Information Security Analyst
Job Location(s)
US-CA-Los Angeles
Job ID |
2025-2182
|
Category |
Information Technology
|
Department |
Engineering Solutions
|
Type |
Regular Full-Time
|
Position Summary
Overview: The Information Security Analyst is an early-career role within TCW's Information Security team, focused on supporting the firm's enterprise security and vulnerability management efforts. The team is responsible for protecting the confidentiality, integrity, and availability of the firm's data and technology assets through proactive monitoring, response, and continuous improvement of information security controls and processes. The analyst will gain hands-on experience with security monitoring, incident investigation, and collaboration across technology and business teams to strengthen the firm's overall security posture. Purpose: The Information Security Analyst will assist in the continuous improvement of TCW's information security operations by analyzing and assessing threats, supporting vulnerability management processes, and contributing to incident response activities. The analyst will work closely with experienced security professionals and cross-functional partners to detect risks, validate security events, and coordinate remediation efforts. This position offers a strong foundation for developing technical skills and understanding enterprise security operations in a dynamic, regulated environment.
Essential Duties
Support the full vulnerability management lifecycle, including vulnerability scanning, risk assessment, prioritization, and remediation efforts.
- Investigate, validate, and escalate suspicious or anomalous security activity through available tools and telemetry.
- Perform detailed analysis of alerts and events generated from security platforms to determine risk and potential impact to the firm.
- Contribute to the enhancement of technical controls and operational processes across the Information Security Program.
- Collaborate with technology and cross-functional teams to assess existing controls and implement security improvements.
- Document incident investigations, analysis steps, and remediation outcomes for knowledge sharing and continuous improvement.
- Participate in threat analysis activities, including reviewing threat intelligence and mapping to TCW's environment to identify risks or exposures.
- Support and maintain the firm's vulnerability management lifecycle, including vulnerability scanning, reporting, and remediation coordination.
- Conduct proactive threat hunting and investigation of anomalous behavior in TCW's systems and networks.
- Participate in regular security operations reviews and recommend improvements to processes, tools, or controls.
- Stay current with evolving threat landscape, attack techniques, and best practices in security monitoring and response.
- Perform other security-related duties as assigned.
Required Qualifications
- 1-4 years of experience in an Information Security Analyst, SOC Analyst, or similar role with significant exposure to security operations, incident and threat analysis
- Hands-on or foundational experience with SIEM platforms (e.g., Microsoft Sentinel, Splunk, QRadar, etc.) and vulnerability scanning tools (e.g., Qualys, Tenable, Rapid7).
- Understanding of incident response methodologies, threat detection, and information security principles.
- Strong analytical skills with the ability to identify root causes and provide actionable recommendations.
- Excellent written and verbal communication skills, including clear documentation of investigative steps and outcomes.
- Ability to work independently and collaboratively with technical and non-technical stakeholders.
- Comfortable managing multiple priorities in a fast-paced, evolving environment.
Professional Skills Qualifications
- Bachelor's degree in information security, Computer Science, Information Systems, or related field
- Familiarity with threat modeling frameworks (e.g., MITRE ATT&CK).
- Knowledge of security frameworks (e.g., NIST, ISO, CSA)
- Exposure to cloud platforms (e.g., Azure, AWS) and associated security practices.
- Experience with scripting or querying tools (e.g., KQL, PowerShell, Python) to assist with analysis and automation.
- Certifications such as Security+, CySA+, CEH, GCIA, GCIH, GSEC, or equivalent.
Estimated Compensation: Base Salary: For a CA based position, the base salary is $80-90K. Other Compensation:In addition to the base salary, this position will be eligible to be considered for an annual discretionary bonus. Benefits: Eligible for TCW's comprehensive benefits package. See more information here.
#LI-JS1
|