- Salary
- $86k – $144k
- Location
- Farmington, Connecticut, United States of America · Remote
- Workplace
- Remote
- Type
- Full-time
- Department
- IT
- Education
- Master
- Source
- Workday
Description
Security & Network Analyst III
The Security & Network Analyst III is an experienced cybersecurity professional responsible for monitoring, protecting, and enhancing the security of The Jackson Laboratory's enterprise networks, systems, and data. This position combines advanced threat detection, incident response, threat hunting, and security engineering capabilities to proactively address emerging risks and strengthen organizational resilience. The role collaborates closely with cross-functional teams throughout JAX, providing technical expertise, supporting strategic security initiatives, and ensuring the effective implementation of cybersecurity best practices.
Key Responsibilities
- Serve as a senior analyst in JAX security and network operations with an emphasis on protection, defense, cyber defense analysis, incident handling, and network operations.
- Independently monitor, triage, investigate, and resolve alerts from SIEM, EDR/XDR, IDS/IPS, firewall, vulnerability management, identity, cloud security, and network monitoring platforms.
- Analyze logs, endpoint telemetry, authentication records, firewall events, DNS activity, proxy logs, packet captures, and network flow data to identify security events, network disruptions, misconfigurations, or performance issues.
- Work assigned tickets independently, including suspicious activity reports, endpoint/security tool alerts, firewall and connectivity requests, vulnerability findings, VPN issues, access-related issues, and service availability concerns.
- Perform initial incident response activities, including scoping, evidence gathering, containment coordination, escalation, documentation, and post-incident follow-up under established procedures.
- Troubleshoot complex issues across DNS, DHCP, routing, switching, firewall policy, VPN, wireless, identity, endpoint, and application connectivity dependencies.
- Evaluate and distinguish between false positives, benign anomalies, policy violations, operational failures, confirmed security events, and incidents requiring escalation.
- Escalate complex technical issues with clear documentation, supporting evidence, business impact, urgency, and recommended next steps for Security Engineering, Network Engineering, Infrastructure, or application teams.
- Identify recurring issues, alert quality concerns, monitoring gaps, control failures, and operational handoff problems; recommend practical improvements based on investigation trends.
- Lead vulnerability management activities by validating findings, confirming exposure, assisting with prioritization, coordinating remediation, and documenting risk-based outcomes.
- Assist with firewall rule reviews, VPN troubleshooting, network segmentation validation, network access issues, implementation validation, and post-change monitoring.
- Lead cross-functional efforts with Security Engineering and Network Engineering to enhance detection logic, alert routing, monitoring coverage, and incident response playbooks and operational procedures.
- Create and maintain knowledge base articles, troubleshooting guides, escalation procedures, ticket handling standards, and incident documentation templates.
- Mentor Security & Network Analyst I and Security & Network Analyst II team members by sharing investigation methods, reviewing escalation quality, and providing technical guidance while remaining an individual contributor.
- Participate in an on-call rotation to support after-hours incidents and ensure continuity of operations.
- This role requires limited travel (less than 10% annually) for team meetups, collaborative planning sessions, and other in-person events that foster connection, innovation, and a strong team culture.
- Perform other duties as assigned.
Knowledge, Skills, and Abilities
- Eight or more years of experience in technology, cybersecurity operations, network operations, infrastructure support, incident response, or a closely related technical role preferred.
- Four or more years of hands-on experience in a SOC, NOC, security operations, network operations, managed security, enterprise infrastructure, or hybrid security/network operations environment preferred.
- Demonstrated ability to work independently on complex tickets, alerts, incidents, and troubleshooting tasks with limited supervision and strong judgment on when to escalate.
- Strong working knowledge of TCP/IP, DNS, DHCP, routing, switching, VPNs, firewalls, proxy services, wireless networking, endpoint security, identity and access management, and common enterprise security controls.
- Experience using several of the following tools preferred: SIEM, EDR/XDR, IDS/IPS, firewall management platforms, vulnerability scanners, packet capture tools, network monitoring systems, log analysis platforms, ITSM/ticketing systems, and cloud security or infrastructure monitoring tools.
- Advanced experience analyzing endpoint, identity, network, cloud, and application telemetry to identify anomalous activity, unauthorized access, malware behavior, phishing, credential abuse, lateral movement, vulnerability exploitation, or service degradation.
- Ability to perform structured troubleshooting and root-cause analysis across security, network, endpoint, identity, and application layers.
- Advanced experience supporting incident response activities such as alert validation, event correlation, impact assessment, containment coordination, evidence collection, timeline development, and post-incident documentation.
- Advanced experience reviewing or supporting firewall policies, VPN access, network segmentation, remote access technologies, and secure connectivity workflows preferred.
- Advanced understanding of frameworks and models such as NIST NICE, NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, MITRE ATT&CK, or similar operational security frameworks preferred.
- Advanced experience supporting hybrid cloud or SaaS environments such as AWS, Azure, Google Cloud, Microsoft 365, Okta, Entra ID, or similar platforms preferred.
- Advanced experience with scripting, automation, or query languages such as PowerShell, Python, Bash, KQL, SPL, SQL, SOAR playbooks, or API-based workflows preferred.
- Security, network, or cyber defense certification(s) preferred, such as Network+, CySA+, CCNA, GCIH, GCIA, GSEC, CISM, CISSP, Splunk Core Certified Power User/Admin, or equivalent experience.
- A strong track record of taking initiative, being resourceful, and consistently improving alert quality, documentation, troubleshooting processes, and operational outcomes.
- Effective organizational skills and ability to manage competing priorities in a high-volume ticket and alert environment.
- A strong ability to establish and maintain productive relationships with internal customers, engineers, vendors, leadership, and cross-functional technology teams.
- Delivery - Strong delivery skills including the proven ability to manage tickets and investigations at a steady, predictable pace; document work clearly; identify important tradeoffs; and complete operational work while contributing to durable process improvements.
- Domain Expertise - Demonstrated domain expertise including the ability to understand immediate systems, recognize relationships with adjacent systems, stay aware of security and network trends, and apply technical knowledge to business priorities.
- Problem Solving - Strong problem solver who breaks large or ambiguous issues into manageable investigative steps, recognizes mistakes as learning opportunities, and recommends solutions that reduce recurrence and improve long-term reliability.
- Communication - Strong communicator who can articulate technical findings clearly and concisely, collaborate as both mentor and mentee, ask clarifying questions when requirements are vague, provide appropriate feedback, receive constructive criticism, and make space for colleagues to contribute.
- A desire for continuous education – Technology doesn’t stand still and neither does the JAX Security and Network teams.
Education: Bachelor's Degree required/ Master's Degree preferred
Experience: 5 years required/ 8 years preferred
Please send us your resume and a cover letter that highlights how your skills and strengths meet our needs.
Both documents are required for your application to be considered complete, so be sure to follow the cover letter instructions carefully.
Pay range: $85,987 - $143,962
#CA-EH8
About JAX:
The Jackson Laboratory is an independent, nonprofit biomedical research institution with a National Cancer Institute-designated Cancer Center and nearly 3,000 employees in locations across the United States (Maine, Connecticut, California), Japan and China. Its mission is to discover precise genomic solutions for disease and empower the global biomedical community in the shared quest to improve human health.
Founded in 1929, JAX applies over nine decades of expertise in genetics to increase understanding of human disease, advancing treatments and cures for cancer, neurological and immune disorders, diabetes, aging and heart disease. It models and interprets genomic complexity, integrates basic research with clinical application, educates current and future scientists, and provides critical data, tools and services to the global biomedical community. For more information, please visit www.jax.org.
EEO Statement:
The Jackson Laboratory provides equal employment opportunities to all employees and applicants for employment in all job classifications without regard to race, color, religion, age, mental disability, physical disability, medical condition, gender, sexual orientation, genetic information, ancestry, marital status, national origin, veteran status, and other classifications protected by applicable state and local non-discrimination laws.