Cyber Security Analyst Cyber Security Analyst
The ideal candidate would have a working knowledge of current and relevant security technologies and how to apply them to cyber incident response actions.
A clear investigative methodology with a focus on preserving evidence and analyzing data to form conclusions that will steer response directions.
Experience responding to multi-faceted security events and incidents and assisting with the coordination of subsequent response efforts prioritizing mission critical elements.
The role involves regular interaction with various groups and leadership within the organization to accomplish job responsibilities.
Working closely with the Cyber Response Manager the Sr Incident Responder will manage workflows, escalations, and advance technical processes to build program maturity and growth.
The successful candidate will be responsible for participating in the following activities :
Day-to-day operational tasks related to the ongoing support of Threat Operations.
Responsible for triaging escalated security incidents and conducting response actions to detect, contain and remediate identified security incidents.
Responsible for overseeing ticket queue triage : prioritization, and escalations.
Responsible for analyzing threat data from multiple sources and identifying security alerts and events of importance for direct escalation to response.
Incident responders are expected to mitigate risk by taking response actions on either Accounts, Communications, Hosts, Files, Networks, or in some cases Handoffs to partner teams
Identify and analyze multiple log sources into a timeline to reach a conclusion
Incident Responders must keep detailed notes on all analysis activity, documented in the case management tool to validate process adherence.
Responsible for contributing to the strategic creation and updating of new and existing SOAR playbooks and runbooks and response process documentation.
On-Call for escalated events for 1 week on a 5-week rotation
Work alongside Incident Commanders and Incident Handlers to contain and remediate named incidents
Quals
Qualifications / Requirements :
Bachelor s Degree / Masters Degree in an IT related field and / or equivalent work experience
Minimum 5 years working in Cyber Defense with experience in Incident Response, Security Operations Center (SOC), detection engineering, or similar functions.
Previous experience supporting or leading incident response functions.
Experience using industry-standard security toolsets in a layered defense model
Working knowledge of core Enterprise IT concepts (web application architectures, networking, etc.)
Experience with host-based and network-based forensics tools and analysis
Knowledge of the cyber threat landscape to include different types of adversaries, campaigns, and the motivations that drive them
Knowledge of industry recognized security and analysis frameworks (Mitre Telecommunication&CK, Kill Chain, Diamond Model, NIST Incident Response, etc.)
Exceptional written and verbal communication skills
Must be self-motivated and able to work both independently and as part of a team
Strong communication (both verbal and written) and client intimacy skills with experience briefing corporate executives and professionals
Ability to be on call and provide support during nontraditional working hours
Desired : - Degree in Computer Science, or equivalent experience - Security Operations Center experience preferred. - Customer service experience, working with users over the phone, via email, and in person.
- Self-motivated with the ability to work independently. - Splunk or other SIEM experience creating alerts, reports, dashboards, etc.
Related Jobs
Cyber Security Analyst Cyber Security Analyst
Security Officer - Security D License Required
Security Guard
Security Guard