You will be responsible for security event detection, analysis, and containment across critical systems.
Responsibilities
- Respond to SOC alerts, performing analysis and containment of security events.
- Support the Cyber Incident Response Team (CIRT) in attack detection, analysis, and containment.
- Operate configuration management and File Integrity Management programs to track and correct deviations from baseline.
- Collect and analyze threat intelligence data, creating intelligence products mapped to MITRE ATT&CK Framework.
- Design, test, and develop content and alerting for critical asset threat identification, and document response playbooks.
Required Skills
- Three years minimum working in cyber threat or information security.
- Familiarity with compliance regulations: SOX, PCI-DSS, GLBA, and Federal Banking regulations.
- Proficiency with cloud security and incident response capabilities in Azure.
- Proficiency with configuration management scanning tools.
- Knowledgeable with Tripwire or similar file integrity management tools.
- Understanding of security technologies: IDS/IPS, firewalls, AV, proxies, EDR.
- Understanding of scripting languages like JavaScript or Perl.
- Ability to map threats and vulnerabilities to MITRE; familiar with STRIDE and OSI model.
- Good social, communication, and technical writing skills.