Harmonia Holdings Group, LLC · 21 hours ago
Cybersecurity Alerts Analyst
Harmonia Holdings Group, LLC is an award-winning, rapidly growing federal government contractor committed to providing innovative, high-performing solutions to our government clients. They are seeking a Cybersecurity Alerts Analyst to monitor key cybersecurity systems for intrusions and vulnerabilities, focusing on triage, investigation, and response for cloud-native security events.
ComputerRoboticsSoftware
Responsibilities
Review and triage alerts generated by Prisma Cloud as the first line of defense and identify if the alert is a true positive or a false positive
Use Prisma Cloud's features to enrich alerts with critical context; examining the affected asset (e.g., a container, serverless function, or virtual machine), its environment (e.g., production vs. development), its network exposure, and any associated user or service identities to help quickly determine severity and business impact
Prioritize the most critical alerts using Prisma Cloud's risk scoring and attack path analysis, focusing on incidents that show a clear path to sensitive data or a known exploitable vulnerability, rather than simply responding to every low-severity misconfiguration
Performs a deeper investigation for true positive alerts, pivoting from the alert to review associated logs, network traffic, and forensic data within Prisma Cloud's dashboard
Proactively use Prisma Cloud's tools to hunt for potential threats that haven't triggered an alert. This can involve searching for anomalous activity, suspicious network connections, or unauthorized changes to cloud configurations
Work to identify the root cause of the incident. For example, if a container has a vulnerability, they investigate why that container was allowed into production in the first place, or if a user has overly permissive access, they look into the reason behind it
Work with security orchestration, automation, and response (SOAR) playbooks, often integrated with Prisma Cloud, to trigger automated response actions. This could involve an automated process to disable a compromised user account or a "virtual patch" to a host to prevent an exploit
Provide the technical team with specific, actionable remediation steps where automation isn’t possible. This could be as simple as telling a DevOps engineer which misconfigured S3 bucket to lock down
Documents the investigation and provides clear, concise communication to stakeholders, escalating high-priority incidents to senior analysts or incident response teams, ensuring they have all the necessary context to take over
Fine-tuning Prisma Cloud policies to reduce "alert fatigue if they consistently see false positives from a certain rule and work with a senior engineers or a DevOps team to adjust the policy or exclude specific resources
Create new detection rules based on emerging threats or new compliance requirements, using Prisma Cloud's policy-as-code capabilities
Qualification
Required
Bachelor's Degree or higher - equivalent experience may be considered in lieu of a degree
3 years' experience with a SIEM tool, 5 years without a degree. (Splunk, Exabeam, SentinelOne, QRadar, Sumo Logic, etc)
Preferred
XSIAM and Prisma Cloud experience a plus
Experience with Agile project management methods and frameworks such as SCRUM
Exceptional written and verbal communication skills
Strong planning, organizational, and time management skills
Exceptional analytical and conceptual thinking skills
Strong leadership skills and ability to work collaboratively with a team of peers
Benefits
Traditional and HSA- eligible medical insurance plans
100% employer-paid dental and vision insurance options
100% employer-sponsored STD, LTD, and life insurance
5% 401(k) company matching
Flexible-schedules and teleworking options
Paid holidays and PTO Accrual Plans
Paid Parental Leave
Professional development and career growth opportunities
Team and company-wide events, recognition, and appreciation-- and so much more!
Company
Harmonia Holdings Group, LLC
Harmonia Holdings Group is a computer software company that provides application development services.
Funding
Current Stage
Growth StageTotal Funding
unknownKey Investors
Madison Dearborn Partners
2024-09-07Private Equity
Recent News
Washington Technology
2025-09-08
The Business Journals
2025-01-10
Company data provided by crunchbase