1

Cyber Email Security Analyst Jobs (NOW HIRING)

... cyber threats, tuning detections, and automating investigative and response workflows. The role ... Experience with endpoint detection and response (EDR) tools and email security analysis (phishing ...

... cyber attacks. Who should apply? * 4+ years of technical experience, including 2+ years in an ... Hands on experience with mitigating security controls (EDR/XDR, IPS/IDS, DLP, email security, web ...

$99K - $128K/yr

... cyber threats, tuning detections, and automating investigative and response workflows. The role ... Experience with endpoint detection and response (EDR) tools and email security analysis (phishing ...

Key responsibilities include daily threat intelligence monitoring, vulnerability management support, email security analysis, and physical security device monitoring. This position collaborates ...

Showing results 21-40

Cyber Email Security Analyst information

See salary details

$43K

$99.4K

$150K

How much do cyber email security analyst jobs pay per year?

As of Sep 14, 2026, the average yearly pay for cyber email security analyst in the United States is $99,400.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,500.00 and $115,500.00 per year, depending on experience, location, and employer.

What does a Cyber Email Security Analyst do?

A Cyber Email Security Analyst is responsible for protecting an organization’s email systems from cyber threats such as phishing, malware, and spam. They monitor email traffic for suspicious activity, investigate incidents, and implement security measures like filters and encryption. Analysts also educate employees on email security best practices and respond to potential breaches. Their goal is to ensure confidential and sensitive information is not compromised via email.

What are the key skills and qualifications needed to thrive as a Cyber Email Security Analyst?

To thrive as a Cyber Email Security Analyst, you need a solid understanding of cybersecurity principles, email protocols, and threat detection, typically with a degree in information security or related certifications like CompTIA Security+ or Certified Email Security Specialist. Familiarity with email security gateways, anti-phishing tools, SIEM systems, and platforms such as Microsoft Defender for Office 365 is essential. Attention to detail, analytical thinking, and strong communication skills enable you to identify threats and educate users effectively. These skills are critical for proactively defending organizations against email-borne threats and ensuring secure business communications.

What are some typical challenges faced by Cyber Email Security Analysts in protecting organizations from email-based threats?

Cyber Email Security Analysts often contend with rapidly evolving phishing tactics, sophisticated social engineering attacks, and the constant influx of spam and malware-laden messages. Staying ahead requires continuous monitoring of email traffic, regular updates to filtering rules, and effective incident response coordination with IT and security teams. Analysts must also educate end-users about best practices and ensure email security policies adapt to emerging threats, making communication and collaboration across departments essential.

What are popular job titles related to Cyber Email Security Analyst jobs?

For Cyber Email Security Analyst jobs, the most frequently searched job titles are:

Network Security Analyst

Austin, TX • On-site

Other

Medical, Life, Retirement

Posted 5 days ago


Job description

Overview
Allied Consultants, Inc is a proudly Austin based firm with over 34 years of experience delivering top-tier technical and business professionals within Texas State Agencies. We are currently seeking an experience Network Security Analyst to play a key role within a high-impact technical services team.
At Allied Consultants, we value our consultants and are committed to providing an exceptional experience including:
  • Highly competitive pay rates
  • Local support staff for responsive, personal service
  • Comprehensive benefits package, including:
    • Medical insurance (with employer cost sharing)
    • Life insurance
    • A 401(K) plan with company match
    • Flexible spending through a cafeteria plan

Candidates selected for interviews will be subject to a criminal background check and may be required to pass a drug screening, in compliance with federal and state regulations. All offers of employment are contingent upon successful completion of these checks.
Allied Consultants is a proud to be an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
Responsibilities
Level Description
1-3 years of experience in the field or in a related area. Has knowledge of commonly used concepts, practices, and procedures within a particular field. Relies on instructions and pre-established guidelines to perform the functions of the job. Primary job functions do not typically require exercising independent judgment. Ability to maintain the security and integrity of critical infrastructure systems by preventing unauthorized access and ensuring compliance with laws and regulations related to national security and foreign ownership restrictions.
Job Description
A network security analyst ensures that information systems and computer networks are secure. This includes protecting the company against hackers and cyber-attacks, as well as monitoring network traffic and server logs for activity that seems unusual. Additionally, these analysts are responsible for finding vulnerabilities in the computer networks and creating recommendations for how to minimize these vulnerabilities. The network security analyst investigates security breaches, develops strategies for any security issues that arise, and utilizes the help of firewalls and antivirus software to maintain security. DISCLAIMER: Candidates for this position will be subject to a pre-employment security review to determine employment eligibility.
Job Summary
The Network Security Analyst I performs advanced cybersecurity analysis and threat triage activities within the Cybersecurity Operations Center (CSOC). Work involves continuously monitoring, triaging, analyzing, and prioritizing cybersecurity alerts; investigating suspicious activity; identifying potential threats; and coordinating incident response activities to protect agency information systems, networks, and data. Serves as a primary point of contact for security event analysis, threat identification, and incident escalation.
Essential Job Functions
  • Monitors, analyzes, and triages cybersecurity alerts generated by Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), cloud security, email security, identity protection, and network security platforms.
  • Conducts initial investigations of detected and reported security events to determine severity, scope, impact, and potential risk to agency operations.
  • Identifies, validates, and prioritizes potential cybersecurity incidents, escalating confirmed threats to Incident Response, Threat Hunting, or SOC Engineering teams according to established procedures.
  • Correlates security events from multiple data sources, including endpoints (EDR), firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), cloud services, authentication systems, and threat intelligence feeds.
  • Reviews and analyzes indicators of compromise (IOCs), suspicious network activity, phishing emails, malware detections, and anomalous user behavior.
  • Documents investigations, findings, and response actions in ticketing and case management systems to ensure accurate tracking and reporting.
  • Assists with incident containment, eradication, and recovery efforts by coordinating with technical teams and stakeholders.
  • Reports and escalates to the CSOC Team Lead and/or SOC Manager.
  • Supports the continuous improvement of threat detection capabilities through alert tuning, process refinement, threat intelligence integration, and identification of false-positive trends.
  • Performs vulnerability assessment reviews and evaluates identified vulnerabilities for potential risk and remediation prioritization.
  • Supports development and maintenance of operational procedures, playbooks, workflows, and knowledge base articles related to threat detection and incident response.
  • Researches emerging cyber threats, attack techniques, tactics, and procedures (TTPs) to improve detection and response effectiveness.

Knowledge, Skills, and Abilities
Knowledge of:
  • Cybersecurity Operations Center (CSOC/SOC) operations and best practices.
  • Security incident triage, analysis, investigation, and escalation procedures.
  • Security monitoring technologies, including SIEM, EDR/XDR, IDS/IPS, firewalls, endpoint security solutions, and cloud security platforms.
  • Common cyber threats, attack vectors, malware, phishing campaigns, insider threats, and advanced persistent threat (APT) techniques.
  • Threat intelligence concepts, indicators of compromise (IOCs), indicators of attack (IOAs), and MITRE ATT&CK methodologies.
  • Windows, Linux, networking protocols, Active Directory, Microsoft Entra ID, cloud environments, and enterprise security controls.
  • Incident response lifecycle and cybersecurity frameworks such as NIST Cybersecurity Framework, NIST Incident Response guidance, and PICERL.

Skill in:
  • Security event analysis and threat triage.
  • Correlating and interpreting data from multiple cybersecurity tools.
  • Investigating suspicious activity and identifying indicators of compromise.
  • Using SIEM, EDR/XDR, threat intelligence, vulnerability management, and case management platforms.
  • Producing clear documentation, incident reports, and technical communications.
  • Prioritizing and managing multiple investigations in a fast-paced operational environment for a large organization.
  • Knowledge of and experience with query languages such as KQL, Lucene, SPL, ESQL, etc.
  • Knowledge of and experience with scripting languages such as PowerShell, Python, Bash, etc.

Ability to:
  • Analyze complex security events and distinguish legitimate threats from false positives.
  • Make risk-based decisions during incident investigations.
  • Execute established incident response and escalation procedures.
  • Collaborate effectively with security engineers, incident responders, system administrators, CISO leadership, and business stakeholders.
  • Communicate technical information clearly to both technical and non-technical audiences.
  • Work independently and as part of a 24x7 cybersecurity operations team.

Preferred Education and Certifications
  • Graduation from an accredited four-year college or university with major coursework in cybersecurity, information security, computer science, computer information systems, management information systems, or a related field is preferred. Relevant education and experience may be substituted for one another.
  • One or more of the following certifications are preferred:
  • CompTIA Security+
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Intrusion Analyst (GCIA)
  • Certified SOC Analyst (CSA)
  • Microsoft Cybersecurity Analyst (SC-200)
  • Other GIAC or SOC-related certifications

Required Qualifications
  • Minimum of five (5) years of experience in cybersecurity operations, security monitoring, incident response, threat detection, security investigations, or related cybersecurity disciplines.
  • Experience working with one or more of the following technologies:
  • SIEM platforms (NetWitness, Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, etc.)
  • Microsoft Security (Microsoft 365 Defender XDR, Microsoft Sentinel)
  • Endpoint Detection and Response (Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, etc.)
  • IDS/IPS technologies (Trellix/FireEye, Corelight)
  • Threat intelligence platforms (VirusTotal, Google Threat Intelligence, Cisco Talos, Recorded Future, MISP)
  • Vulnerability management tools (Tenable, Qualys, Rapid7)
  • Email security platforms (IronPort ESA, Abnormal.ai, Proofpoint)
  • Cloud security monitoring solutions (Google Wiz, MDCA, Cortex Cloud, Sysdig)
  • Secure Access Service Edge (Zscaler, Prisma, Netskope)
  • Experience triaging security alerts, analyzing security events, and documenting incident investigations.
  • Experience with cybersecurity frameworks, incident response processes, and threat detection methodologies.

Work Expectations
  • Participate in incident response, escalation, and after-action review activities as needed.
  • Support enterprise security monitoring for systems that process, store, or transmit sensitive information.
  • Follow client's policies, procedures, standards, and applicable state and federal security requirements.
  • Maintain accurate operational documentation, investigation notes, metrics, and leadership-ready summaries.
  • Must be able to provide support outside of normal business hours during high-priority security incidents, as approved by the SOC Manager.

Qualifications
Minimum Requirements:
Candidates that do not meet or exceed the minimum stated requirements (skills/experience) will be displayed to customers but may not be chosen for this opportunity.
Years
Required/Preferred
Experience
3
Required
Experience triaging security alerts
3
Required
Experience analyzing security events
3
Required
Experience documenting incident investigations
3
Required
Experience with cybersecurity frameworks
3
Required
Experience with incident response processes
3
Required
Experience with threat detection methodologies
3
Required
Experience in cybersecurity operations
3
Required
Experience in security monitoring
3
Required
Experience in incident response
3
Required
Experience in threat detection
3
Required
Experience in security investigations
3
Required
Experience in related cybersecurity disciplines
5
Preferred
Please See Job Description Section for more specific Preferred and Required Skills.