Cabrillo Coastal General Insurance Agency, LLC
Gainesville, FL
Cybersecurity Analyst I/II/III
We tailor your resume to this role and apply for you in seconds.
Apply to Cybersecurity Analyst I/II/III at Cabrillo Coastal General Insurance Agency, LLCJob details
- Location
- Gainesville, FL
- Work type
- Onsite
- Visa
- Sponsorship available
- Posted
- today
- Apply on
- recruiting.paylocity.com
About this role
Cabrillo Coastal General Insurance Agency, LLC is seeking a hands-on cybersecurity professional to protect the confidentiality, integrity, and availability of its information systems and data. The Cybersecurity Analyst investigates incidents, administers security technologies, evaluates risks, supports remediation, and partners with technology teams to strengthen cybersecurity safeguards and processes.
What you'll do:
- Leads and/or performs investigations of suspected cybersecurity incidents, including phishing, compromised accounts, malicious software, ransomware, unauthorized access, suspicious endpoint activity, data exposure and other potential security events
- Reviews, analyzes and correlates alerts and technical information from endpoint, identity, firewall, email, network, cloud and other security technologies to determine the nature, scope, severity and potential impact of cybersecurity events
- Coordinates and/or performs incident containment, eradication and recovery activities; documents investigation timelines, evidence, decisions and corrective actions; assists with post-incident reviews and identifies opportunities to improve security controls and response processes
- Administers, monitors, maintains and continually improves Cabrillo Coastal’s security technology suite, including endpoint security tools, firewalls, identity and access management technologies, multifactor authentication solutions and other cybersecurity platforms
- Reviews security-platform configurations, policies, alerts, exclusions, integrations, system health and operational effectiveness; recommends and implements configuration changes, process improvements and additional security capabilities, as appropriate
- Reviews vulnerability scans, penetration-test findings, threat intelligence, security assessments, vendor notifications and technical advisories to identify potential risks to Cabrillo Coastal systems, applications, networks and business operations
- Evaluates and prioritizes security findings based upon system exposure, exploitability, business criticality, data sensitivity, available safeguards and potential organizational impact
- Translates cybersecurity findings into clearly defined and actionable tickets or work items for IT, Systems/Development and other responsible teams; identifies affected systems, supporting evidence, recommended corrective actions, priority levels and validation requirements
- Tracks identified vulnerabilities and security-remediation activities through completion; verifies that corrective actions have been implemented and appropriately address the identified risk
- Performs proactive security reviews and threat-hunting activities using available endpoint, network, identity, email, firewall and system information to identify potentially malicious or unauthorized activity
- Contributes to the design, implementation and review of secure systems, networks, applications, cloud services and business processes; participates in technology projects and architecture reviews to identify security requirements and risks
- Provides technical security guidance regarding system configuration, network segmentation, endpoint protection, application control, identity management, privileged access, multifactor authentication, encryption, logging, monitoring and other cybersecurity safeguards
What they're looking for:
- Security-oriented; quality-oriented; detail-oriented; analytical; self-starter; team player; multi-tasker; adaptable; flexible; dependable; inquisitive; collaborative; service-oriented; coachable; strong work ethic; positive “can do” attitude; sound judgment; discretion; strong sense of ownership and accountability
- Strong skill sets in the following areas: cybersecurity incident investigation and response; technical troubleshooting; problem analysis and solving; risk identification and prioritization; effective decision-making; organization; time management and working under tight deadlines; technical research; documentation; active listening; asking productive questions; applying learned information to a variety of related or similar situations; oral and written communication; interpersonal communication; collaborating with technical and non-technical team members; translating complex technical findings into understandable business risks and actionable technical requirements; reviewing and analyzing endpoint, identity, authentication, firewall, email, network, cloud, application and operating-system logs; independently investigating a technical security finding, identifying potentially affected systems and users, evaluating possible business impact and recommending practical corrective actions; creating clear and complete security-remediation tickets that communicate the affected asset, identified condition, supporting evidence, potential risk, required action, priority and criteria for successful completion; appropriately handling confidential, sensitive and restricted Company information and maintaining discretion during cybersecurity investigations
- Strong working knowledge of: cybersecurity principles and practices, including defense in depth, least privilege, zero-trust concepts, identity security, endpoint security, network security, vulnerability management, system hardening, secure configuration, security monitoring, incident response and risk-based decision-making; cybersecurity threats and attacker techniques, including phishing, credential theft, malicious software, ransomware, social engineering, unauthorized access, privilege escalation, persistence, lateral movement and data exfiltration; Microsoft Windows operating systems, Active Directory, Microsoft Entra ID, Microsoft 365, identity and access-management principles, multifactor authentication and privileged-access controls; endpoint detection and response, antivirus, application control, firewall, vulnerability-management, email-security, identity-security and security-monitoring technologies; networking principles and technologies, including TCP/IP, DNS, DHCP, HTTP/S, VPNs, routing, switching, network segmentation, wireless networking and firewall rules; standard business writing, grammar and punctuation rules; telephone and email business etiquette rules; desktop computer operations; standard business software and web-based operations, including Microsoft Word, Microsoft Excel, Microsoft Outlook, Microsoft PowerPoint, Microsoft Teams and web browsers
- Education for All levels: Bachelor's degree in Cybersecurity, IT, Computer Science, or related field or equivalent experience and training
- 1–3 years in cybersecurity, IT operations, systems, networking, or related technical support; experience reviewing security alerts, logs, or suspicious activity
- 3–5 years of cybersecurity or related infrastructure experience, signficiant experience independently investgating security incidents, hands-on experience with EDR, firewalls, IAM/MFA, vulnerability management, or security monitoring and experience translating security findings into actionable remediation work
- 5–8+ years of cybersecurity or security engineering experience; experience leading incident investigations and complex remediation efforts; advanced experience managing enterprise security platforms; eExperience with security architecture, vulnerability management, threat hunting, and technical standard; experience mentoring others and serving as a technical escalation point
- Familiarity with PowerShell, Python, application programming interfaces or other scripting and automation technologies is a plus
- And familiarity with recognized cybersecurity frameworks, standards and regulatory requirements, including the NIST Cybersecurity Framework, CIS Controls, NIST security publications, NYDFS cybersecurity requirements and PCI DSS, is a plus
- Security+ or similar entry-level certification preferred and relevant Microsoft or vendor certifications are a plus
- CySA+, Microsoft Security, GCIH, CEH, or relevant vendor certifications preferred
- CISSP, CISM, GIAC, or advanced Microsoft/vendor certifications preferred
Ready to apply?
ApplyBolt finds matching jobs, tailors your resume, and submits applications for you.