| Detail | For this role |
|---|---|
| Department | Information Technology |
| Level | Mid level |
| Reports to | Information Security Manager |
| Direct reports | None |
| Experience | 2 to 5 years in a security operations or IT security role |
Security Analyst job description template
Copy this job description, replace the text in square brackets and post it on your careers page or a job portal.
Job title: Security Analyst
Department: Information Technology
Reports to: Information Security Manager
Location: [City], [office, branch or site]
About the role
A Security Analyst protects a company's systems and data by monitoring for threats, investigating alerts and closing security gaps. They review logs and alerts from security tools, respond to incidents, run vulnerability scans and help teams fix weaknesses before attackers use them. A good analyst tells a real threat from noise, acts quickly during an incident, and helps the business meet its security and compliance obligations. The role sits in the information security or IT team and reports to a security lead or manager.
Key responsibilities
- Monitor security alerts from the SIEM, endpoint and network tools, and triage them by real risk.
- Investigate suspected incidents, gather evidence, contain the threat and document the timeline.
- Run vulnerability scans, prioritise findings by severity and track fixes with the owning teams.
- Review firewall, access and identity logs for unusual activity and follow up on anomalies.
- Manage user access reviews and flag excessive or dormant privileges for cleanup.
- Test phishing awareness, run security drills and help train staff on safe practices.
- Maintain security documentation, runbooks and evidence for audits and certifications.
- Apply and verify security patches and configuration hardening across servers and endpoints.
- Support compliance work by mapping controls to standards and closing gaps.
- Report the security posture, open risks and incident trends to the security manager.
Requirements
- Graduate in computer science, IT or a related field
- Security certification such as CompTIA Security+ or CEH
- Knowledge of a SIEM and endpoint protection tools
- 2 to 5 years in a security operations or IT security role
KRAs and KPIs for a Security Analyst
Key result areas for the appraisal form, each with a KPI you can measure every month or quarter.
| Key result area | How to measure it |
|---|---|
| Alert triage | Priority alerts triaged within the agreed time, with false positives tracked and reduced |
| Incident response | Confirmed incidents contained within the response time set by policy |
| Vulnerability closure | Critical vulnerabilities remediated within the agreed patch window |
| Access hygiene | Access reviews completed on schedule with excess privileges removed |
| Awareness | Phishing simulation failure rate reduced quarter on quarter |
| Audit readiness | Security evidence produced for audits with no major findings |
Skills and tools
Tools used day to day: SIEM platform, EDR tools, Nessus, Wireshark, Firewall consoles, Ticketing system.
Reporting line and career path
Next roles: Senior Security Analyst, Incident Response Lead, Security Engineer
Interview questions for a Security Analyst
- Walk me through how you triage a suspicious login alert from first look to closure.
- How do you tell a false positive from a real threat in the SIEM?
- What are your first actions when you suspect a compromised endpoint?
- How do you prioritise vulnerabilities when the fix list is long?
- Explain how phishing works and how you reduce the risk from it.
- Describe an incident you handled and what you changed afterwards.
Managing a Security Analyst in ZeniaHR
Hire and manage your information technology team in one place
Post the role, onboard the new hire, and track attendance, leave and KRAs in ZeniaHR. Free for your first 50 employees.
Book a free demoSee pricingFrequently asked questions
What does a security analyst do?
A security analyst monitors a company's systems for threats, investigates alerts, responds to incidents and closes security gaps. They watch logs and security tools, run vulnerability scans, review access and help staff work safely. The goal is to catch and contain attacks early and keep data and systems protected.
What is the difference between a security analyst and a SOC analyst?
A SOC analyst usually works inside a security operations centre, watching alerts around the clock and escalating incidents by tier. A security analyst covers a wider scope: monitoring plus vulnerability management, access reviews, awareness and audit support. In small companies one person does both, while larger firms separate the roles.
What qualifications do you need to become a security analyst?
Most security analysts hold a computer science or IT degree and a certification such as CompTIA Security+ or CEH. Employers value hands on knowledge of a SIEM, endpoint tools and networking more than the paper alone. Many start in IT support or a SOC and move up as they build incident and investigation experience.