Skip to content

Open nowPosted 21 hours ago

IT Security Analyst

WE Soda3 open roles

Where
Green River, WY 82935, USA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowIT Security AnalystWE Soda · Green River, WY 82935, USA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on WE Soda's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.8%1 day
  2. 3.6%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.0%30 days
This job: posted 21 hours ago

The posting

Title: IT Security Analyst Plant Information Resources  Location: Green River, WY (On-site)Supports operations across the United States and collaborates closely with global teams in the United Kingdom and Turkey. Reports to: Global Information Security Lead Direct Reports: None Role Purpose: The IT Security Analyst is the primary hands-on cybersecurity resource for WE Soda’s United States operations, covering both IT and OT/ICS environments. Reporting to the Global Information Security Lead, the role engineers, operates, and continuously improves the security controls protecting the US business — including firewalls and network security, SIEM, endpoint detection and response (EDR), OT security monitoring, email security, and data loss prevention — and acts as the local lead for security incident response, vulnerability management, and the security awareness program. The role works closely with the US IT team and with global information security colleagues in the UK and Turkey and supports post-acquisition integration by aligning US network and security services with WE Soda’s global standards, policies, and compliance requirements. Key Responsibilities: • Serve as the principal technical cybersecurity specialist for the US region, spanning IT and OT/ICS environments. • Engineer, configure, and maintain network security infrastructure: firewalls, VPN/remote access, network segmentation, IDS/IPS, and wireless security. • Administer the SIEM platform: log source onboarding, detection rule and use-case development, alert triage, tuning, dashboards, and reporting. • Administer the EDR/endpoint protection platform: policy management, threat hunting, containment, and response actions. • Support OT/ICS security: asset visibility and passive monitoring, IT/OT segmentation, and secure remote access to industrial environments, aligned with IEC 62443 and NIST SP 800-82. • Lead local detection, triage, containment, and recovery of security incidents, following global incident response playbooks and escalation paths. • Support the wider security program: email security and phishing triage, data loss prevention (DLP), security awareness activities, vulnerability and patch management, and audit/compliance evidence gathering. • Implement and enforce WE Soda security policies and standards and contribute to an Information Security Management System aligned with NIST CSF 2.0 and ISO 27001. • Communicate project status, risks, and achievements clearly to internal and external partners, including managed service providers. Activities:    Engineering and Provisioning • Configure, manage, and troubleshoot networking and security equipment (firewalls, switches, wireless, VPN concentrators). • Maintain secure network architecture and segmentation, including IT/OT boundary controls. • Conduct regular security assessments, network audits, and configuration reviews. • Apply security patches and firmware updates to network devices and security systems. • Perform network traffic analysis and packet inspection to investigate anomalies. Security Operations and Incident Response • Monitor and triage SIEM and EDR alerts; investigate suspicious activity and escalate per incident response procedures. • Execute containment and remediation actions during security incidents and produce incident reports and lessons learned. • Perform phishing triage and message removal for reported emails; feed confirmed indicators of compromise into blocking controls. • Coordinate vulnerability scanning, prioritization (including known-exploited vulnerabilities), and remediation tracking with system owners. • Act as the US point of contact for the managed security service provider (MSSP/MDR) and external penetration testing engagements. OT/ICS Security • Support deployment and operation of OT security monitoring tooling and asset inventory for industrial environments. • Work with plant engineering and operations teams to assess and reduce cyber risk to industrial control systems without disrupting production. Governance, Awareness and Compliance • Support the global security awareness program locally: phishing simulations, training assignment and completion follow-up, and awareness campaigns. • Implement and monitor DLP and data protection controls in line with data classification requirements. • Maintain evidence and documentation to support internal audits, certifications, and regulatory requirements. Maintenance and Support: • Document and maintain operations, configurations, standards, and procedures. • Monitor system performance and security, identifying and addressing issues proactively; ensure appropriate up time. • Maintain infrastructure system backups and the security camera system. • Participate in infrastructure support and the on-call rotation. • Support post-acquisition integration: assessment, alignment, and transition of network and security services to meet WE Soda’s standards and compliance requirements. Required Skills, Capabilities, and Educational Requirements: • University degree in computer science, information technology, cybersecurity, or a related field — or equivalent professional experience — plus 5+ years of network administration and cybersecurity experience in enterprise environments. • Hands-on firewall administration and network security engineering (e.g. Fortinet FortiGate, Cisco FTD/FMC), including IDS/IPS and secure remote access/VPN. • Deep knowledge of networking technologies (routing protocols, VLANs, ACLs, NAT, VPN) and proficiency with command-line interfaces (CLI). • SIEM administration and detection engineering experience (log onboarding, rule creation, alert tuning); LogRhythm experience is a strong advantage. • EDR/endpoint protection administration and threat hunting experience; Sentinel One experience is a strong advantage. • Practical security incident response experience: triage, investigation, containment, and reporting. • Working knowledge of OT/ICS environments and industrial protocols, and of securing IT/OT boundaries (IEC 62443, NIST SP 800-82). • Familiarity with Microsoft 365 and Entra ID security (Conditional Access, MFA) and email security controls. • Excellent problem-solving skills and the ability to communicate findings clearly to colleagues and management. • Strong attention to detail, strong communication and interpersonal skills, and the ability to work autonomously as the primary regional security resource within a global team spanning multiple time zones. Preferred Skills, Capabilities, and Educational Requirements: • Master’s degree in cybersecurity or a related discipline. • Experience with OT security monitoring platforms (e.g. Dragos, Claroty, Nozomi Networks). • Hands-on experience with Cisco FTD, FMC, WLC, ISE, AnyConnect VPN, Duo, Microsoft SCCM/Intune, and Commvault. • Experience with email security gateways (e.g. Proofpoint, Microsoft Defender for Office 365), phishing triage platforms, DLP tooling, and security awareness platforms (e.g. KnowBe4). • Scripting and automation skills (PowerShell, Python). • Familiarity with security frameworks and regulations: NIST CSF 2.0, NIST SP 800-53, ISO 27001, and US state breach notification requirements. • Professional certifications such as CompTIA Security+ or CySA+, GIAC (GSEC, GCIA, GCIH, GICSP), Fortinet NSE, Cisco security certifications, or CISSP. • Experience in manufacturing, chemical, or other critical infrastructure sectors.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against WE Soda's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on WE Soda's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    WE Soda's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.