IT Cybersecurity Analyst

Chromalloy
Chromalloy

IT

Posted on Jul 24, 2026
Position Summary Work schedule: 11:00am - 7:00pm Pacific or Mountain TimeThe Global IT Security Analyst monitors, detects, investigates, and responds to cybersecurity threats across Chromalloy's global environment of 20+ facilities. Following Chromalloy's CMMC Level 2 certification (110/110 NIST 800-171 practices met), this role is central to sustaining that posture — operating an expanding security platform portfolio, driving incident response, and supporting the controls and evidence required of a defense-industrial-base company under ITAR, CUI, DFARS, and SOX obligations.This is a hands-on role for someone motivated by incident response, cross-functional collaboration, and strengthening the security of systems, infrastructure, and end-user computing. The analyst exercises strong technical judgment to prioritize and drive incidents to resolution while clearly communicating impact and next steps to technical teams and business partners. Chromalloy operates two Global IT Security Analyst seats on staggered East/West U.S. coast schedules to extend daily coverage and share an on-call rotation.Primary Accountabilities: Monitor, triage, and investigate security alerts using SIEM and EDR tooling (ReliaQuest GreyMatter MDR, CrowdStrike Falcon, Microsoft Defender, Palo Alto); validate severity and scope and document findings.Serve as an internal escalation point for the 24/7 MDR provider; lead containment and remediation (isolate endpoints, disable accounts, block indicators, reset credentials) and track actions to closure.Execute and continuously improve incident response processes and maintain playbooks/runbooks for common scenarios (phishing, malware, account compromise, ransomware), aligned to CYBER-002/CYBER-003.Operate and tune the FY26 security platform portfolio as assigned: SailPoint IGA (identity lifecycle, access reviews), Delinea PAM (and CyberArk evaluation), Titus and DSPM (data classification/posture), AI governance tooling (Securiti.AI, Harmonic), Palo Alto IoT/OT security, and the GRC platform.Own and run the security awareness program: phishing simulation campaigns, weekly user training, and monthly security culture communications; engage end users during investigations with clear, empathetic guidance.Coordinate and support the annual tabletop exercise, penetration test, and purple team engagement — including scoping, facilitation, and tracking all findings through remediation to closure with audit-ready evidence.Support governance and assurance: control evidence collection, policy/standard reviews, and third-party/vendor risk activities aligned to NIST 800-171, CMMC, DFARS 252.204-7012, ISO 27001, and CIS Controls.Create and tune detection content (queries, correlation rules, indicators) to improve signal quality and reduce false positives; maintain threat-intelligence awareness and translate it into actionable detections and hardening.Perform vulnerability management activities and basic malware triage and forensic collection as needed. Qualifications BS in Computer Science, Engineering, Information Technology, or equivalent experience.3–5 years in a cybersecurity / SOC / IT security operations role with hands-on incident triage, investigation, and coordinated response.Working knowledge of security frameworks and how they translate into operational controls: NIST 800-171/800-53, CMMC, DFARS, ISO 27001/27002, CIS Controls.Experience with common security tooling preferred: SIEM, EDR (CrowdStrike preferred), email security, vulnerability scanning, and identity/PAM platforms (SailPoint, Delinea/CyberArk); SOAR a plus.U.S. person status required for ITAR/CUI access (see Location & Eligibility).Security+ required; CySA+, GCIH, GCIA, CEH, or SSCP preferred.Strong written and verbal communication; able to explain risk and response to end users and stakeholders, produce incident documentation, and present post-incident findings.Ability to participate in a shared after-hours and weekend on-call rotation.Able to travel as needed, sometimes up to 30%.