Security Operations Analyst
Hours will vary during training: 40 hours per week for the first 2–3 months, with shifts from 8–4 or 9–5. After training, schedule shifts to 12-hour shifts (3 twelve-hour days followed by a 6-day break).
Description
The IT Security Analyst position supports security information, incident response, forensics, threat intelligence, and event monitoring functions utilizing Client's Security Information and Event Management (SIEM) tool, open-sourced tools, forensic tools, threat intelligence platform (TIP), Security Orchestration, Automation and Response (SOAR) platform, and big data solutions. This role focuses primarily on monitoring the events and logs from Client's Information Technology, Cyber Security and Physical Security data feeds and building out analytics based on adversarial behaviors. If activity is picked up through monitoring processes, this role requires the technical expertise to investigate the scenario appropriately. The ability to work independently as well as within groups is essential to this role. Sensitivity to accuracy, timeliness, and professionalism in all areas of support activity is imperative.
Responsibilities
- Perform daily monitoring and investigative activities while on shift either days or nights
- Assist with processing cases that require forensics to validate findings, produce threat intelligence, or fulfill an HR/Legal request
- Process different threat reports for value and potential content development, as well as keeping up with the current/relevant threat landscape
- Provide continuous feedback on opportunities to enhance current processes and content, assisting to implement those changes
- Assist with engineering data to enhance analytical capabilities based on structure, enrichments, and linking between other data sets
- Research new capabilities from both open and closed sourced technologies to find opportunities to enhance the Security Operation Center (SOC) ecosystem
- Provide documentation for cases and forensic reports
- Maintain current knowledge of relevant technology as assigned
- Assist with metrics, reporting, and other SOC communications
- Process and share information with other Client security teams
- Assist or lead projects designated by the SOC team
Qualifications
- Associates Degree in Computer Science, Information Security, or similar discipline is preferred with 0 to 2 years experience. Bachelor's Degree preferred
- An Associate degree in another field with 2 years relevant industry experience in cyber/information security will be considered
- In lieu of a degree, 2 years of related experience is required
- Related experience includes but is not limited to: SOC (Security Operations Center) experience, IT Security experience in detection, triage, investigation, and remediation of security incidents within a network
- Demonstrate strong communication skills, both verbal and written
- Demonstrate creative problem solving and solutioning
- Ability to work effectively, independently and within a team environment
- Ability to handle, protect and preserve highly confidential information
- Ability to learn independently and from others
- Ability to find answers effectively using open-sourced information
- Understanding of programming/scripting code (Python, PowerShell, Bash), to interpret its functionality
- Understanding of both Linux and Windows operating systems
- Understanding of networking concepts and technologies
- Understanding of adversarial techniques (i.e., MITRE ATT&CK framework)
- Basic understanding of statistics
- Must be organized and comfortable with ongoing changes in priorities
- Must be able to work independently with minimal supervision