# Information Security Analyst

*/JobTypes/Information_Security_Analyst*

## Neighborhood

### Parent

- [Computer and Information Analysts](/Occupations/Computer_and_Information_Analysts) — parent · Occupations

### Siblings

- [Data Analyst](/JobTypes/Data_Analyst) — siblings · JobTypes
- [IT Risk Analyst](/JobTypes/IT_Risk_Analyst) — siblings · JobTypes
- [Technology Analyst](/JobTypes/Technology_Analyst) — siblings · JobTypes

### Related (signature role)

- [IT Compliance Consultancy](/CompanyTypes/IT_Compliance_Consultancy) — signature role · CompanyTypes
- [Healthcare IT Managed Services Providers](/CompanyTypes/Healthcare_IT_Managed_Services_Providers) — signature role · CompanyTypes

### Related (staff)

- [IT](/Departments/IT) — staff · Departments
- [Information Security](/Departments/Information_Security) — staff · Departments

### Related (delivered by)

- [Analyze impact on, and risk to, essential business functions or information systems to identify acce...](/Tasks/Analyze_impact_on,_and_risk_to,_essential_business_functions_or_information_systems_to_identify_acce...) — delivered by · Tasks
- [Monitor the security of digital information.](/Activities/Monitor_the_security_of_digital_information.) — delivered by · Activities
- [Develop standards and guidelines for the use and acquisition of software and to protect vulnerable i...](/Tasks/Develop_standards_and_guidelines_for_the_use_and_acquisition_of_software_and_to_protect_vulnerable_i...) — delivered by · Tasks
- [Develop plans to safeguard computer files against accidental or unauthorized modification, destructi...](/Tasks/Develop_plans_to_safeguard_computer_files_against_accidental_or_unauthorized_modification,_destructi...) — delivered by · Tasks
- [Maintain network hardware and software, direct network security measures, and monitor networks to en...](/Tasks/Maintain_network_hardware_and_software,_direct_network_security_measures,_and_monitor_networks_to_en...) — delivered by · Tasks
- [Identify and evaluate IT risk](/Processes/Identify_and_evaluate_IT_risk) — delivered by · Processes
- [Protect the security of medical records to ensure that confidentiality is maintained.](/Tasks/Protect_the_security_of_medical_records_to_ensure_that_confidentiality_is_maintained.) — delivered by · Tasks
- [Identify or implement solutions to information security problems.](/Tasks/Identify_or_implement_solutions_to_information_security_problems.) — delivered by · Tasks
- [Train staff on, and oversee the use of, information security standards, policies, and best practices...](/Tasks/Train_staff_on,_and_oversee_the_use_of,_information_security_standards,_policies,_and_best_practices...) — delivered by · Tasks
- [Provide technical support to computer users for installation and use of security products.](/Tasks/Provide_technical_support_to_computer_users_for_installation_and_use_of_security_products.) — delivered by · Tasks
- [Develop and document security procedures, policies, or standards.](/Tasks/Develop_and_document_security_procedures,_policies,_or_standards.) — delivered by · Tasks
- [Define system security requirements](/Processes/Define_system_security_requirements) — delivered by · Processes
- [Conduct IT compliance control auditing of internal and external services](/Processes/Conduct_IT_compliance_control_auditing_of_internal_and_external_services) — delivered by · Processes
- [Audit IT user identity and authorization systems](/Processes/Audit_IT_user_identity_and_authorization_systems) — delivered by · Processes
- [Coordinate documentation of computer security or emergency measure policies, procedures, or tests.](/Tasks/Coordinate_documentation_of_computer_security_or_emergency_measure_policies,_procedures,_or_tests.) — delivered by · Tasks
- [Configure information systems to incorporate principles of least functionality and least access.](/Tasks/Configure_information_systems_to_incorporate_principles_of_least_functionality_and_least_access.) — delivered by · Tasks
- [Encrypt data transmissions and erect firewalls to conceal confidential information as it is being tr...](/Tasks/Encrypt_data_transmissions_and_erect_firewalls_to_conceal_confidential_information_as_it_is_being_tr...) — delivered by · Tasks
- [Confer with users to discuss issues such as computer data access needs, security violations, and pro...](/Tasks/Confer_with_users_to_discuss_issues_such_as_computer_data_access_needs,_security_violations,_and_pro...) — delivered by · Tasks
- [Recommend information security enhancements to management.](/Tasks/Recommend_information_security_enhancements_to_management.) — delivered by · Tasks
- [Recommend cyber defense software or hardware to support responses to cyber incidents.](/Tasks/Recommend_cyber_defense_software_or_hardware_to_support_responses_to_cyber_incidents.) — delivered by · Tasks
- [Administer document and system access rights and revision control to ensure security of system and i...](/Tasks/Administer_document_and_system_access_rights_and_revision_control_to_ensure_security_of_system_and_i...) — delivered by · Tasks
- [Assess the physical security of servers, systems, or network devices to identify vulnerability to te...](/Tasks/Assess_the_physical_security_of_servers,_systems,_or_network_devices_to_identify_vulnerability_to_te...) — delivered by · Tasks
- [Protect and control proprietary materials.](/Tasks/Protect_and_control_proprietary_materials.) — delivered by · Tasks
- [Identify and classify documents or other electronic content according to characteristics such as sec...](/Tasks/Identify_and_classify_documents_or_other_electronic_content_according_to_characteristics_such_as_sec...) — delivered by · Tasks
- [Develop security penetration testing processes, such as wireless, data networks, and telecommunicati...](/Tasks/Develop_security_penetration_testing_processes,_such_as_wireless,_data_networks,_and_telecommunicati...) — delivered by · Tasks
- [Monitor use of data files and regulate access to safeguard information in computer files.](/Tasks/Monitor_use_of_data_files_and_regulate_access_to_safeguard_information_in_computer_files.) — delivered by · Tasks
- [Develop guidelines for procedures such as the management of viruses.](/Tasks/Develop_guidelines_for_procedures_such_as_the_management_of_viruses.) — delivered by · Tasks
- [Identify, standardize, and communicate levels of access and security.](/Tasks/Identify,_standardize,_and_communicate_levels_of_access_and_security.) — delivered by · Tasks
- [Update corporate policies to improve cyber security.](/Tasks/Update_corporate_policies_to_improve_cyber_security.) — delivered by · Tasks
- [Maintain cyber defense software or hardware to support responses to cyber incidents.](/Tasks/Maintain_cyber_defense_software_or_hardware_to_support_responses_to_cyber_incidents.) — delivered by · Tasks
- [Document computer security and emergency measures policies, procedures, and tests.](/Tasks/Document_computer_security_and_emergency_measures_policies,_procedures,_and_tests.) — delivered by · Tasks
- [Implement security practices to preserve assets, minimize liabilities, or ensure customer privacy, u...](/Tasks/Implement_security_practices_to_preserve_assets,_minimize_liabilities,_or_ensure_customer_privacy,_u...) — delivered by · Tasks
- [Plan, coordinate, and implement security measures to safeguard information in computer files against...](/Tasks/Plan,_coordinate,_and_implement_security_measures_to_safeguard_information_in_computer_files_against...) — delivered by · Tasks
- [Plan, coordinate, and implement network security measures to protect data, software, and hardware.](/Tasks/Plan,_coordinate,_and_implement_network_security_measures_to_protect_data,_software,_and_hardware.) — delivered by · Tasks
- [Review security assessments for computing environments or check for compliance with cybersecurity st...](/Tasks/Review_security_assessments_for_computing_environments_or_check_for_compliance_with_cybersecurity_st...) — delivered by · Tasks
- [Review and approve data access requests](/Processes/Review_and_approve_data_access_requests) — delivered by · Processes
- [Review and monitor physical and logical IT data security measures](/Processes/Review_and_monitor_physical_and_logical_IT_data_security_measures) — delivered by · Processes
- [Monitor and control business information](/Processes/Monitor_and_control_business_information) — delivered by · Processes
- [Monitor and manage IT activity risk](/Processes/Monitor_and_manage_IT_activity_risk) — delivered by · Processes
- [Manage external communication and communications security](/Processes/Manage_external_communication_and_communications_security) — delivered by · Processes
- [Implement and administer business information access](/Processes/Implement_and_administer_business_information_access) — delivered by · Processes
- [Establish mitigation approaches for IT risks](/Processes/Establish_mitigation_approaches_for_IT_risks) — delivered by · Processes
- [Develop security program](/Processes/Develop_security_program) — delivered by · Processes
- [Determine critical IT risks](/Processes/Determine_critical_IT_risks) — delivered by · Processes
- [Create IT risk mitigation strategies and approaches](/Processes/Create_IT_risk_mitigation_strategies_and_approaches) — delivered by · Processes
- [Create and maintain IT security policies, standards, and procedures](/Processes/Create_and_maintain_IT_security_policies,_standards,_and_procedures) — delivered by · Processes
- [Create and maintain IT compliance requirements](/Processes/Create_and_maintain_IT_compliance_requirements) — delivered by · Processes

### Who staffs this

- [Security And Fraud](/Departments/Security_And_Fraud) — staffs · Departments
- [Security And Risk](/Departments/Security_And_Risk) — staffs · Departments
- [Enterprise Technology Company](/CompanyTypes/Enterprise_Technology_Company) — staffs · CompanyTypes
- [Platform IT Support](/Departments/Platform_IT_Support) — staffs · Departments
- [Information Technology](/Departments/Information_Technology) — staffs · Departments
- [Mid-Market Managed IT & Hosting Services](/CompanyTypes/Mid-Market_Managed_IT_&_Hosting_Services) — staffs · CompanyTypes

### AI agents replacing this role

- [Artifact Correlation Agent](/Agents/Artifact_Correlation_Agent) — replaces · Agents
- [Zero-Day Detection Agent](/Agents/Zero-Day_Detection_Agent) — replaces · Agents

### Perform

- [Monitor security alerts and telemetry](/Tasks/Monitor_security_alerts_and_telemetry) — perform · Tasks
- [Investigate Potential Security Incidents](/Tasks/Investigate_Potential_Security_Incidents) — perform · Tasks
- [Analyze Threat Intelligence](/Tasks/Analyze_Threat_Intelligence) — perform · Tasks
- [Review access and control configurations](/Tasks/Review_access_and_control_configurations) — perform · Tasks
- [Report on security posture](/Tasks/Report_on_security_posture) — perform · Tasks
- [Tune Detection Rules](/Tasks/Tune_Detection_Rules) — perform · Tasks
- [Recommend necessary corrective actions, based on inspection results.](/Tasks/Recommend_necessary_corrective_actions,_based_on_inspection_results.) — perform · Tasks
- [Recommend improvements in security systems or procedures.](/Tasks/Recommend_improvements_in_security_systems_or_procedures.) — perform · Tasks
- [Assess System Vulnerabilities](/Tasks/Assess_System_Vulnerabilities) — perform · Tasks
- [Document incidents and response actions](/Tasks/Document_incidents_and_response_actions) — perform · Tasks
- [Support phishing and awareness exercises](/Tasks/Support_phishing_and_awareness_exercises) — perform · Tasks
- [Triage and investigate suspected incidents](/Tasks/Triage_and_investigate_suspected_incidents) — perform · Tasks
- [Tune detection rules and reduce false positives](/Tasks/Tune_detection_rules_and_reduce_false_positives) — perform · Tasks
- [Assess vulnerabilities and prioritize remediation](/Tasks/Assess_vulnerabilities_and_prioritize_remediation) — perform · Tasks
- [Monitor security alerts and SIEM dashboards](/Tasks/Monitor_security_alerts_and_SIEM_dashboards) — perform · Tasks
- [Hunt for indicators of compromise across logs](/Tasks/Hunt_for_indicators_of_compromise_across_logs) — perform · Tasks
- [Investigate suspicious activity](/Tasks/Investigate_suspicious_activity) — perform · Tasks
- [Monitor security alerts and logs](/Tasks/Monitor_security_alerts_and_logs) — perform · Tasks
- [Report on security posture metrics](/Tasks/Report_on_security_posture_metrics) — perform · Tasks
- [Support security control reviews](/Tasks/Support_security_control_reviews) — perform · Tasks

### Required knowledge

- [Security Control Frameworks](/Knowledge/Security_Control_Frameworks) — requires knowledge · Knowledge
- [Operating System Internals](/Knowledge/Operating_System_Internals) — requires knowledge · Knowledge
- [Incident Response](/Knowledge/Incident_Response) — requires knowledge · Knowledge
- [Common Vulnerabilities and Exposures](/Knowledge/Common_Vulnerabilities_and_Exposures) — requires knowledge · Knowledge
- [Threat Landscape](/Knowledge/Threat_Landscape) — requires knowledge · Knowledge
- [Network Security](/Knowledge/Network_Security) — requires knowledge · Knowledge
- [Network protocols and attack techniques](/Knowledge/Network_protocols_and_attack_techniques) — requires knowledge · Knowledge
- [Common Attack Patterns](/Knowledge/Common_Attack_Patterns) — requires knowledge · Knowledge
- [Security Operations](/Knowledge/Security_Operations) — requires knowledge · Knowledge
- [Vulnerability Management](/Knowledge/Vulnerability_Management) — requires knowledge · Knowledge

### Type of

- [Information Security Analyst](/Occupations/Information_Security_Analyst) — type of · Occupations
- [Information Security Analysts](/Occupations/Information_Security_Analysts) — type of · Occupations

### Engage in

- [Assess system vulnerabilities](/Activities/Assess_system_vulnerabilities) — engage in · Activities
- [Monitor security alerts and events](/Activities/Monitor_security_alerts_and_events) — engage in · Activities
- [Investigate Suspicious Activity](/Activities/Investigate_Suspicious_Activity) — engage in · Activities
- [Monitor security alerts and SIEM dashboards](/Activities/Monitor_security_alerts_and_SIEM_dashboards) — engage in · Activities
- [Triage and investigate suspected incidents](/Activities/Triage_and_investigate_suspected_incidents) — engage in · Activities
- [Hunt for indicators of compromise across logs](/Activities/Hunt_for_indicators_of_compromise_across_logs) — engage in · Activities
- [Assess vulnerabilities across systems](/Activities/Assess_vulnerabilities_across_systems) — engage in · Activities

### Required skills

- [Vulnerability Analysis](/Skills/Vulnerability_Analysis) — requires skill · Skills
- [Critical Thinking](/Skills/Critical_Thinking) — requires skill · Skills
- [Security Monitoring](/Skills/Security_Monitoring) — requires skill · Skills
- [Vulnerability assessment](/Skills/Vulnerability_assessment) — requires skill · Skills
- [Threat hunting](/Skills/Threat_hunting) — requires skill · Skills
- [Log analysis and correlation](/Skills/Log_analysis_and_correlation) — requires skill · Skills
- [Detection rule tuning](/Skills/Detection_rule_tuning) — requires skill · Skills
- [Alert triage and incident investigation](/Skills/Alert_triage_and_incident_investigation) — requires skill · Skills
- [Detection Tuning](/Skills/Detection_Tuning) — requires skill · Skills
- [Log Analysis](/Skills/Log_Analysis) — requires skill · Skills

### Uses software

- [Security Information and Event Management Software](/Software/Security_Information_and_Event_Management_Software) — uses software · Software
- [CrowdStrike Falcon](/Software/CrowdStrike_Falcon) — uses software · Software
- [Microsoft Sentinel](/Software/Microsoft_Sentinel) — uses software · Software
- [Wireshark](/Software/Wireshark) — uses software · Software
- [Tenable Nessus](/Software/Tenable_Nessus) — uses software · Software
- [Splunk](/Software/Splunk) — uses software · Software
- [Endpoint Protection Platform](/Software/Endpoint_Protection_Platform) — uses software · Software
- [Security Information and Event Management System](/Software/Security_Information_and_Event_Management_System) — uses software · Software
- [Vulnerability Scanner](/Software/Vulnerability_Scanner) — uses software · Software

### Requires ability

- [Inductive reasoning](/Ability/Inductive_reasoning) — requires ability · Ability
- [Pattern recognition](/Ability/Pattern_recognition) — requires ability · Ability
- [Problem sensitivity](/Ability/Problem_sensitivity) — requires ability · Ability
- [Selective attention](/Ability/Selective_attention) — requires ability · Ability
- [Deductive Reasoning](/Ability/Deductive_Reasoning) — requires ability · Ability

### Problems this exposes

- [threat-intel mapped to the org's exposure ad hoc](/Problems/threat-intel_mapped_to_the_org's_exposure_ad_hoc) — exposes problem · Problems
- [SIEM alert triage overwhelmed by false positives needing manual review](/Problems/SIEM_alert_triage_overwhelmed_by_false_positives_needing_manual_review) — exposes problem · Problems
- [security-control evidence re-collected per SOC2/ISO audit cycle](/Problems/security-control_evidence_re-collected_per_SOC2%2FISO_audit_cycle) — exposes problem · Problems
- [incident timelines reconstructed manually across disparate logs](/Problems/incident_timelines_reconstructed_manually_across_disparate_logs) — exposes problem · Problems
- [vulnerability findings prioritized by hand against asset criticality](/Problems/vulnerability_findings_prioritized_by_hand_against_asset_criticality) — exposes problem · Problems
