configuration, and validation of security controls across endpoints, identity systems, networks, and cloud services.
- Collaborate with infrastructure, application, and business teams to remediate findings and strengthen security posture.
- Contribute to continuous improvement of detection capabilities, including tuning alerts and reducing false positives.
- Support audit and compliance activities by maintaining evidence, control documentation, and participating in assessments.
- Research emerging threats, vulnerabilities, and attack techniques to enhance detection and prevention strategies.
- Generate clear and concise reports on incidents, vulnerabilities, and security metrics for technical and non-technical stakeholders.
- Provide occasional on-site or remote support for security implementations and assessments across multiple locations.
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, or a related field.
- Minimum 1 year of experience in a security-related role.
- CompTIA Security+, CompTIA CySA+, (ISC)² SSCP or equivalent certification.
- Foundational understanding of security operations concepts, including threat detection, incident response, and vulnerability management.
- Familiarity with security tools such as SIEM, EDR, vulnerability scanners, firewalls, email security platforms, and identity/security controls.
- Basic knowledge of operating systems (Windows and Linux), networking fundamentals, and Active Directory or identity management systems.
- Understanding of modern security principles such as Zero Trust, least privilege access, and defense-in-depth.
- Awareness of common attack techniques (e.g., phishing, malware, credential attacks) and MITRE ATT&CK concepts.
- Ability to identify and assess security risks and vulnerabilities.
- Strong analytical and problem-solving skills with attention to detail.
- Willingness to learn, adapt, and stay current with evolving cybersecurity threats and technologies.
- Ability to work independently and collaboratively in a team environment.
- Ability to communicate effectively with both technical and non-technical stakeholders.
- Ability to work in a fast-paced, dynamic environment.
- Ability to collaborate with cross-functional teams.
- Exposure to cloud environments (e.g., Microsoft 365, Azure, AWS) and associated security controls is a plus.
- Understanding of security frameworks and standards such as NIST Cybersecurity Framework (CSF), NIST SP 800-53, CIS Critical Security Controls, or ISO 27001 preferred.
Skills
- SIEM
- EDR
- Vulnerability Scanners
- Firewalls
- Email Security Platforms
- Identity/Security Controls
- Windows
- Linux
- Networking Fundamentals
- Active Directory
- Identity Management Systems
- Zero Trust
- Least Privilege Access
- Defense-in-Depth
- Phishing
- Malware
- Credential Attacks
- MITRE ATT&CK
- Microsoft 365
- Azure
- AWS
- NIST Cybersecurity Framework (CSF)
- NIST SP 800-53
- CIS Critical Security Controls
- ISO 27001
Location
- Multiple Locations
Work Type
- Remote
- On-site
- Hybrid
Experience Level
- 1 year of experience in a security-related role
Education Level
- Bachelor’s degree in Cybersecurity, Information Technology, or a related field
- CompTIA Security+ certification
- CompTIA CySA+ certification
- ISC² SSCP certification
Salary/Compensations
- $64,000 - $80,000
Benefits
- Full benefits package
About the Company
- Spellman High Voltage Electronics Corporation is a family-owned business with over 75 years of experience powering progress in health, security, and quality of life.
- They are key partners with leading medical device, semiconductor, scientific analytics, and industrial systems manufacturers.
- With design and manufacturing sites in North America, Europe, and Asia, they are the preferred provider of high voltage power solutions for OEMs globally.
- Their products power many of the most advanced technologies that make modern life possible.
Equal Opportunity
- Spellman High Voltage Electronics Corporation believes that each individual is entitled to equal employment opportunities without regard to race, color, creed, gender, sexual orientation, gender identity, marital status, national origin, age, veteran status or disability.
- The right of equal employment opportunity extends to recruiting, hiring selection, transfer, promotion, training and all other conditions of employment.
- To request accommodation related to disabilities, please email us at careers@spellmanhv.com, or call +1 (631) 630-3000.
