Skip to main content

Hire security analysts

An alert is only the start of the investigation.

Security analysts investigate signals using trustworthy asset, identity and event evidence, then explain confidence, gaps and proposed next steps. Effective work connects technical findings to exposure and business context. Werkon should assess one bounded investigation and its handoff, while incident command, production action, legal judgment, disclosure and risk acceptance remain with accountable client owners.

Responsibility contract

Give defensive evidence an owner without making the analyst the incident commander.

A security analyst can improve signals, investigate behavior and recommend action. They cannot grant themselves production access, declare legal facts, attribute an actor from a weak indicator, contain systems without authority or accept residual risk. Define the mandate and escalation path before the first alert.

01

Client security, incident, production, and risk authority

Named owners define the mandate, approve access and actions, command incidents, and make consequential decisions.

  • Security service product data identity asset and business owners define protected outcomes, criticality, threat priorities, in-scope systems, ownership, acceptable use, monitoring objectives, classification, escalation thresholds and material risk; resolve inventory and policy conflicts; and decide which defensive services are required.
  • Platform cloud network endpoint application data and supplier owners identify deployed assets, versions, dependencies, logging capability, control state and recovery paths; grant least-privilege time-bounded access; approve instrumentation; maintain source health; diagnose causes; and execute authorized technical changes.
  • Incident command legal privacy compliance communications people insurance finance executive and production owners declare and classify incidents; authorize containment evidence handling external support notification disclosure restoration and exceptions; weigh operational harm; accept residual risk; and make customer regulator law-enforcement and public decisions. The analyst does not sign for them.
02

Security analyst contribution

The analyst turns defensive questions and imperfect signals into bounded, reproducible findings.

  • Map owned assets identities services data paths trust boundaries and telemetry to threat and incident questions; document source purpose schema clock collection retention integrity privacy access and health; identify blind spots; design and tune detection hypotheses; test expected signal paths safely; and keep source loss or disabled monitoring visible.
  • Triage events and alerts using asset identity baseline change vulnerability and threat context; preserve raw evidence and queries; build timelines; correlate independent sources; distinguish indicator observation inference and attribution; record confidence alternatives and missing data; escalate according to impact and mandate; and maintain a defensible case trail without collecting unrelated private content.
  • Validate affected asset version reachability exposure control and exploit context for vulnerabilities; separate severity from local risk and priority; propose containment remediation monitoring and recovery options with side effects; support authorized execution; verify outcomes; update cases detections controls runbooks and risk records; and leave client-owned queries evidence decisions and handoff materials.
03

Shared defensive operating model

Detection and response cross engineering, operations, security, privacy, legal, communications, suppliers, and business ownership.

  • Engineering and platform teams make applications identities and infrastructure observable; asset owners keep inventory and criticality current; threat and vulnerability specialists contribute context; incident responders coordinate action; legal privacy and communications owners handle duties and exposure; service owners restore safe operation.
  • Tools may ingest telemetry, correlate entities, enrich indicators, score vulnerabilities, group alerts, summarize cases or propose queries, but people validate source health, local deployment, timeline, inference and authority. Automation cannot declare an incident, attribute an actor, approve containment or conceal missing evidence.
  • Governance reviews access, retention, detection quality, false positives, false negatives, blind spots, vulnerability aging, incident actions and recovery evidence; exercises the plan; feeds lessons into design and testing; and confirms another qualified person can continue. Hiring owners confirm competence, safe judgment, terms and current availability.

Capability evidence

Assess one defensive question from source coverage to an owned response.

A dashboard tour and alert count are weak hiring evidence. Use a case with an incomplete asset record, a delayed source, a plausible benign explanation, a vulnerable component and a containment option that could harm the service.

01

Assets, identities, telemetry, logging, and detection coverage

Provide conflicting inventories, several log sources and a request for complete monitoring. Ask the person to define the questions the evidence can and cannot answer.

Confirm: The person begins with protected business and service outcomes; maps assets, versions, owners, identities, privileges, data, dependencies, environments and trust boundaries; distinguishes inventory presence from current deployment and exposure; identifies endpoint, identity, network, DNS, cloud control plane, application, API, database, data access, security tool, supplier and physical signals according to risk; gives each source a purpose and owner; records event producer, collection path, schema, normalization, timestamp semantics, timezone, clock quality, correlation identifiers, retention, expected volume, latency, loss, access and integrity controls; avoids secrets and unnecessary content; protects logs from unauthorized change; monitors collector and source health; defines blind spots and degraded operation; links telemetry to specific threat and incident questions; and tests that representative safe activity reaches the expected detection and investigation path.

02

Detection hypotheses, triage, investigation, and evidence

Provide a noisy rule, several related identities, incomplete logs and a recent approved change. Ask for an investigation that keeps observation separate from conclusion.

Confirm: The person states the behavior or control failure a detection seeks rather than relying on a signature name; records scope, required sources, analytic logic, baseline, expected false positives, severity, confidence and escalation; distinguishes raw event, enriched event, alert, case and confirmed incident; deduplicates without erasing recurrence; validates source health before trusting absence; checks asset identity role geography time change and business context; pivots across independent endpoint identity network cloud application and data evidence; preserves original records, queries and collection time; builds a normalized timeline while retaining source timestamps; distinguishes observation, indicator, hypothesis, corroborated finding, alternative explanation and attribution; limits collection to the mandate; records missing or contradictory evidence; communicates confidence and potential impact; and closes or escalates with a reason that another analyst can reproduce.

03

Vulnerability, exposure, threat, and remediation analysis

Provide a scanner export, vendor advisory, base severity score, exploitation signal and incomplete deployment data. Ask what should actually happen next.

Confirm: The person confirms product, component, version, package, location and asset ownership; distinguishes installed from loaded, reachable, exposed and exploitable; validates scan identity and evidence; checks vendor status, configuration, compensating controls, privileges, attack path, data and operational consequence; uses CVE and weakness identifiers as references rather than local proof; separates CVSS Base, Threat, Environmental and Supplemental context; treats known exploitation and EPSS as distinct prioritization inputs rather than certainties; records source version and time; identifies affected population and inventory gaps; proposes update, configuration, isolation, monitoring, acceptance or replacement options with dependencies and side effects; assigns remediation and exception authority; verifies the deployed correction and control state; monitors for attempted exploitation where proportionate; and updates the asset, case and risk record instead of closing on ticket status alone.

04

Incident coordination, authorized response, recovery, and learning

Provide a suspected compromise, fragile service, customer impact, legal uncertainty and pressure to disconnect systems immediately. Ask for safe next actions and an evidence-preserving handoff.

Confirm: The person applies the organization's declaration and severity criteria; establishes incident command, scope, objectives, communication channels, roles and decision log; preserves volatile and durable evidence under the approved legal and privacy process; restricts access and uses an agreed information-sharing marking; identifies affected identities assets data dependencies and time window; proposes reversible containment options with operational and evidential tradeoffs; never changes production beyond authority; records actions actors times and observed effects; supports eradication and correction without confusing symptom removal with cause; verifies identity, configuration, vulnerability and persistence conditions; monitors for recurrence; confirms restoration, backlog, customer and control state with owners; distinguishes technical recovery from legal notification and public communication; records residual uncertainty; conducts a blameless evidence-led review; improves telemetry detections architecture access runbooks exercises and training; and demonstrates continuity before closing the incident.

Assessment sequence

Move from a defensive question to a response whose authority and evidence are clear.

Security analysis remains defensible when source health, observations, hypotheses, actions and decisions stay linked. Begin with mandate and protected outcome, not with the loudest alert.

  1. 01

    Define mandate, protected outcomes, and authority

    Identify in-scope assets identities data and services, monitoring and investigation purpose, escalation criteria, access, incident command, action limits, evidence handling and legal privacy communication owners.

  2. 02

    Map assets, sources, coverage, and blind spots

    Connect owned inventory and trust boundaries to telemetry purpose, schema, timestamps, integrity, retention, access, collection health and detection hypotheses; record what cannot currently be observed.

  3. 03

    Triage, investigate, and challenge the hypothesis

    Validate source health, enrich with asset identity change vulnerability and threat context, preserve evidence, correlate independent signals, test benign alternatives and state confidence and missing data.

  4. 04

    Coordinate authorized response and remediation

    Escalate through the agreed process, present containment monitoring repair or acceptance options and side effects, support owner-approved action, record decisions and protect operational and evidential state.

  5. 05

    Verify recovery, learn, and preserve continuity

    Confirm the deployed correction, restored service and control state, monitor recurrence, document residual uncertainty, improve telemetry detections runbooks and architecture, and prove a qualified handoff.

Defensive loops

Keep telemetry, investigation, response, and prevention connected.

A detection that never learns becomes noise. A response that does not change the defensive system leaves the next analyst with the same blind spot.

  1. 01

    Coverage and source-health loop

    Can the current telemetry answer the most important defensive questions within the required window?

    Working evidence: Owned assets and identities, protected outcomes, source purpose, schema, clocks, collection path, access, integrity, retention, latency, loss, test signal, blind spots, degraded mode and review trigger.

  2. 02

    Alert and investigation loop

    Does the evidence support the hypothesis, a benign explanation, or an escalation?

    Working evidence: Detection version, source health, raw events, enrichment, asset and identity context, normalized timeline, queries, corroboration, alternatives, confidence, missing data, disposition and reviewer.

  3. 03

    Vulnerability and remediation loop

    Is the identified condition present and consequential here, and was the chosen correction actually deployed?

    Working evidence: Asset, component, version, reachability, exposure, configuration, controls, threat and exploitation inputs, local impact, options, exception, owner, change evidence, verification and monitoring.

  4. 04

    Incident and learning loop

    Did response and recovery reduce harm and strengthen the next detection and decision?

    Working evidence: Declaration, command, scope, decision log, preserved evidence, actions, effects, containment, correction, recovery checks, residual uncertainty, review findings, assigned improvements and exercised follow-up.

Continuity controls

Recover without one analyst, one dashboard, or a timeline held in memory.

Defensive work remains in client-owned inventories, cases, queries, runbooks and decisions. Access can end without taking the operating memory with it.

Owned asset, identity, and telemetry map
Services, criticality, owners, assets, versions, identities, privileges, data, dependencies, trust boundaries, source purposes, schemas, clocks, collection health, retention, access and blind spots remain connected.
Versioned detections and investigation methods
Hypotheses, required sources, logic, baselines, severity, confidence, expected noise, test signals, triage paths, queries, evidence-preservation steps, escalation criteria and review triggers have owners.
Traceable case, vulnerability, and decision record
Raw evidence, hashes or integrity records where required, source and normalized time, queries, observations, alternatives, findings, asset context, response options, authority, actions, outcomes, residual risk and disclosure state remain linked.
Demonstrated handoff and safe access exit
Another qualified person can validate sources, reproduce analysis, use the runbooks, locate owners and continue open work; excessive access is removed; credentials rotate when required; and stale detections or records are retired deliberately.

Fit check

Use a security analyst when defensive questions need owned evidence and response paths.

Good reason to begin

  • Important services, assets, identities or data need clearer monitoring, investigation, vulnerability context, incident support or defensive learning, and accountable owners can define what matters.
  • The client can provide authorized least-privilege access, current asset and identity context, relevant telemetry, retention, known changes, vulnerability inputs, incident runbooks, recovery owners and safe assessment artifacts.
  • Engineering operations security privacy legal and business owners can act on findings, exercise response, improve instrumentation and accept explicit blind spots and residual risk.
  • The organization wants reproducible case evidence, proportionate escalation, verified remediation and continuity rather than a larger alert queue or an unsupported promise of round-the-clock protection.

Resolve before beginning

  • The requested outcome is a guarantee of security, complete detection, attribution, zero incidents, instant response or compliance based on a tool deployment, analyst title or monitoring dashboard.
  • There is no owned asset scope, incident authority, escalation path, legal privacy process, production action boundary or recovery owner, leaving analysis unable to lead to safe decisions.
  • The role depends on unrestricted production access, shared credentials, covert monitoring without authority, unnecessary collection of private content, evidence handling outside approved process or destructive response without rollback.
  • No team can correct logging gaps, repair vulnerabilities, tune noisy detections, exercise response, verify recovery or preserve analyst handoff, leaving findings to recur without an operating change.

Source basis

Sources behind the control model.

  • 01

    National Institute of Standards and Technology

    Cybersecurity Framework 2.0

    The final framework organizes cybersecurity outcomes across Govern, Identify, Protect, Detect, Respond and Recover and supports profiles for communicating current and target state. It does not prescribe one implementation or establish a client's risk posture.

  • 02

    National Institute of Standards and Technology

    Incident Response Recommendations, SP 800-61 Revision 3

    The 2025 final publication integrates incident response throughout CSF 2.0 risk management and covers preparation, detection, response, recovery and improvement. Organizational authority, legal duties and local procedures still need definition.

  • 03

    National Institute of Standards and Technology

    Information Security Continuous Monitoring, SP 800-137

    The final federal guidance connects asset, threat, vulnerability and control visibility with organizational risk tolerance and timely response. Its federal scope and 2011 publication date are explicit.

  • 04

    National Institute of Standards and Technology

    Guide to Enterprise Patch Management Planning, SP 800-40 Revision 4

    The final guide frames patching as preventive maintenance and covers identifying, prioritizing, acquiring, installing and verifying updates through an enterprise strategy. It does not turn every available patch into an immediate production action.

  • 05

    Cybersecurity and Infrastructure Security Agency

    Federal cybersecurity incident and vulnerability response playbooks

    CISA describes standardized federal incident and vulnerability response processes for identification, coordination, remediation, recovery and successful mitigation tracking. Federal requirements are explicit, while the broader process is useful as a bounded reference.

  • 06

    Cybersecurity and Infrastructure Security Agency

    Known Exploited Vulnerabilities Catalog

    The living catalog records vulnerabilities with evidence of active exploitation and is an input to prioritization. Presence or absence does not establish the client's affected version, reachability, exposure or complete risk.

  • 07

    Cybersecurity and Infrastructure Security Agency

    Cross-Sector Cybersecurity Performance Goals

    The voluntary critical-infrastructure baseline includes outcomes for log collection, protected log storage, incident planning and tested recovery across the CSF functions. It is a prioritized baseline, not complete fulfillment of a framework or local requirements.

  • 08

    UK National Cyber Security Centre

    Logging and monitoring

    The guidance connects proportionate logging and active monitoring with incident questions, source access, exercises and response planning and explicitly rejects one universal monitoring model.

  • 09

    UK National Cyber Security Centre

    Introduction to logging for security purposes

    The guidance starts from incident questions, source selection, event detail, timestamps, retention, access and protection against inappropriate modification. Logging remains sensitive infrastructure and not every available field should be collected.

  • 10

    UK National Cyber Security Centre

    Incident management

    The guidance calls for defined roles, authority, detection alignment, careful action, decision records, stakeholder communication, recovery and post-incident improvement. It also warns that overreaction can cause additional harm.

  • 11

    UK National Cyber Security Centre

    Technical response capabilities

    The guidance covers triage, containment, analysis, remediation and recovery plus available sources, searchable retention, time synchronization, provider logging and evidential capture. Legal-grade collection requires the applicable approved process.

  • 12

    UK National Cyber Security Centre

    Vulnerability management

    The guidance frames vulnerability management as continuing lifecycle work across assets, updates, exposure and response. Its recommendations do not establish that a product is affected or authorize an unsafe production change.

  • 13

    Forum of Incident Response and Security Teams

    CSIRT Services Framework Version 2.1

    The review-version framework organizes possible incident-management services and functions and states that no team is expected to provide every service. It supports explicit mandate and handoff without implying a standing Werkon CSIRT.

  • 14

    Forum of Incident Response and Security Teams

    CVSS Version 4.0 Consumer Implementation Guide

    The current guide explains how consumers add Threat and Environmental context to Base severity and warns that Base scores alone can mislead local prioritization. CVSS remains severity context, not a complete vulnerability program or business-risk decision.

  • 15

    Forum of Incident Response and Security Teams

    Exploit Prediction Scoring System

    EPSS estimates the probability that a published CVE will be exploited in the wild within a defined future window. A probability is a changing prioritization input, not proof of exploitation, safety or local exposure.

  • 16

    MITRE

    ATT&CK knowledge base

    ATT&CK organizes adversary tactics and techniques from real-world observations and includes data components, detection strategies and analytics. It can structure threat hypotheses but does not prove attribution or complete local coverage.

  • 17

    MITRE

    D3FEND knowledge graph

    D3FEND relates defensive techniques, digital artifacts and offensive techniques in a public knowledge graph. A relationship suggests analysis paths and countermeasure concepts, not an effective deployed control.

  • 18

    OpenTelemetry

    Logs data model

    The current specification defines a common model for event time, observed time, severity, body, resource, instrumentation scope, attributes, trace context and flags. Normalized fields support correlation but do not ensure source truth or collection completeness.

  • 19

    OWASP Foundation

    Logging Cheat Sheet

    The living guidance covers application event purpose, fields, confidence, exclusions, collection, verification, protection, monitoring and disposal and warns against both missing context and alarm fog. It is focused guidance, not a client logging policy.

  • 20

    OASIS Open

    STIX Version 2.1

    The OASIS Standard defines structured objects and relationships for representing cyber threat intelligence with markings, identities, indicators, sightings and versioning. Structured exchange does not make supplied intelligence accurate, authorized or relevant.

[ WORKFLOW / SYSTEMS AUDIT ]
THE FIRST ENGAGEMENT

Start with one real workflow

A Systems Audit is the usual starting point. If the opportunity is already clear, we can move directly into a focused build.

Show Us the WorkflowStart with the free automation readiness checklist

OBSERVEQUANTIFYDECIDEBUILD