Cybersecurity Analyst
Kahana & Feld LLP New York, New York, United States
Law Practice · 201-500 employees
Applying here? Try the free cover letter tool — paste this posting and your résumé, no account needed.
About the role
The Cybersecurity Analyst will monitor security tools, investigate alerts, and support incident response and remediation efforts. They will also manage client security questionnaires and maintain documentation to ensure compliance with firm policies and standards.
What they look for
Requirements
Candidates must have at least 2 years of experience in information security, preferably within a law firm environment. A degree in a related field is required, along with hands-on experience in Microsoft 365 security and familiarity with industry frameworks like NIST or ISO 27001.
Full description
Description
The Cybersecurity Analyst will perform the day-to-day work required to protect the firm’s systems, networks, applications, and confidential information. This role will monitor security tools, investigate alerts, support incident response and remediation, work with the CIO to complete client security questionnaires, maintain documentation, and work closely with the infrastructure team.
Duties and Responsibilities
- Implement, operate, and document security controls under approved firm policies, standards, procedures, and change-management requirements.
- Monitor security alerts, logs, dashboards, and managed security service notifications; triage events, document findings, and escalate issues under established procedures.
- Support incident response through evidence collection, investigation, containment, user coordination, documentation, and remediation tracking.
- Run or coordinate vulnerability scans, validate findings, assign remediation tasks, and track corrective actions through closure.
- Work with the infrastructure and applications teams to maintain endpoint, network, cloud, identity, email, web, and data-protection controls.
- Assist with security tools for endpoint detection and response, event monitoring, email protection, multifactor authentication, mobile device management, and data loss prevention.
- Support user and privileged access reviews, joiner-mover-leaver controls, and investigation of unusual sign-in activity.
- Complete client and prospective-client security questionnaires by gathering current information and coordinating accurate, consistent, and timely responses.
- Maintain an organized library of approved questionnaire responses, control descriptions, supporting evidence, policies, certifications, and other due-diligence materials.
- Track findings from audits, tests, assessments, client reviews, and incidents, and follow up with assigned owners until completion.
- Support third-party security reviews by collecting questionnaires, reviewing available documentation, recording findings, and escalating concerns.
- Assist with phishing simulations, security awareness communications, user training, and follow-up coaching for employees who need additional guidance.
- Maintain operating procedures, system records, incident notes, knowledge base articles, metrics, and other security documentation.
- Stay current on relevant threats, vulnerabilities, product updates, and other law-firm security concerns.
- Perform other assigned security duties.
Qualifications & Skills
- Associate’s or Bachelor’s degree in cybersecurity, information technology, computer science, or a related field, or equivalent professional experience, is required.
- Minimum of 2 years of information security, cybersecurity, or security-focused information technology experience supporting a law firm.
- Hands-on experience with Microsoft 365 security and technologies such as Entra ID, Intune, Defender, Azure, or comparable platforms.
- Working knowledge of network, identity, endpoint, and email security; vulnerability management; patching; encryption; and backup protection.
- Experience completing client security questionnaires, collecting audit evidence, maintaining control documentation, or supporting security and compliance reviews.
- Familiarity with the NIST Cybersecurity Framework, CIS Controls, ISO 27001, SOC 2, or comparable security requirements.
- Ability to investigate alerts using logs, endpoint detection and response tools, event monitoring systems, vulnerability scanners, or managed security providers.
- Strong attention to detail, documentation, written communication, organization, and follow-through, with the ability to manage multiple assigned tasks and deadlines.
- Sound judgment, discretion, and a service-oriented approach when handling confidential information; Security+, SSCP, or a comparable certification is preferred but not required.
This job description reflects management's assignment of essential functions; it does not prescribe or restrict the tasks that may be assigned.
Equal Opportunity Employer
Kahana Feld provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
Job Type
Full-Time
Supervisory Responsibilities
None
Work Location
Hybrid or Remote
Physical Requirements
Primarily sedentary work. Exerting up to 40 pounds of force occasionally and/or negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects. Repetitive motion. Substantial movements (motions) of the wrists, hands, and/or fingers. The worker is required to have close visual acuity to perform an activity such as: preparing and analyzing data and figures; transcribing; viewing a computer terminal; extensive reading. Work is performed in an office environment and requires the ability to operate standard office equipment and keyboards. Must have the ability to walk short distances, and/or drive a vehicle to deliver and pick up materials. Work can be performed with or without accommodations.
Travel
Up to 10% domestic travel by ground and/or air, dependent on firm needs.
Similar roles
-
(LPS) Senior Cybersecurity Consultant
Lenovo Hong Kong, Hong Kong Island, Hong Kong S.A.R.
-
Cybersecurity Analyst
Valiant Solutions, LLC Dayton, Ohio, United States
-
Cybersecurity Analyst
Edgewater Federal Solutions, Inc. District of Columbia, United States · $190K–$200K/yr
-
Sr. Security Engineer - GRC APAC Fintech & Financial Services
SpaceXAI Tokyo, Japan
-
Security Engineer, Modern Workplace Technology, Security Services Remote
BCD Pune, Maharashtra, India
-
Graduate Application Security Analyst
NextGen Sydney, New South Wales, Australia