We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

IT Security Analyst, Public Sector

BDO USA, LLP
United States, Florida, Orlando
450 South Orange Avenue (Show on map)
Jul 10, 2025

Job Summary:

The IT Security Analyst supports the implementation and continuous improvement of cybersecurity controls, monitoring, and compliance activities across cloud and endpoint systems. This role uses data collected from a variety of cyber defense tools to analyze events that occur within their environments for the purposes of mitigating threats. They are responsible for the analysis and development of the integration, testing, operations, and maintenance of systems security.

Job Duties:



  • Monitors and analyzes security event data across Microsoft 365 GCC High services, including Office, Entra ID, Intune, Defender, and Purview
  • Supports the configuration, implementation, and maintenance of secure baseline architectures in accordance with NIST SP 800-171
  • Conducts regular control testing and analyzes data to identify trends, deviations from baselines, and control effectiveness
  • Ensures all systems security operations and maintenance activities are properly documented and updated
  • Performs regular system patching, configuration reviews, and vulnerability remediation activities in coordination with change control processes
  • Documents and maintains detailed and auditable records for control evidence, system events, and incident response activities
  • Assists in evaluating and applying cybersecurity-enabled technologies or compensating controls to mitigate identified risks
  • Conducts phishing simulations and cybersecurity awareness campaigns
  • Responds to system alerts and coordinates for triage, escalation, or containment
  • Contributes to System Security Plans (SSPs), Plan of Action & Milestones (POA&Ms), and other artifacts for audit readiness
  • Works with stakeholders to resolve security incidents
  • Other duties as assigned


Supervisory Responsibilities:



  • N/A


Qualifications, Knowledge, Skills, and Abilities:

Education:



  • High School Diploma or GED, required
  • Bachelor's degree in cloud computing, information technology, information science, informatics, software engineering, or information systems, preferred
  • Annual 40 hours of continuous learning, (may include professional memberships, forums, lunch and learns, roundtables, online training courses, and maintaining certifications), required


Experience:



  • Three (3) or more years information technology, information systems, cybersecurity, computer science, software engineering, or computer engineering experience, required


License/Certifications:



  • AZ-104 - Microsoft Azure Administrator, preferred
  • AZ-500 - Microsoft Azure Security Technologies, preferred
  • MS-900 - Microsoft 365 Fundamentals, preferred


Software:



  • Proficiency with Microsoft Defender and Microsoft Sentinel, preferred
  • Proficiency with Microsoft Power Apps, preferred


Language:



  • N/A


Other Knowledge, Skills, and Abilities:



  • Knowledge of FedRAMP, NIST SP 800-53, NIST SP 800-171, NIST CSF, Cybersecurity Maturity Model Certification (CMMC), ISO 27000
  • Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy
  • Knowledge of cybersecurity and privacy principles
  • Knowledge of cyber threats and vulnerabilities
  • Knowledge of authentication, authorization, and access control methods
  • Knowledge of information technology (IT) security principles and methods (e.g., firewalls, demilitarized zones, encryption)
  • Knowledge of network access, identity, and access management (e.g., public key infrastructure, Oauth, OpenID, SAML, SPML)
  • Knowledge of network traffic analysis methods
  • Ability to conduct vulnerability scans and recognize vulnerabilities in security systems
  • Ability to accurately and completely source all data used in intelligence, assessment and/or planning products

Applied = 0

(web-8588dfb-vpc2p)