Tirana International Airport SHPK (TIA) kërkon të punësojë një Information Security Analyst, që do të raportojë te IT&T Manager i kompanisë.
Kërkesat e pozicionit:
The Information Security Analyst helps protect the organization’s systems, networks, applications, and data by monitoring threats, investigating suspicious activity, supporting incident response, and improving security controls. This role works closely with IT, Security, Safety, Compliance and business teams to reduce risk through strong operational processes, vulnerability management, and security awareness.
Detyrat dhe përgjegjësitë kryesore të pozicionit:
1) Security Monitoring & Alert Triage
- Monitor security alerts from SIEM, EDR/XDR, email security, network tools and cloud platforms.
- Triage alerts, determine severity, validate true/false positives, and document findings.
- Escalate high-risk events using defined procedures and SLAs.
2) Incident Response Support
- Support the incident response lifecycle: identify, contain, eradicate, recover, and lessons learned.
- Collect and analyze evidence (logs from computers and network devices).
- Assist with containment actions (e.g., isolating endpoints, disabling accounts, blocking domains/IPs) per policy.
- Contribute to post-incident reviews and updates to runbooks and detections.
3) Threat Investigation & Analysis
- Analyze endpoint, identity, network, and cloud logs to build a timeline and determine scope/impact.
- Investigate phishing reports and suspicious emails, coordinate quarantines and user guidance.
- Identify patterns and recurring root causes and recommend improvements.
4) Vulnerability Management
- Run or coordinate vulnerability scans (internal/external) and validate results.
- Prioritize remediation based on severity, exploitability, and asset criticality.
- Track remediation progress with system owners and verify closure.
- Document exceptions and compensating controls when remediation is not immediately possible.
5) Identity & Access Security (IAM) Support
- Support access reviews and least privileged practices.
- Investigate suspicious logins and credential compromise signals.
- Assist with MFA adoption and privileged access controls.
6) Security Hygiene & Control Improvements
- Support secure configuration and hardening baselines (workstations/servers/cloud services).
- Help maintain endpoint protection policies and improve detection rules.
- Assist with backup/ransomware readiness checks in collaboration with IT.
7) Documentation, Reporting & Collaboration
- Maintain accurate incident tickets, investigation notes, and evidence artifacts.
- Produce periodic security summaries.
- Update and create playbooks/runbooks for common scenarios (phishing, malware, suspicious login).
- Work cross-functionally with IT, Security and business teams to drive remediation and prevention.
8) Security Awareness Support
- Help deliver awareness initiatives, support phishing simulations, and reinforce secure practices.
- Provide end-user guidance on reporting incidents and handling sensitive data.
Arsimi:
Degree/diploma in IT, Cybersecurity or related field
Eksperienca e punës:
Work Experience: at least 2+ years in Cyber Security, Network Specialist, IT or relevant position
Foundational IT knowledge:
- Networking basics (TCP/IP, DNS, HTTP/HTTPS, VPN concepts)
- OS basics (Windows and/or Linux logs, processes, permissions)
- Security basics (phishing, malware, authentication, common attack patterns)
- Preferred Qualifications (Nice-to-Have):
- Exposure to any SIEM/log search concepts and basic queries.
- Familiarity with an EDR console.
- Basic scripting or automation interest (PowerShell/Python) and comfort working with CSV/Excel data.
- Familiarity with vulnerability concepts (CVSS, patching priorities, remediation workflows).
- Cyber Security Certifications
- Any cloud/SaaS familiarity (Azure/AWS/GCP basics; identity and logging concepts).
Aftësi dhe Kompetenca:
- Strong analytical skills and attention to detail; comfortable working with tickets and documentation.
- Ability to communicate clearly with technical and non-technical colleagues.
- Willingness to learn tools in a mixed environment and follow procedures.
Tirana International Airport SHPK (TIA) kërkon të punësojë një Information Security Analyst, që do të raportojë te IT&T Manager i kompanisë.
Kërkesat e pozicionit:
The Information Security Analyst helps protect the organization’s systems, networks, applications, and data by monitoring threats, investigating suspicious activity, supporting incident response, and improving security controls. This role works closely with IT, Security, Safety, Compliance and business teams to reduce risk through strong operational processes, vulnerability management, and security awareness.
Detyrat dhe përgjegjësitë kryesore të pozicionit:
1) Security Monitoring & Alert Triage
- Monitor security alerts from SIEM, EDR/XDR, email security, network tools and cloud platforms.
- Triage alerts, determine severity, validate true/false positives, and document findings.
- Escalate high-risk events using defined procedures and SLAs.
2) Incident Response Support
- Support the incident response lifecycle: identify, contain, eradicate, recover, and lessons learned.
- Collect and analyze evidence (logs from computers and network devices).
- Assist with containment actions (e.g., isolating endpoints, disabling accounts, blocking domains/IPs) per policy.
- Contribute to post-incident reviews and updates to runbooks and detections.
3) Threat Investigation & Analysis
- Analyze endpoint, identity, network, and cloud logs to build a timeline and determine scope/impact.
- Investigate phishing reports and suspicious emails, coordinate quarantines and user guidance.
- Identify patterns and recurring root causes and recommend improvements.
4) Vulnerability Management
- Run or coordinate vulnerability scans (internal/external) and validate results.
- Prioritize remediation based on severity, exploitability, and asset criticality.
- Track remediation progress with system owners and verify closure.
- Document exceptions and compensating controls when remediation is not immediately possible.
5) Identity & Access Security (IAM) Support
- Support access reviews and least privileged practices.
- Investigate suspicious logins and credential compromise signals.
- Assist with MFA adoption and privileged access controls.
6) Security Hygiene & Control Improvements
- Support secure configuration and hardening baselines (workstations/servers/cloud services).
- Help maintain endpoint protection policies and improve detection rules.
- Assist with backup/ransomware readiness checks in collaboration with IT.
7) Documentation, Reporting & Collaboration
- Maintain accurate incident tickets, investigation notes, and evidence artifacts.
- Produce periodic security summaries.
- Update and create playbooks/runbooks for common scenarios (phishing, malware, suspicious login).
- Work cross-functionally with IT, Security and business teams to drive remediation and prevention.
8) Security Awareness Support
- Help deliver awareness initiatives, support phishing simulations, and reinforce secure practices.
- Provide end-user guidance on reporting incidents and handling sensitive data.
Arsimi:
Degree/diploma in IT, Cybersecurity or related field
Eksperienca e punës:
Work Experience: at least 2+ years in Cyber Security, Network Specialist, IT or relevant position
Foundational IT knowledge:
- Networking basics (TCP/IP, DNS, HTTP/HTTPS, VPN concepts)
- OS basics (Windows and/or Linux logs, processes, permissions)
- Security basics (phishing, malware, authentication, common attack patterns)
- Preferred Qualifications (Nice-to-Have):
- Exposure to any SIEM/log search concepts and basic queries.
- Familiarity with an EDR console.
- Basic scripting or automation interest (PowerShell/Python) and comfort working with CSV/Excel data.
- Familiarity with vulnerability concepts (CVSS, patching priorities, remediation workflows).
- Cyber Security Certifications
- Any cloud/SaaS familiarity (Azure/AWS/GCP basics; identity and logging concepts).
Aftësi dhe Kompetenca:
- Strong analytical skills and attention to detail; comfortable working with tickets and documentation.
- Ability to communicate clearly with technical and non-technical colleagues.
- Willingness to learn tools in a mixed environment and follow procedures.