Senior Detection & Response Analyst
Toyota Tsusho Systems US, Inc. · Plano, TX · Yesterday
RemoteRemoteOTHRFull-time
About the role
The Senior Detection and Response Analyst role provides ongoing support to the Regional Security Operations program. This role involves maintaining effective 24x7 monitoring and detection services for both internal and external clients.
Essential Functions
- Act as the point of escalation for all security incidents; provide expert level feedback regarding current monitoring and ways to improve it
- Assume the role of shift lead as needed, and fulfill this responsibility through leadership and guidance of ID team members, proactively prioritizing, identifying, analyzing and remediating threats
- Maintain an understanding of the overall threat landscape (cyber, malware, botnets, phishing, DDoS, physical)
- Triage security incidents and perform in-depth analysis using Cyber Threat Intelligence, intrusion detection systems, firewalls and other boundary protection devices
- Maintain 24x7 coverage to support the RSOC services; participate in an on-call rotation
- Support Agentic SOC development through providing expert level feedback, tuning, and feature requests for our engineering team to support accurate machine speed response
- Train and mentor team members within the Incident Detection Team
- Improve the effectiveness and efficiency of day-to-day operations
- Contribute to the creation of documentation to standardize processes and procedures, including playbooks to improve internal processes and procedures
- Use investigation findings to identify gaps and recommend security posture improvements
- Identify, recommend, coordinate, and deliver timely knowledge to support teams
Requirements
- 4+ years of experience in Security Operations monitoring
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (preferred)
- Experience with Security Operations processes, procedures, and services
- Experience working with cyber security tools and software such as Sentinel, Splunk, ATP, Symantec End Point, TrendMicro Antivirus, McAfee Web Gateway, Checkpoint Firewalls, Bluecoat, Sourcefire, Active Directory, or relevant cyber security assets
- Advanced knowledge of network monitoring and network exploitation techniques
- Strong technical background in security, network, infrastructure, cloud, applications
- Knowledge of risk assessment tools, technologies and methods
- Experience with common attack vectors, including advanced adversaries (nation state/financial motivation)
- Knowledge around common web application attacks including SQL injection, cross-site scripting, invalid inputs, and forceful browsing
- Experience working with cyber security tools and software such as Splunk, ATP, Symantec Endpoint, TrendMicro Antivirus, McAfee Web Gateway, Checkpoint Firewalls, Bluecoat, Sourcefire, Active Directory, or relevant cyber security assets
- Technical certifications such as GCIA, GCFA, GCIH or CASP is a plus
- Tines (or other automation) experience is highly valued
- Proficient with Microsoft Office & documentation skills (Word, Excel, PowerPoint)