{"id":256,"date":"2025-02-10T01:07:12","date_gmt":"2025-02-10T01:07:12","guid":{"rendered":"https:\/\/wp.odu.edu\/cyberimpact-template\/?page_id=256"},"modified":"2026-08-18T03:22:31","modified_gmt":"2026-08-18T03:22:31","slug":"ids-493","status":"publish","type":"page","link":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/ids-493\/","title":{"rendered":"IDS 493"},"content":{"rendered":"\n<p>This is an essay I wrote for IDS 493. The assignment was very interesting. I had no idea people analyzed job posting like this. Enjoy the read.<\/p>\n\n\n\n<p><strong>Between the Lines:\u00a0<\/strong><\/p>\n\n\n\n<p><strong>An Analysis of a Security Analyst<\/strong> <strong>Job Advertisement at Aptos Foundation<\/strong><\/p>\n\n\n\n<p>Kenneth Thomas<\/p>\n\n\n\n<p>Old Dominion University<\/p>\n\n\n\n<p>IDS 493 Dr. Phan  Jul 19 2026<\/p>\n\n\n\n<p>Abstract<\/p>\n\n\n\n<p>This paper breaks down a Security Analyst job posting from Aptos Foundation (a blockchain org) to show how its phrasing, and unstated expectations reveal what the company actually wants out of the role. Let\u2019s be honest. Cyber security roles and their names are all over the place. And rarely encompass all aspects of the role. Using Harper\u2019s (2012) framework for analyzing job ads as primary data, I argue that Aptos is looking for someone who balances technical security knowledge with independent judgment and solid written communication traits that are implied through repetitive tasks rather than listed outright as hard requirements. I connect these expectations (like access governance, phishing response, and cross-team communication) back to my own cybersecurity coursework and certifications at&nbsp; ODU, including CompTIA Security+, GIAC GFACT, and GSEC. Ultimately, looking at a job posting critically instead of treating it like a checklist gives a much clearer picture of both the daily work and the company culture.<\/p>\n\n\n\n<p>Between the Lines: Analysis of a Security Analyst Job Advertisement at Aptos Foundation<\/p>\n\n\n\n<p>&#8220;Reading between the lines&#8221; is advice every entry-level job seeker gets, but almost nobody actually teaches you how to do it. When a company like Aptos Foundation posts a Security Analyst opening, the text is doing a lot more work than just listing tasks: it defines what the company thinks security work looks like, signals what traits it actually cares about, and reveals a lot about its internal culture. As Harper (2012) pointed out in a methodological review of job ad research, postings aren&#8217;t just objective, neutral descriptions of a job; they reflect &#8220;ideal values&#8221; and what the company \u201cwants\u201d to be rather than a purely objective account of day-to-day operations (p. 31). Treating a job posting like a text to analyze rather than just a checklist to match your resume against is a very useful exercise for anyone trying to break into cybersecurity. This paper analyzes the Security Analyst posting at Aptos Foundation (a blockchain organization built on tech originally created for the Diem project) and argues that its language points to a hybrid role rewarding both technical fluency and independent judgment qualities that line up directly with the classes and certs I&#8217;ve completed in the cybersecurity program at&nbsp; ODU.<\/p>\n\n\n\n<p>Aptos Foundation describes itself as a &#8220;people-first blockchain&#8221; focused on giving people fair, scalable access to decentralized assets (Aptos Foundation, 2026). The Security Analyst role fits into this mission at the operational level. The ad notes that the role will &#8220;support core security workflows spanning phishing response, bug bounty operations, access governance, and operational security hygiene&#8221; while reporting directly to a Security Lead (Aptos Foundation, 2026). Interestingly, the job doesn&#8217;t use a tiered title like &#8220;Security Analyst II,&#8221; and it explicitly frames the position as &#8220;ideal for someone looking to develop a wide view of security in a fast-moving organization&#8221; (Aptos Foundation, 2026). That phrasing, paired with a low experience requirement (just two years), shows this posting is aimed at an early-career analyst rather than a seasoned specialist. That makes it a really practical target for someone transitioning out of college into a mid-level analyst role.<\/p>\n\n\n\n<p>The way the requirements are ordered shows a clear hierarchy of what Aptos cares about most. The top priority is &#8220;2+ years of experience in a security-focused role, such as security operations, IAM, application security support, operational security, or a similar domain,&#8221; followed by &#8220;familiarity with core security concepts including phishing, authentication, access control, least privilege, and common vulnerability classes&#8221; (Aptos Foundation, 2026). The ordering here matters. By placing broad experience above specific technical terminology, Aptos signals that they care less about mastery over a single proprietary tool and more about whether you&#8217;ve actually spent time in a SOC environment and understand how security operations flow. This matches the responsibilities section, which mixes hands-on technical work (like triaging phishing alerts with tools like Sublime and Doppel) with heavy coordination duties, such as handling &#8220;communication with researchers, issue tracking, reporting, and internal follow-up&#8221; for their bug bounty program (Aptos Foundation, 2026).<\/p>\n\n\n\n<p>Soft skills are built into almost every section of the ad, though they&#8217;re rarely called &#8220;soft skills&#8221; outright which is a classic pattern in job descriptions. The requirement for &#8220;clear written communication and confidence coordinating across technical and non-technical stakeholders&#8221; is the only place communication is explicitly mentioned, but tasks involving documentation, reporting, and tracking fixes show up at least four separate times. Looking at that repetition, it&#8217;s clear that written communication isn&#8217;t just an added bonus it&#8217;s a core requirement for keeping the job. Time management is another one: it&#8217;s never explicitly named, but asking someone to &#8220;manage multiple concurrent workflows with strong attention to detail and reliable follow-through&#8221; is literally just describing time management. Harper (2012) notes that job postings are often affected by &#8220;uncontrollable variables&#8221; depending on how well the recruiter actually wrote the ad (p. 30). The recruiter might not have thought to label these traits as &#8220;soft skills,&#8221; but for a student analyzing the text, the takeaway is the same: the skill is essential, even without the label.<\/p>\n\n\n\n<p>The tone and structure of the posting also say a lot about the culture at Aptos. The company references its Ohlone-derived name (meaning &#8220;The People&#8221;) and frames its mission around fairness and accessibility rather than raw financial metrics. The benefits section highlights full health coverage and &#8220;protocol token grants,&#8221; and the listing emphasizes a &#8220;remote-first environment with minimal supervision.&#8221; Put together, this points to a workplace culture that values autonomy and trusts people to manage their own workloads. For a fresh graduate, that sounds great because it means actual ownership over your work, but it also comes with a hidden challenge. If you need step-by-step handholding or a very rigid onboarding program, you&#8217;re probably going to struggle. The real hurdle here isn&#8217;t necessarily technical it&#8217;s learning how to navigate an environment where processes are still being built while communicating across both technical and non-technical teams.<\/p>\n\n\n\n<p>There are also two unstated expectations worth calling out. First, basic scripting or automation skills are strongly implied under the &#8220;Nice to Have&#8221; section, which mentions &#8220;automating operational workflows using LLMs or AI tooling.&#8221; That tells me Aptos is already looking to automate repetitive task work like access reviews and alert management, even if they don&#8217;t explicitly require a specific programming language like Python. Second, the heavy emphasis on a &#8220;fast-moving organization&#8221; paired with a broad salary band reflects a reality of the market: web3 and blockchain security are moving so fast that companies prefer hiring adaptable generalists and training them up, rather than waiting months for a candidate who meets every single bullet point.<\/p>\n\n\n\n<p>My own academic background maps onto these expectations pretty closely. My coursework at ODU in cryptography specifically hands-on work with key exchange protocols like Diffie-Hellman and ElGamal encryption gives me a solid foundation in the authentication and access control concepts the ad mentions. My CompTIA Security+ certification covers the exact core concepts listed (phishing, authentication, least privilege), while my GIAC GFACT and GSEC certs reflect the broad, operations-focused background that Aptos prioritizes over hyper-specialized knowledge. Where I still need to grow is in their &#8220;nice to have&#8221; list, particularly practical experience with bug bounty triage and SaaS access reviews, which gives me a clear idea of what lab environments or internship tasks I should focus on before applying.<\/p>\n\n\n\n<p>At the end of the day, this job posting rewards candidates who take its coordination and communication requirements just as seriously as its technical skills. Aptos isn&#8217;t just looking for someone who knows what a phishing attack is; they need someone who can triage it, document it, explain it to non-technical staff, and close the ticket with minimal supervision. Analyzing the posting through this lens rather than viewing it as a flat list of requirements is what Harper (2012) calls reading for the &#8220;reality as it is perceived by the writers&#8221; (p. 31), and it&#8217;s an approach I plan to use for every job application moving forward.<\/p>\n\n\n\n<p>References<\/p>\n\n\n\n<ul>\n<li>&nbsp;Aptos Foundation. (2026). *Security Analyst*. Indeed \u2013 https:\/\/www.indeed.com\/viewjob?jk=1a83a611e839db23&amp;from=shareddesktop.<\/li>\n\n\n\n<li>Harper, R. (2012). The collection and analysis of job advertisements: A review of research methodology. *Library and Information Research*, 36(112), 29\u201354.<\/li>\n<\/ul>\n\n\n\n<h1 class=\"wp-block-heading\"><\/h1>\n","protected":false},"excerpt":{"rendered":"<p>This is an essay I wrote for IDS 493. The assignment was very interesting. I had no idea people analyzed job posting like this. Enjoy the read. Between the Lines:\u00a0 An Analysis of a Security Analyst Job Advertisement at Aptos Foundation Kenneth Thomas Old Dominion University IDS 493 Dr. Phan Jul 19 2026 Abstract This&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/ids-493\/\">Read More<\/a><\/div>\n","protected":false},"author":30543,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/pages\/256"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/users\/30543"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/comments?post=256"}],"version-history":[{"count":5,"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/pages\/256\/revisions"}],"predecessor-version":[{"id":321,"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/pages\/256\/revisions\/321"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/kenneththomas100-\/wp-json\/wp\/v2\/media?parent=256"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}