Responding to cyber security alerts within defined SLAs
Contributing to key initiatives to enhance the Cyber Security Operations team’s maturity and operational capabilities
Adhering to cyber security processes, procedures and other documentation while performing incident response duties
Assisting with development of documentation regarding how to perform specific incident response tasks
Analyzing security system logs, security tools, and available data sources to identify attacks against the enterprise and report on any irregularities, issues related to improper access patterns, trending, and event correlations and make suggestions for detection development and system tuning
Assisting in identifying monitoring/detection gaps and helping to drive them toward resolution
Escalating cyber security incidents to incident response analysts when appropriate
Identifying and actioning incident trends observed during triage and response activities
Assisting with the development, maintenance of, and training on technical documentation and Standard Operating Procedures (SOP)
Assisting with cyber security awareness and education initiatives, as needed
Operating in a global on-call rotation and being available to respond outside of normal business hours, if necessary
Requirements
Basic understanding of system logging and auditing concepts
Basic understanding of security controls (i.e. anti-virus, EDR, IPS/IDS) and their capabilities
Ability to author original technical documentation
Working knowledge of diverse operating systems, networking protocols, systems administration, and security technologies
Familiarity with cyber security terminology and concepts, and basic understanding of the cyber threat landscape and attack vectors
Capability to learn new concepts and processes quickly, and adapt to a constantly changing environment
Demonstrated critical thinking, problem solving, and analytical skills with the ability to de-construct complex concepts
Ability to successfully interact with non-technical personnel
Ability to analyze and understand technical information
Ability to work independently with minimal direction for day-to-day activities
Minimum of 6 years of IT experience with 4 years in a specialized information security role
Bachelor’s Degree in computer science or related technical field and 4 years of IT experience
Bachelor’s Degree in computer science or related technical field and 3 years of specialized information security experience
Master’s Degree in computer science or related technical field and 2 years of specialized information security experience