Data First Jobs

NYCOR

Cyber Security Analyst

Full Time · In Office · Plymouth, Minnesota (USA)

$100,000–$150,000 · Posted Sep 11, 2026

Work Options
Cloud Stack
Job Type
Position Group

CYBERSECURITY ANALYST LEAD

Work Authorization: Applicants must be U.S. Citizens or lawful permanent residents (Green Card Holders). We are unable to sponsor or work with candidates on any type of visa, including but not limited to H-1B, H-4, F-1, CPT/OPT, L-1, TN, or EAD-based visas.

  • We are seeking a Cybersecurity Analyst Lead for an established organization with a broad operational footprint, diverse business functions, and a growing reliance on secure, connected technology.
  • The teams depend on enterprise applications, cloud services, infrastructure, business systems, and other connected platforms. Protecting these resources, the information they contain, and the operations they support is a growing business priority.
  • They are increasing their investment in cybersecurity and are looking for their first dedicated cybersecurity professional to establish, strengthen, and mature the program.
  • About the Role
  • This is a foundational cybersecurity position with the opportunity to shape a growing security program from the ground up.
  • We are looking for a hands-on professional who can work directly within the technology environment while bringing the judgment, curiosity, and leadership needed to influence the future direction of cybersecurity.
  • You will support day-to-day protection while turning security risks, third-party assessments, business needs, and evolving threats into a practical improvement plan. The role goes beyond identifying concerns: you will set priorities, coordinate action, track results, and strengthen their ability to manage cyber risk over time.
  • As the first dedicated cybersecurity resource, you will work closely with Technology, business leaders, external partners, and stakeholders across the organization.
  • The successful candidate will be equally comfortable investigating a security event, reviewing a control setting, drafting a security standard, prioritizing a roadmap, and explaining to leaders why an issue matters and what action should follow.
  • What You’ll Be Accountable For
  • 1. Strengthen Day-to-Day Protection
  • Operate and continually improve the safeguards protecting our people, systems, data, and essential business activities.
  • Monitor, assess, prioritize, and coordinate responses to cybersecurity alerts, events, and incidents across the technology environment.
  • Develop and manage a risk-based vulnerability program that identifies significant exposures, sets remediation expectations, assigns accountability, and confirms resolution.
  • Improve security across endpoints, servers, cloud services, email, identity, networks, and remote-access solutions.
  • Administer, assess, and optimize security tools, including EDR, email protection, identity controls, vulnerability platforms, logging, SIEM, and related technologies.
  • Identify privileged accounts and conduct recurring reviews of elevated and administrative access.
  • Support access certifications, phishing prevention, security awareness, and routine cybersecurity activities.
  • Examine suspicious behavior, record findings, coordinate the appropriate response, and convert lessons learned into lasting improvements.
  • Collaborate with infrastructure, applications, and other Technology teams to reduce risk while supporting practical business operations.
  • 2. Build a Scalable Cybersecurity Program
  • Convert security assessments, business risk, and strategic priorities into a focused, measurable program of improvement.
  • Lead the cybersecurity improvement roadmap by turning findings and risks into sequenced quarterly priorities, clear ownership, measurable deliverables, and leadership updates.
  • Create, refine, and put into practice cybersecurity policies, standards, procedures, and supporting guidance.
  • Establish practical governance processes for risk tracking, exceptions, control verification, and performance measurement.
  • Develop repeatable practices for vulnerability management, identity and access management, incident response, logging and monitoring, continuity planning, disaster recovery, and security education.
  • Support readiness for contractual or regulated requirements, including CMMC and NIST SP 800-171 obligations related to Controlled Unclassified Information.
  • Assist with customer, regulatory, and cyber-insurance expectations, including reviews aligned with NIST CSF, CIS Controls, and other relevant frameworks.
  • Assess security products and services based on risk reduction, organizational need, overall value, and operational fit.
  • Verify that controls are not only documented, but implemented, effective, and improving.
  • Define useful cybersecurity measures that demonstrate program progress and reduced risk.
  • 3. Translate Cyber Risk Into Business Priorities
  • Help leaders understand the cybersecurity issues that matter most and turn that understanding into practical, sustained action.
  • Describe significant cybersecurity risks in clear, business-focused language.
  • Sequence security work according to potential impact, likelihood, operational importance, compliance obligations, and available capacity.
  • Turn technical observations into actionable recommendations and explain the business reasoning behind them.
  • Assign owners, expected results, and target dates for priority remediation efforts, then help drive them to completion.
  • Partner with Technology, operations, Legal, HR, and other functions to embed cybersecurity into business processes and decisions.
  • Build support and influence action across technical and business groups without depending on formal authority.
  • Deliver concise, decision-ready reporting on cyber risk and program performance to leadership.
  • Track changes in threats, practices, technologies, and regulatory expectations, and determine which developments warrant action.
  • What You Bring
  • We value demonstrated ability more than a particular job title or traditional career path.
  • A strong candidate will offer:
  • At least four years of meaningful hands-on experience in information security or an IT position with significant cybersecurity ownership.
  • Current technical strength across several disciplines, such as incident response, vulnerability management, endpoint protection, identity and access management, Microsoft or cloud security, logging and SIEM, network security, or secure configuration.
  • A record of moving beyond task execution to identify risk, establish priorities, create a plan, and carry work through completion.
  • The ability to shift comfortably between technical details and broader business considerations.
  • Experience explaining cyber risk and technical findings in language that Technology and business leaders can understand and use.
  • Working familiarity with one or more established frameworks, such as NIST CSF, NIST SP 800-171, CIS Controls, CMMC, or ISO 27001.
  • Sound judgment when deciding how to apply limited time, budget, and resources.
  • The ability to work autonomously, develop trusted partnerships, and achieve outcomes through collaboration.
  • Curiosity, initiative, practical problem-solving ability, and a commitment to continuous improvement.
  • Clear written and verbal communication skills.
  • A willingness to remain technically engaged while assuming greater ownership for program direction and maturity.
  • Nice to Have
  • Experience creating, expanding, or significantly improving a cybersecurity program.
  • Exposure to CMMC and NIST SP 800-171 through readiness planning, assessment, implementation, or ongoing compliance.
  • Experience supporting a complex organization with varied systems, locations, or operational requirements.
  • Familiarity with both enterprise technology and specialized or operational systems.
  • Knowledge of Microsoft 365, Azure and Microsoft security products, and commonly used SIEM, EDR, vulnerability, and identity platforms.
  • Participation in or leadership of cybersecurity incident response activities.
  • Experience producing security metrics, roadmaps, standards, or executive-level reporting.
  • Relevant credentials such as Security+, CySA+, GSEC/GIAC, CISSP, CISM, or equivalent demonstrated expertise.
  • Certifications are beneficial, but they do not replace practical experience, sound judgment, and a history of delivering results.
  • How Success Will Be Measured
  • Success will be reflected in measurable gains in our ability to identify, prioritize, and reduce cybersecurity risk.
  • Examples include:
  • Significant cyber risks are clearly defined, ranked, assigned, and actively addressed.
  • Critical findings and vulnerabilities are resolved within agreed-upon timeframes.
  • Visibility into assets, identities, logging, monitoring, and control performance increases.
  • Incident response and recovery processes become documented, exercised, and repeatable.
  • Cybersecurity policies and standards are consistently applied in daily operations.
  • We develop a clear, actionable approach to CMMC and NIST SP 800-171 readiness where applicable.
  • Leaders receive concise, useful reporting on cyber risk and program advancement.
  • The security roadmap delivers visible improvements rather than remaining a static plan.
  • Cybersecurity considerations become part of routine Technology and business decisions.
  • Where This Role Can Go
  • This opportunity is designed around capability and growth potential rather than a narrowly defined career path.
  • As the cybersecurity function develops, this position is expected to expand into greater ownership of program leadership, strategic planning, enterprise risk management, and potentially future team development.
  • For the right professional, this is a chance to build a cybersecurity capability from its early stages while staying close enough to the work to see the impact directly.

This will require a US Citizen or GC Holder.

Mention you found this on Data First Jobs — it helps us bring you more roles like this.

Cyber Security Analyst

NYCOR

Like this role? Get carefully selected jobs like it, twice a week, straight to your inbox.

Free, no spam. Unsubscribe anytime.