Punë
Information Security Analyst
Tirana International Airport
Përshkrimi
**Company Description**
Tirana International Airport (TIA) is the primary international gateway to Albania, connecting the country with Europe and beyond. Situated 15 km from the capital city of Tirana, TIA facilitates millions of passengers annually, playing a vital role in Albanian tourism, commerce, and investment. Managed by Kastrati Group since 2020, the airport has seen over €100 million invested in infrastructure, sustainability, and technological advancements. As one of the fastest-growing airports in Europe, TIA continues to expand its route network and enhance the passenger experience, solidifying its position as a premier international airport in the Western Balkans.
**Role Description**
This is a full-time, on-site role based in Tirana, Albania, for an Information Security Analyst.
The Information Security Analyst plays a key role in protecting Tirana International Airport’s digital infrastructure, systems, and information assets. Reporting to the IT & Technology Manager, the role supports the monitoring, detection, investigation, and response to cybersecurity threats while contributing to the continuous improvement of security controls, vulnerability management, and operational resilience.
Working closely with IT, Security, Safety, Compliance, and business teams, the Information Security Analyst helps ensure the confidentiality, integrity, and availability of TIA's information systems in a dynamic and critical infrastructure environment.
**Core Responsibilities**
**Security Monitoring & Threat Detection**
- Monitor security events and alerts generated by SIEM, EDR/XDR, email security, network security tools, and cloud platforms.
- Investigate and triage security alerts to identify genuine threats and reduce false positives.
- Escalate critical security incidents following established procedures and service levels.
- Support continuous improvement of security monitoring capabilities.
**Incident Response & Investigation**
- Support the full incident response lifecycle, including identification, containment, eradication, recovery, and post-incident review.
- Collect and analyze endpoint, server, network, and cloud logs during investigations.
- Assist in containment activities such as isolating endpoints, disabling compromised accounts, and blocking malicious domains or IP addresses.
- Maintain accurate documentation of incidents, investigations, and remediation actions.
**Vulnerability Management**
- Support vulnerability assessments and coordinate internal and external vulnerability scans.
- Prioritize remediation activities based on severity, exploitability, and business impact.
- Track remediation progress with system owners and verify issue resolution.
- Document exceptions and recommend compensating controls where necessary.
**Identity & Access Security**
- Support Identity and Access Management (IAM) activities, including user access reviews and least privilege principles.
- Investigate suspicious authentication events and potential credential compromise.
- Assist with Multi-Factor Authentication (MFA) implementation and privileged access management initiatives.
**Security Operations & Continuous Improvement**
- Assist in maintaining secure configurations for workstations, servers, and cloud services.
- Support endpoint protection technologies and detection rule improvements.
- Participate in backup validation and ransomware readiness activities.
- Contribute to the development and maintenance of security procedures, playbooks, and operational documentation.
**Security Awareness & Collaboration**
- Support cybersecurity awareness campaigns and phishing simulation initiatives.
- Provide guidance to employees on security best practices and incident reporting.
- Collaborate closely with IT, Security, Compliance, and operational teams to strengthen the organization's cybersecurity posture.
**Qualifications**
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field.
- Approximately 2 years of professional experience in Information Security, Cybersecurity, Security Operations (SOC), Network Security, or a related IT role.
- Solid understanding of networking fundamentals (TCP/IP, DNS, HTTP/HTTPS, VPN).
- Knowledge of Windows and/or Linux operating systems, authentication mechanisms, and security fundamentals.
- Familiarity with common cyber threats, phishing, malware, and incident response processes.
- Exposure to SIEM platforms, EDR/XDR solutions, vulnerability management, or cloud security is considered an advantage.
- Experience with Microsoft Defender, Microsoft Sentinel, Azure, or Microsoft 365 Security is a plus.
- Basic scripting knowledge (PowerShell or Python) and cybersecurity certifications (Security+, SC-200, CEH, etc.) are considered an advantage.
**Skills & Competencies**
- Strong analytical and problem-solving abilities.
- High attention to detail and investigative mindset.
- Excellent communication and documentation skills.
- Ability to collaborate effectively with technical and non-technical stakeholders.
- Strong organizational and time management skills.
- Eagerness to learn and continuously develop cybersecurity knowledge.
- Ability to remain calm and make sound decisions in high-pressure situations.
- Professional integrity and commitment to protecting confidential information.
Burimi: https://www.linkedin.com/jobs/view/4448899418/
Kërkesat
Niveli: mid level
Kjo shpallje vjen nga një burim i jashtëm. Aplikimi kryhet në faqen e punëdhënësit.
Apliko në burim