We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled, inclusive culture and talent experience and our ability to be compelling to our clients. You’ll find an environment that inspires and empowers you to thrive both personally and professionally. There’s no one like you and that’s why there’s nowhere like RSM.
The Security Operations Analyst is responsible for detecting, investigating, and responding to cybersecurity threats and incidents across the organization’s systems, networks, cloud environments, and applications. This role helps protect enterprise assets by monitoring security controls, leading incident investigations, coordinating response activities, and driving continuous improvement of threat and vulnerability management programs.
The analyst applies structured analytical techniques to assess risk, identify emerging threats, and provide actionable recommendations to Information Technology and business leadership. The role also contributes to broader Information Security initiatives, including security architecture reviews, standards development, security automation, and operational maturity improvements.
Key Responsibilities
Security Monitoring and Incident Response
Monitor security events and alerts across enterprise technologies to identify malicious activity, security incidents, and control failures.
Investigate cybersecurity events and incidents, including malware infections, account compromise, insider threats, phishing attacks, unauthorized access attempts, and data security concerns.
Coordinate and facilitate incident response activities across technical and business teams.
Execute containment, eradication, and recovery activities during security incidents.
Perform root cause analysis and document lessons learned following incident resolution.
Maintain incident documentation, evidence collection, and reporting in accordance with organizational standards.
Threat Detection and Threat Management
Monitor for attempts to circumvent security controls by internal users, third parties, and external threat actors.
Conduct threat hunting activities using available telemetry, logs, and threat intelligence.
Manage and improve security detection capabilities within SIEM, EDR, and related security technologies.
Analyze threat intelligence and translate findings into actionable security improvements.
Maintain blacklist, watchlist, and detection management processes.
Vulnerability Management
Execute and continuously improve vulnerability management processes across infrastructure, applications, cloud environments, and emerging technologies.
Coordinate vulnerability assessments, penetration testing, secure code reviews, red team exercises, and remediation efforts.
Evaluate vulnerabilities for business risk and prioritize remediation activities.
Track remediation progress and communicate risk exposure to leadership and stakeholders.
Security Operations and Continuous Improvement
Analyze, evaluate, and test the effectiveness of existing security controls.
Assess security processes and identify opportunities for operational improvement and increased efficiency.
Apply structured analytical methodologies to incident investigations, threat analysis, and process optimization efforts.
Develop operational metrics, reporting, and dashboards to support risk-informed decision-making.
Support audit, compliance, and regulatory initiatives as required.
Security Strategy and Collaboration
Communicate security risks, control effectiveness, and incident trends to Information Technology leadership and business stakeholders.
Support security architecture reviews, technology evaluations, and project security assessments.
Contribute to the development and maintenance of security standards, policies, procedures, and playbooks.
Partner with infrastructure, cloud, application development, and business teams to strengthen the organization’s overall security posture.
Required Qualifications
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field, or an equivalent combination of education and experience.
Five or more years of experience in cybersecurity, security operations, incident response, or threat management.
Experience coordinating multidisciplinary teams during cybersecurity incidents.
Strong understanding of security principles across operating systems, applications, networking, cloud platforms, mobile technologies, endpoint security, and identity and access management.
Experience with SIEM, EDR/XDR, vulnerability management, and security monitoring technologies.
Strong analytical, communication, and problem-solving skills.
Ability to perform effectively under pressure and manage multiple priorities simultaneously.
Preferred Qualifications
Industry certifications such as CISSP, GCIH, GCFA, CISA, CEH, OSCP, or Security+.
Master’s degree in Cybersecurity, Information Security, Computer Science, or related discipline.
Experience managing or responding to significant cybersecurity incidents and enterprise-scale investigations.
Experience with business intelligence, reporting, and data analytics tools.
Experience with Python, PowerShell, or other automation and orchestration technologies.
Experience designing or supporting Security Orchestration, Automation, and Response (SOAR) solutions.
Knowledge of threat intelligence, digital forensics, cloud-native security, and modern detection engineering practices.
Experience applying artificial intelligence, machine learning, or neural network technologies to cybersecurity operations.
At RSM, we offer a competitive benefits and compensation package for all our people. We offer flexibility in your schedule, empowering you to balance life’s demands, while also maintaining your ability to serve clients. Learn more about our total rewards at https://rsmus.com/careers/working-at-rsm/benefits https://rsmus.com/careers/el-salvador.html.
RSM does not tolerate discrimination and/or harassment based on race; colour; creed; sincerely held religious beliefs, practices or observances; sex (including pregnancy or disabilities related to nursing); gender (including gender identity and/or gender expression); sexual orientation; HIV Status; national origin; ancestry; familial or marital status; age; physical or mental disability; citizenship; political affiliation; medical condition (including family and medical leave); domestic violence victim status; past, current or prospective service in the Salvadoran Military/Veteran status; pre-disposing genetic characteristics or any other characteristic protected under applicable provincial employment legislation.
Accommodation for applicants with disabilities is available upon request in connection with the recruitment process and/or employment/partnership. RSM is committed to providing equal opportunity and reasonable accommodation for people with disabilities. If you require a reasonable accommodation to complete an application, interview, or otherwise participate in the recruiting process, please send us an email at [email protected].
Skills Required
- Bachelor's degree or equivalent work experience
- 5+ years' security experience
- Ability to perform under pressure and handle multiple priorities
- Solid understanding of security applied to OS, applications, networking, cloud, mobile
- Experience organizing multidisciplinary groups and organizations through security incidents (incident response coordination)
- CISSP, CISA, GCIH, CEH, OSCP or similar certifications
- Master's degree in relevant field
- Experience handling significant cyber incidents
- Business Intelligence and Analytics
- Python or other methods to automate and orchestrate
- Applied Neural Network Solutions
- Applied skills in Security Orchestration and Automated Response
RSM US LLP Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about RSM US LLP and has not been reviewed or approved by RSM US LLP.
-
Parental & Family Support — Parental leave, caregiver leave, and family‑building assistance are standout strengths, including 12 weeks fully paid parental leave, six weeks paid family caregiver leave, up to $50,000 in fertility coverage, and up to $20,000 per child for adoption or surrogacy, plus backup care resources. These benefits create a family‑forward package that stands out within the firm’s total rewards.
-
Leave & Time Off Breadth — Time‑off options are broad, with self‑managed PTO for associates and above, at least 14 paid holidays, and firm‑wide wellbeing days alongside hybrid work flexibility. This breadth is consistently presented as a strong component of the overall offering.
-
Healthcare Strength — Medical coverage includes multiple plan designs (two HDHPs and a PPO), telehealth access, and a mental‑health platform offering up to eight free 1:1 sessions per year. Health benefits are characterized as solid to strong for the industry.
RSM US LLP Insights
What We Do
RSM is the leading provider of audit, tax and consulting services to the middle market. With over 11,000 employees across the U.S. and Canada and a global presence in 120 countries, our purpose is to deliver the power of being understood to our clients, colleagues and communities. As first-choice advisors, we are focused on developing leading professionals and innovative services to meet our clients’ evolving needs in today’s ever-changing business environment. Through a supportive, caring culture, our people are empowered to be their authentic selves and share their unique perspectives. Our culture of diversity and inclusion enhances the insights we provide while transforming innovation, collaboration and business results through fostering an inclusive environment, working hard to engage a talented workforce and reflect our diverse community, and developing relationships that serve others in business and the broader community. Together, our people’s individual talents and diverse perspectives strengthen our teams and enhances the unique insights that we provide to our clients. Through a supportive, caring culture, our people are empowered to be their authentic selves and share their unique perspectives. Our culture of diversity and inclusion enhances the insights we provide while transforming innovation, collaboration and business results through fostering an inclusive environment, working hard to engage a talented workforce and reflect our diverse community, and developing relationships that serve others in business and the broader community. Together, our people’s individual talents and diverse perspectives strengthen our teams and enhances the unique insights that we provide to our clients. For more information, visit rsmus.com.






