Information Security Analyst

Hybrid-based
ONET: 15-1122.00

1

Years

82

Skills

371h

Related instructions

2100h

On-the-job training
Curriculum
  • Ethical Hacking and Network Defense
  • Information Security Professional Practices
  • Firewalls
  • Hacking Mobile Devices
  • Advanced Ethical Hacking
  • Exploit Development
  • Practical Malware Analysis
On-the-job training
  • Assists in developing security policies and protocols; assists in enforcing company compliance with network security policies and protocols
    • Basic - Locates (in Intranet, employee handbook or security protocols) organizational policies intended to maintain security and minimize risk and explains their use
    • Advanced - Provides guidance to employees on how to access networks, set passwords, reduce security threats and provide defensive measures associated with searches, software downloads, email, Internet, add-ons, software coding and transferred files
    • Basic - Ensures that password characteristics are explained and enforced and that updates are required and enforced based on appropriate time intervals
    • Advanced - Assigns individuals to the appropriate permission or access level to control access to certain web IP addresses, information and the ability to download programs and transfer data to various locations
    • Intermediate - Assists employees in the use of technologies that restrict or allow for remote access to the organization's information technology network
    • Advanced - Develops security compliance policies and protocols for external services (i.e. Cloud service providers, software services, external data centers)
    • Advanced - Complies with incident response and handling methodologies
    • Intermediate - Articulates the business need or mission of the organization as it pertains to the use of IT systems and the storage of sensitive data
    • Intermediate - Explains organization policies for the storage, use and transfer of sensitive data, including IP and personally identifiable information. Identifies data life cycle, storage facilities, technologies and describes business continuity risks
  • Provides technical support to users or customers
    • Advanced - Implements security measures for uses in system and ensures that system designs incorporate security configuration guidelines
    • Basic - Manages inventory of IT resources
    • Intermediate - Diagnoses and resolves customer-reported system incidents
    • Basic - Installs and configures hardware, software and peripheral equipment for system users
    • Basic - Monitors client-level computer system performance
    • Basic - Tests computer system performance
    • Basic - Troubleshoots system hardware and software
    • Intermediate - Administers accounts, network rights, and access to systems and equipment
  • Installs, configures, tests, operates, maintains and manages networks and their firewalls including hardware and software that permit sharing and transmission of information
    • Basic - Diagnoses network connectivity problems
    • Intermediate - Integrates new systems into existing network architecture
    • Intermediate - Establishes adequate access controls based on principles of least privilege and need-to-know
    • Basic - Implements security measures for users in system and ensures that system designs incorporate security configuration guidelines
    • Intermediate - Collaborates with system developers and users to assist in the selection of appropriate design solutions to ensure the compatibility of system components
    • Advanced - Installs, replaces, configures and optimizes network hubs, routers and switches
    • Intermediate - Assists in network backup and recovery procedures
    • Advanced - Modifies network infrastructure to serve new purposes or improve workflow
    • Intermediate - Patches network vulnerabilities to ensure information is safeguarded against outside parties
    • Basic - Repairs network connectivity problems
    • Basic - Tests and maintains network infrastructure including software and hardware devices
  • Installs, configures, troubleshoots and maintains server configurations, firewalls, patch and vulnerability management
    • Intermediate - Checks system hardware availability, functionality, integrity and efficiency
    • Basic - Conducts functional and connectivity testing to ensure continuing operability
    • Basic - Conducts periodic server maintenance including cleaning (physically and electronically), disk checks, system configuration and monitoring, data downloads, backups and testing
    • Intermediate - Installs server fixes, updates and enhancements
    • Basic - Manages accounts, network rights and access to systems and equipment
    • Basic - Supports network components
    • Intermediate - Verifies data redundancy and system recovery procedures
    • Intermediate - Provides ongoing optimization and problem-solving support
    • Basic - Resolves hardware/software interface and interoperability problems
    • Advanced - Assists in the development of group policies and access control lists to ensure compatibility with organizational standards, business rules and needs
    • Intermediate - Monitors and maintains server configuration
    • Intermediate - Documents compliance with or changes to system administration standard operating procedures
    • Intermediate - Maintains baseline system security according to organizational policies
    • Basic - Diagnoses faulty system/server hardware; seeks appropriate support or assistance to perform server repairs
    • Intermediate - Assists in the coordination or installation of new or modified hardware, operating systems and other baseline software
    • Advanced - Establishes adequate access controls based on principles of least privilege, role based access controls (RBAC) and need-to-know
  • Configures tools and technologies to detect, mitigate and prevent potential threats
    • Intermediate - Installs and maintains cyber security detection, monitoring and threat management software
    • Intermediate - Coordinates with network administrators to administer the updating of rules and signatures for intrusion/detection protection systems, anti-virus and network black and white list
    • Basic - Ensures application of security patches for commercial products integrated into system design
    • Intermediate - Manages IP addresses based on current threat environment
    • Advanced - Uses computer network defense tools for continual monitoring and analysis of system activity to identify malicious activity
  • Assesses and mitigates system network, business continuity and related security risks and vulnerabilities
    • Intermediate - Applies security policies to meet security objectives of the system
    • Intermediate - Performs system administration to ensure current defense applications are in place, including on Virtual Private Network devices
    • Basic - Ensures that data back up and restoration systems are functional and consistent with company's document retention policy and business continuity needs
    • Advanced - Performs technical and non-technical risk and vulnerability assessments of relevant technology focus areas
    • Intermediate - Documents systems security operations and maintenance activities
    • Advanced - Identifies information technology security program implications of new technologies or technology upgrades
    • Advanced - Identifies potential conflicts with implementation of any computer network defense tools. Performs tool signature testing and optimization
    • Advanced - Installs, manages and updates intrusion detection system
    • Intermediate - Conducts authorized penetration testing (Wi-Fi, network perimeter, application security, cloud, mobile devices) and assesses results
    • Advanced - Communicates potential risks or vulnerabilities to manager. Collaborates with others to recommend vulnerability corrections
  • Reviews network utilization data to identify unusual patterns, suspicious activity or signs of potential threats
    • Receives and analyzes network alerts from various sources within the enterprise and determines possible causes of such alerts
    • Basic - Identifies organizational trends with regard to the security posture of systems; identifies unusual patterns or activities
    • Advanced - Characterizes and analyzes network traffic to identify anomalous activity and potential threats; performs computer network defense trend analysis and reporting
    • Advanced - Runs tests to detect real or potential threats, viruses, malware, etc.
    • Intermediate - Assists in researching cost-effective security controls to mitigate risks
    • Advanced - Helps perform damage assessments in the event of an attack
    • Advanced - Monitors network data to identify unusual activity, trends, unauthorized devices or other potential vulnerabilities
    • Intermediate - Documents and escalates incidents that may cause immediate or long-term impact to the environment
    • Advanced - Provides timely detection, identification and alerts of possible attacks and intrusions, anomalous activities, and distinguish these incidents and events from normal baseline activities
    • Advanced - Uses network monitoring tools to capture and analyze network traffic associated with malicious activity
    • Advanced - Performs intrusion analysis
    • Intermediate - Sets containment blockers to align with company policy regarding computer use and web access
  • Responds to cyber intrusions and attacks and provides defensive strategies
    • Advanced - Reconstructs a malicious attack or activity based on network traffic
    • Advanced - Receives and analyzes network alerts from various sources within the enterprise and determines possible causes of such alerts
    • Advanced - Assists in the development of appropriate courses of action in response to identified anomalous network activity
    • Advanced - Triages systems operations impact: malware, worms, man-in-the-middle attack, denial of service, rootkits, keystroke loggers, SQL injection and cross-site scripting
    • Advanced - Correlates incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation
    • Advanced - Monitors external data sources to maintain currency of Computer Network Defense threat condition and determines which security issues may have an impact on the enterprise. Performs file signature analysis
    • Advanced - Performs analysis of log files from a variety of sources to identify threats to network security; performs file signature analysis
    • Intermediate - Tracks and documents computer network defense incidents from initial detection through final resolution
    • Advanced - Collects intrusion artifacts and uses discovered data to enable mitigation of potential computer network defense (CND) incidents
    • Basic - Performs virus scanning on digital media
    • Advanced - Performs computer network defense incident triage to include determining scope, urgency and potential impact; identifies the specific vulnerability; provides training recommendations; and makes recommendations to enable expeditious remediation
Interested in this apprenticeship?
Sign up to receive notifications about changes and updates about Information Security Analyst
Headquarters location
San Francisco, CA (94112)
Get on our calendar
Not sure if WorkHands is right for you? Chat with our team today
Send us an email
We'll get back to you shortly