The Role
The Cyber Threat Security Analyst role will focus on security event and incident monitoring, threat hunting, and deep analysis of threat information within SIEM environments, various log sources, and within security control technologies directly.
The Security Analyst will work directly with customers to determine and communicate relevant risk and potential impact, as well as make recommendations for risk mitigation.
This role will also provide direction for SIEM rule changes, customer escalations and inquiries, and help develop improved threat analysis process and procedures.
The Cyber Threat Security Analyst role is expected to participate in a shift schedule and on-call rotation to accommodate a global 24x7x365 Managed Threat Security Services program.
The Main Responsibilities
Perform security incident and event monitoring support, including deep dive data analysis and responseDevelop and manage customer security event analysis notifications with thoughtful analysis details, evidence, conclusions, and recommendationsRespond and manage customer issues and questions regarding security events, including evidence supporting risk identification and recommended risk mitigation, via trouble ticket, email, and phoneReview threat detection rules and correlations, and make recommendations for improved fidelityWhat We Look For in a Candidate
Qualifications & Skills:
Required
Requires Bachelor’s degree in related field or equivalent combination of education and experience.Possess strong customer service skillsCommunicate effectively with managers, customers and vendorsMaintain solid working relationships, including collaborative technical activities with peersGood written and verbal communication skills Good analytical and problem-solving skillsAttention to detail with good organizational skillsBasic experience performing security monitoring, hunting, and analysis within SIEM platforms and security controlsPreferred
1 or more years in a Security Operations environment performing cyber threat hunting and incident response supportSecurity industry certifications (examples):GIACCISSPCRISCCISMSecurity+CCNACEHBasic knowledge and skills of at least one programming language (python preferred)Compensation