Experience - 4+ yrs
Short joiners preferred
Responsibilities
- Ability to apply thorough and methodical assessment skills to analyze and properly triage reported events and incidents
- Possess excellent and thorough communication and documentation skills
- Ability to work collaboratively in a team of professionals sharing workload and investigation assignments in a fast-paced environment
- Ability and willingness to provide (when necessary) afterhours (night and weekend) support for security related incidents as needed
- Maintain skills through annual and ongoing training and certification
- Performs analysis to determine scope, risk, and impact of security events leveraging the MITRE ATT&CK framework and other best practices
- Identifies supporting information for events including attack vectors, effected resources, effected profiles, and other supporting evidence
- Properly and thoroughly document event findings, evidence, analysis steps, and create after action reports and recommendations if needed
- Identifies and applies mitigation controls (where possible) to remediate alerts
- Engages appropriate levels of management to provide updates to any ongoing security issues
- Provides updates to team guidance and other central documentation
Required Skills
4+ years hands-on experience with cybersecurity platforms including Data Loss Prevention (DLP), Endpoint Detection and Response (EDR), antivirus (AV), Identity and Access Management (IDAM), Security Information and Event Monitoring (SIEM), and Security Orchestration and Automation (SOAR) platforms
Related work or educational experience in Information Technology (IT), particularly in cybersecurity / information security