Running head: INFORMATION SECURITY ANALYST CAREER 1
Research Paper: Information Security Analyst Professional Career
Author:
Class: CSIS110 Introduction to Computer Science
Institutional Affiliation: Liberty University
Author Note
No grant or external funding was received to conduct the research or write this paper.
INFORMATION SECURITY ANALYST CAREER 2
Abstract
In today’s interconnected world, where cyber threats loom large, the role of Information Security
Analysts has become critical. These professionals are entrusted with the important task of
safeguarding an organization’s computer systems and networks against cyber risks, unauthorized
access, and data breaches. In this research paper, I delve into the multifaceted responsibilities of
information security analysts working for the Defense Department, exploring their impact on
organizational security and the broader cybersecurity landscape that includes risk assessment and
mitigation, security and incident response, policy development and implementation, vulnerability
management, and emerging threat landscape. The research paper aims at informing information
technology enthusiasts about the unsung heroes who protect sensitive data and uphold
organizational security in any enterprise. Additionally, the paper will briefly discuss how this
career support government agencies to carry out national security actions.
Running head: INFORMATION SECURITY ANALYST CAREER 3
Information Security Analyst: Unsung Heroes Who Protect Sensitive Data
In an era where digital threats loom large, Information Security Analysts emerge as the
unsung guardians of our interconnected world. These professionals meticulously plan and
execute security measures to protect an organization’s computer networks and systems. Their
multifaceted responsibilities span risk assessment, security monitoring, incident response, and
policy development. Armed with a bachelor’s degree in a computer science field and relevant
work experience, information security analysts stand at the forefront of safeguarding critical
data. Within government agencies, information security analysts play a pivotal role. They secure
critical infrastructure, analyze cyber threats, and collaborate closely with intelligence agencies.
By detecting vulnerabilities, monitoring security, and minimizing risks, these cyber sentinels
ensure that our digital borders remain unaffected. As we unravel the intricate threads that weave
them into the fabric of national security, their tireless efforts resonate far beyond the confines of
code and firewalls.
Job Description
Information Security Analyst safeguard organizations against cyber threats. They design
and implement security systems to protect computer networks from attacks. In addition, these
information technology experts monitor networks to detect vulnerabilities, investigate security
breaches, and assess the damage caused. These analysts also install security measures and
operate security software, including firewalls, and data encryption programs. But the job
description does not end there. Information security analysts must stay informed, current on IT
security trends, news, and emerging threats since they research security enhancements and
recommend improvements to management, as well as collaborating with teams. They work
INFORMATION SECURITY ANALYST CAREER 4
closely with programmers, developers, and other government and nongovernmental
organizations to defend national security digital assets.
Typical Job. Tasks of an Information Security Analyst.
Task One. Risk Assessment and Mitigation
Information security analysts meticulously assess vulnerabilities within an organization’s IT
infrastructure. They identify potential risks, evaluate security controls, and recommend strategies
to fortify defenses.
Task Two. Security Monitoring and Incident Response
These professionals vigilantly monitor networks, detecting and investigating security breaches.
When incidents occur, they swiftly respond, mitigating damage and restoring integrity.
Task Three. Policy Development and Implementation
Analysts shape security policies, ensuring compliance with industry standards. Their efforts
establish best practices, safeguarding critical data.
Task Four. Vulnerability Management
By prioritizing vulnerabilities, information security analysts collaborate with IT teams to patch
weaknesses and minimize exposure.
Task Five. Cyber Threat Intelligence
By analyzing threats, information security analysts provide actionable intelligence to government
agencies, enabling proactive defense and deterrence.
INFORMATION SECURITY ANALYST CAREER 5
Typical Job Advertisements
1. Information Security Analyst – Beale AFB. Information Security Analyst Senior -
Beale AFB (gdit.com)
JOB DESCRIPTION
Join General Dynamics IT and be a part of a team that solve some of the world's most complex
technical challenges. General Dynamics Information Technology (GDIT), a world leader in
Defense IT Systems Integration and Services, is seeking an Information Security Analyst Senior
to join its Air Force (AF) Distributed Common Ground System (DCGS) Enterprise Product
Support (EPS) team.
We provide modernization for the integrated sustainment of the AF DCGS which also includes
lab support for operational, production and test environments. This position is located at Beale
AFB, CA. As the Information Security Analyst Senior, you assess and mitigate system security
threats and risks throughout the program life cycle:
Validate system security requirements definition and analysis.
Establish system security designs.
Verifies security requirements and performs system certification and accreditation planning and
testing and liaison activities.
Support secure systems operations and maintenance.
Participate in infrastructure design reviews, identifying security and privacy risks, providing
infrastructure risk mitigation guidance, and participating in Security and Privacy certification and
accreditation.
Basic Qualifications:
INFORMATION SECURITY ANALYST CAREER 6
BS/MS degree; additional years of experience may be considered in lieu of degree 3-10
years of experience with security systems development and analysis
Security+
TS with SCI Eligibility
2. Information Security Tech Lead Analyst. Information Security Tech Lead Analyst at
Citi
Citibank, N.A. seeks an Info Security Tech Lead Analyst for its Irving, TX location.
Duties: Assist the Early Application Vulnerability Detection (EAVD) team, as part of the
Vulnerability Assessments (VA) organization, with the implementation and integration of
automated application security testing tools in a continuous integration and continuous delivery
(CI/CD) environment. Use subject matter expertise in multiple security domains and perform
static analysis, binary analysis, and dynamic assessments against thick, web, mobile, and cloud
applications to identify security risks and recommend appropriate controls to application teams.
Foster constructive dialogue and resolve differing opinions on security risks. Engage and partner
with application development teams on vulnerability remediation techniques and security design
pattern recommendations. Plan and document new testing and operational processes. Assume
informal and formal mentorship roles within teams and assist with the coaching and training of
new team members. Collaborate with different Vulnerability Assessment teams to share testing
and remediation techniques and experience. Remote work may be permitted within a
commutable distance from the worksite, in accordance with Citi policy.
Requirements: Bachelor’s degree, or foreign equivalent, in Computer Science (any),
Engineering, Technology or a related field of study, and five (5) years of experience in the job
offered or in a related occupation. Must possess five (5) years of experience with all of the
INFORMATION SECURITY ANALYST CAREER 7
following: Utilizing knowledge of software development lifecycles and CI/CD pipelines;
Perform manual source code review for security vulnerabilities and vulnerability review call;
Validating automated testing results such as SQL Injection, Cross side scripting, Authentication
bypass vulnerabilities; Creating self-service vulnerabilities remediation initiatives with the
development team to triage vulnerabilities and writing secure code to avoid risk exposure;
Utilizing static analysis tools such as Checkmarx. 40 hrs./wk. Applicants submit resumes at
https://jobs.citi.com/ or by email to Citigroup Recruiting Dept. at
[email protected]. Please reference Job ID# 23701273. EO Employer.
Wage Range: $175,440.00 to $181,337.27
Job Family Group: Technology
Job Family: Information Security
3. Security Analyst – (CON-20-00211) Careers - Yorktown Systems Group (hrsmart.com)
Job Title
Security Analyst
Location
Fort Eustis, VA - Fort Eustis, VA 23604 US (Primary)
Category
Contractors
Job Description
Summary:
Yorktown systems Group is seeking highly qualified Security Analyst to provide professional
services and support to the TRADOC Deputy Chief of Staff for Intelligence (G-2) Operational
INFORMATION SECURITY ANALYST CAREER 8
Environment (OE) and Core Functions. The Operational Environment (OE) is a composite of the
conditions, circumstances, and influences that affect the employment of military forces and bear
on the decisions of the unit commander. As an organic, complex system, the OE provides the
common framework in which warfighting programs and strategies are conceived, defined, and
executed. It is a living foundation in which choices made, by adversary and allies alike, affect the
outcome of the future which must be accounted for. As adversary’s asymmetrical approach to
warfare continues to generate greater complexity and flexibility, the government’s requirement
for similar complexity and adaptability in Tactics, Techniques and Procedures (TTPs) escalates
correspondingly.
Specific duties may include, but are not limited to:
In support of TRADOC trainee security holdover tracking, collects and validates all field-
provided inputs, updates security holdover summary products, and verifies high time or
high interest individual status with the investigating agency and/or the adjudicating
agency. Updates or creates reporting templates (MS Excel, PowerPoint, Word) as
required.
Provide administrative processing of security portal access requests for TRADOC.
Thoroughly validate CoE, DRU, and HQ Staff requests for access to security clearance
and supporting portals. These portals include: Defense Information System for Security
(DISS), Joint Personnel Adjudication System (JPAS), Personnel Security Investigation
Portal (PSIP), Consolidated Adjudication Facility (CAF), NBIB's Public Portal (NP2),
and any of their successor programs. Also processes account termination requests when
access is no longer needed or appropriate.
INFORMATION SECURITY ANALYST CAREER 9
Support command-level and G-2 meetings and conferences with clearance verification,
creation and issuance of event security badges, event entry control, and support to
classified portions as needed to prevent security incidents.
Conduct other security related administrative actions including, but not limited to:
overseas classified courier requests, continuous evaluation notifications, daily and
monthly security checks and management (SF 701, SF702), and responding to telephonic
and email requests for information (RFI) and other customer support requirements.
Required Qualifications:
Must have 8 years’ experience providing administrative security assistance in the areas of
Personnel, Information, and NATO Security as described in AR 380-5, AR 380-67, and USSAN
1-07, respectively.
Must be proficient with Microsoft Office products (MS Excel, PowerPoint, Word).
Possess a thorough knowledge and understanding of the following systems:
Defense Information System for Security (DISS)
Joint Personnel Adjudication System (JPAS)
Personnel Security Investigation Portal (PSIP), Consolidated Adjudication Facility (CAF)
NBIB’s Public Portal (NP2)
Clearance: Secret clearance is required.
Location: Fort Eustis, VA
Travel: Some travel (less than 5%) may be required.
Job Type
Full-time
Exemption Type
INFORMATION SECURITY ANALYST CAREER 10
Exempt
Travel
Some travel may be required
Career Possibilities
Salary Range
The estimated total pay for an information security analyst is $120,761 per year in the
United States area, with an average salary of $112,619 per year (Glassdoor, 2024). These
numbers represent the median, which is the midpoint of the ranges from our proprietary Total
Pay Estimate model and based on salaries collected from our users. The estimated additional pay
is $8,142 per year. Additional pay could include cash bonus, commission, tips, and profit
sharing. The "Most Likely Range" represents values that exist within the 25th and 75th percentile
of all pay data available for this role.
Types of Industries
Information Industry: The information industry is composed of companies that produce,
gather, and create large amounts of data. These include companies in the fields of research,
surveys, data analytics, cloud solutions, software solutions, media, and production. The
information industry deals with a vast amount of sensitive data that holds an intangible value. It
is most vulnerable to threats, manipulation, and data loss. “It is common for companies in this
industry to hire a security engineer, security consultant, security architect, security analyst, and
other cyber security consultants to conduct risk assessments and digital forensics”
(CareerKarma.2022).
INFORMATION SECURITY ANALYST CAREER 11
Telecommunications Industry: The telecommunications industry connects people through
the internet, telephones, televisions, radios, and other services. They bring their technology
to households, individuals, businesses, and the government. This industry is one of the top
employers of computer software engineers, telecommunications specialists, information
security analysts, and network systems analysts. They hire cyber security analysts to
prevent potential threats such as Distributed Denial of Service (DDoS) attacks, routing
attacks, and Session Initiation Protocol (SIP) hacking. For this industry, entry-level jobs
for a professional position require a bachelor’s degree, preferably in engineering or any
computer-related field. Continuing studies and an advanced degree will help grow your
career much faster in this field.
Computer System Design and Related Services: The computer systems and design industry
conducts business with various institutions to help them design, implement, and manage their
systems, security controls, and software products so that office workflow will be efficient. They
work on a per-project or contract basis. Typical projects include setting up a marketplace and
creating a secure website. This industry mostly hires computer systems analysts, software
engineers, and programmers. Still, they also employ various professionals in computer-related
and administrative fields because the nature of work requires multiple hard and soft skills.
Geographic Locations
New York. Companies centered in the New York metropolitan areas are in high demand
for information Security analysts.
Virginia. This state is known as the military industrial complex conglomerate, and it is always in
search of highly competent information security analysts to propel national security objectives
and policies.
INFORMATION SECURITY ANALYST CAREER 12
Texas. The cities of Huston, Austin, and San Antonio are in high demand for security analysts.
Companies like IBM, Oracle, Department of Defense, Hitachi Consulting, and General
Dynamics are some of the major employers in the state.
Preparation
Training
You can take several paths to becoming an information security analyst. Ultimately,
you’ll need to have certain skills. These include:
Computer security basics. This includes knowledge of firewalls, routers, and other security
infrastructure, as well as an understanding of risk management frameworks. Some information
security jobs might ask for ethical hacking or penetration testing experience.
Familiarity with privacy laws. Information security analyst positions can call for familiarity with
data privacy laws in your region. Working in specific sectors, like health care or finance, might
also call for an understanding of those sectors’ privacy laws.
Communication and teamwork. Knowing where and how security threats happen, and
responding to them once they do, means you’ll be communicating frequently with your team and
other players (Cursera.org, 2024)
Education.
IT certifications: Earning a cybersecurity certification can give you a knowledge base in
security issues, while also giving you the credentials to show employers your competency.
Certifications in security or networks are a good place to start.
Degrees: Information security analyst positions typically call for at least a bachelor’s degree. The
majority of employers look to ideally hire candidates with a bachelor’s degree or a two-year
diploma in an appropriate field of study such as information technology and computer science.
INFORMATION SECURITY ANALYST CAREER 13
“Majoring in computer science or computer engineering can set you up to be a competitive job
candidate for information security jobs upon graduation” (R. Half, 2023).
Work Experience
Many employers required a minimum work experience of 3 years working in the field or
related experience that can translate into the job field where the professional has conducted the
duties of network administrator, security analyst, information technology lead, security engineer,
program developer, cybersecurity OPS officer, and digital counter-threat officer. “Many required
industry certifications such as CompTIA- Security+ network security, and ethical hacker”
(Galarita, 2024).
Fulfillment of Giftings (SWOT Analysis)
Giftings
I can become an information security analyst because I possess a strong foundation in
technology and a keen interest in safeguarding digital assets. My qualifications include
educational background. I am in the process of finishing a degree in a relevant field such as
Computer Science, Information Technology, or Cybersecurity. My coursework has equipped me
with knowledge in network security, cryptography, risk management, and ethical hacking.
Certifications: I am enrolled in pursuing a google certification in information technology. I
intend to complete industry-recognized certifications, such as CompTIA Security+, Certified
Information Systems Security Professional (CISSP), or Certified Ethical Hacker (CEH). These
certifications demonstrate my commitment to staying current with security best practices.
Technical Skills: I am proficient in firewall configuration, intrusion detection systems, and
vulnerability assessment tools. My hands-on experience with tools like Wireshark, Nmap, and
Metasploit showcases my practical expertise.
INFORMATION SECURITY ANALYST CAREER 14
Analytical Mindset: I excel at analyzing security incidents, identifying vulnerabilities, and
proposing effective solutions. My ability to think critically and troubleshoot complex issues sets
me apart.
Communication Skills: I understand the importance of clear communication. Whether writing
security policies, conducting risk assessments, or collaborating with cross-functional teams, my
ability to convey technical concepts to non-technical stakeholders is invaluable.
Professional Need Analysis
To become an information security analyst, several essential steps are crucial. First,
acquire at least a bachelor’s degree in a relevant field such as Computer Science, Cybersecurity,
or Information Technology. These programs provide foundational knowledge in areas like
network security, cryptography, and risk management. Next, gain practical work experience in
IT or related roles to understand real-world security challenges. Consider internships or entry-
level positions. Additionally, pursue industry-recognized certifications such as CompTIA
Security+, CISSP, or CEH to validate your skills. Lastly, stay updated through continuing
education, attend workshops, and participate in professional development activities to keep pace
with the evolving field of cybersecurity. “By combining education, experience, certifications,
and a passion for security, you’ll be well-prepared for a successful career in this dynamic
domain” (White, 2023).
Gifting Gap Analysis
Based on my current background and qualifications, here are the areas that I believe I
need to focus on to bridge the gaps and become a successful information security analyst.
Let’s begin with Certifications. While I have foundational knowledge from my degrees and
courses, I need to consider pursuing industry-recognized certifications. These certifications
INFORMATION SECURITY ANALYST CAREER 15
validate my expertise and enhance my marketability. I understand that CompTIA Security+ is a
great starting point for understanding security fundamentals. The Certified Information Systems
Security Professional (CISSP) is also another prestigious certification that demonstrates my
advanced knowledge in various security domains. I intend to pursue this one in the following
months. A Certified Ethical Hacker (CEH) is also essential in this industry, and it focuses on
ethical hacking techniques and vulnerability assessment. And lastly, Certified Information
Security Manager (CISM) is one of the most important. It emphasizes information risk
management and governance.
Hands-On Experience is another area where I am lacking. I need to seek practical experience
related to security. I am considering internships, volunteer work, and personal projects.
I am in the process of setting up a home lab to practice configuring firewalls, intrusion detection
systems, and other security tools.
Networking and Community Involvement is another area where I need to close the
educational/experience gap. I see the need to join local or virtual security meetups, conferences,
and forums. I understand that networking with professionals in the field can provide valuable
insights and job opportunities. And lastly, engaging with online communities, following security
blogs, and contributing to open-source projects can enhance my ability to finally become an
information security analyst.
Kingdom Mission
In the realm of information security, the role of an analyst extends beyond safeguarding
data and networks—it intersects with broader ethical and spiritual considerations. As followers
of Christ, information security analysts can actively contribute to the Kingdom Mission in
several ways. The first one is being a steward of God’s creation. This implies securing digital
INFORMATION SECURITY ANALYST CAREER 16
assets, protecting valuable information that impacts individuals, organizations, and communities.
This stewardship aligns with the biblical mandate to care for God’s creation and exercise
responsible dominion. A second consideration is promoting justice and integrity. This
entails upholding confidentiality, integrity, and availability that aligns with the biblical principles
of honesty, fairness, and justice. Analysts play a vital role in ensuring that systems operate
ethically and transparently.
Lastly, considerations such as safeguarding vulnerable populations are of
extreme importance in the life of a Christian. In a world where cyber threats disproportionately
affect marginalized communities, “information security analysts can advocate for equitable
protection”( Lee-Zankl, 2019). Their work contributes to a safer digital environment for all,
reflecting Christ’s concern for the vulnerable. The digital realm is not immune to spiritual
battles. Attacks on systems mirror the unseen warfare described in Scripture. Analysts must
recognize their role in defending against both physical and spiritual threats.
Conclusion
The multifaceted arena of information security demands a comprehensive understanding
of the roles and responsibilities entrusted to information security analysts. As guardians of digital
assets, these professionals shoulder the weighty responsibility of safeguarding sensitive data and
critical infrastructures against evolving cyber threats. The continuous evolution of technology
underscores the necessity for ongoing professional development, education, and ensuring that
information security analysts remain equipped with the latest tools and knowledge to counteract
emerging risks. Furthermore, the critical role they play in national security is evident as they act
as the first line of defense against cyber-attacks that could have far-reaching consequences on a
INFORMATION SECURITY ANALYST CAREER 17
global scale. Amidst these challenges lie opportunities for innovation, collaboration, and the
cultivation of a robust cybersecurity ecosystem. Therefore, fostering a emerging and resilient
professional group of information security analysts is not only essential for protecting our digital
assets but is also integral to the broader landscape of national security in an interconnected
world. May God continue to give us wisdom to comprehend the challenges of the emerging
world.
Running head: INFORMATION SECURITY ANALYST CAREER 2
References
1. Coursera Staff. 2023. How to Become an Information Security Analyst: Salary, Skills and
More. Coursera.org. Article. Accessed on 3 February 2024. Retrieved from: How to
Become an Information Security Analyst: Salary, Skills, and More | Coursera
2. Robert Half. 2023. The 29 Most Valuable IT Certifications. Robert Half Inc. Article.
Accessed on 5 February 2024. Retrieved from: The 29 Most Valuable IT Certifications
(roberthalf.com).
3. Brandon Galarita. 2024. Top Information Technology Careers: Salaries, Degrees, and Job
Growth. Forbes Advisor. Article. Accessed on 5 February 2024. Retrieved from: Degrees,
Salaries, And Job Outlook For Information Technology Careers – Forbes Advisor
4. Sara K. White. 2023. 16 best entry-level IT certifications to launch your career. CIO
publisher. Article. Accessed on 5 February 2023. Retrieved from: 16 best entry-level IT
certifications to launch your career | CIO
5. Dr. Christopher Ahlberg. 2018. Threat Intelligence Handbook: A Practical Guide for
Security Teams to Unlocking the Power of Intelligence. Second Edition CyberEdge Group
Publisher. Textbook. Accessed on 5 February 2024. Retrieved from: The Threat
Intelligence Handbook, Second Edition | Recorded Future
6. Wanbil W. Lee & Wolfgang Zankl. (2019). An Ethical Approach to Data Privacy
Protection. ISACA org. Article. Accessed on 5 February 2024. Retrieved from: An Ethical
Approach to Data Privacy Protection (isaca.org).
7. Katie Lange. 2018. DOD’s Cyber StrategyV: 5 Things to Know. U.S. Department of
Defense. Article. Accessed on 5 February 2024. Retrieved from: DOD’s Cyber Strategy: 5
Things to Know > U.S. Department of Defense > Story