Padmi

IT Security Analyst III

Remote · United StatesPosted 59 months ago
CybersecurityUnspecified
Apply at MSR Technology Group

Opens the source posting on hire.myavionte.com

Source description

About the role

View original

Shift Responsibilities: The Security Analyst is responsible for the following shift duties: • Daily Traffic Review – replaying traffic from previous shifts and reviewing customer reports to ensure potential security incidents were not missed by a Level 1 Analyst • Report Run Verification – ensure customer reports run as scheduled • Improve their knowledge of the customer environment, intrusion detection, methodologies, and intrusion detection services with the support of on-going training from the analysts and self-study • Review SOC Activity log, cases and other monitoring tools for complete understanding of previous shift activities and incidents • Handle Tier 2 event incident response, case management, and customer notification • Ensure security devices contain up-to-date signatures libraries • Assist with engineering tasks as necessary • Train SOC Level 1 Analysts on new attack signatures and attack methodologies • Providing process and operational improvement suggestions • Review and update documentation (such as SOPs and TTPs) • Complete vendor training as requested by Management • Daily Case Management – the Security Analyst will review open cases and provide follow up that may be required

Qualifications

• Must be U.S. citizen • 5+ years of Information Security experience • Expertise experience in Splunk preferred • Strong understanding of security principles such as attack frameworks, threat landscapes, attacker TTPs, etc. • Working experience with integration with different security systems and devices • 3+ years coding and scripting experience in Python, Linux shell scripting or Windows PowerShell scripting etc. • Working experience and knowledge of SOAR platforms and solutions • 2-4 years of systems analysis • Working knowledge of Linux and syslog from CLI • Proven ability and past experience performing moderately complex security analysis for information technology is required • Excellent writing and communications skills • Familiarization with a variety of information and network security monitoring tools (ArcSight SIEM, QRadar SIEM, Splunk, Arbor DDoS Mitigation, Cisco IDS/IPS, Netcool, and Imperva WAF, among others) • Ability to work in a dynamic team-centered environment

Education Preferred: • Bachelor’s Degree in Computer Information Systems or related field

Industry Certifications: All Analysts should possess the background and experience necessary to obtain Industry or SOC specific certifications as instructed by management. Possible applicable certifications include, but are not limited to: • Certified Information Systems Security Professional (CISSP) • Information Systems Security Engineering Professional (CISSP-ISSEP) • Systems Security Certified Practitioner (SSCP) • CompTIA Security+ • Certified Ethical Hacker (CEH) • Certified Security Analyst (ECSA) • Certified Incident Handler (ECIH) • CompTIA Cybersecurity Analyst (CSA+) • Information Technology Infrastructure Library (ITIL) • Cisco CCNA • Cisco CCNP + Security • GSEC • GCIH • GCIA • MCSE • Linux+

Work Experience: • 2-3 years of Managed Security Service Provider (preferred) • 3-4 years of senior SOC analyst experience • Threat Intelligence or Forensic background is a plus {"@context":"http://schema.org","@type":"JobPosting","baseSalary":null,"datePosted":"2021-11-01","validThrough":"2022-11-01","description":"Shift Responsibilities:

The Security Analyst is responsible for the following shift duties:

• Daily Traffic Review – replaying traffic from previous shifts and reviewing customer reports to ensure potential security incidents were not missed by a Level 1 Analyst • Report Run Verification – ensure customer reports run as scheduled • Improve their knowledge of the customer environment, intrusion detection, methodologies, and intrusion detection services with the support of on-going training from the analysts and self-study • Review SOC Activity log, cases and other monitoring tools for complete understanding of previous shift activities and incidents • Handle Tier 2 event incident response, case management, and customer notification • Ensure security devices contain up-to-date signatures libraries • Assist with engineering tasks as necessary • Train SOC Level 1 Analysts on new attack signatures and attack methodologies • Providing process and operational improvement suggestions • Review and update documentation (such as SOPs and TTPs) • Complete vendor training as requested by Management • Daily Case Management – the Security Analyst will review open cases and provide follow up that may be required

Qualifications

• Must be U.S. citizen • 5+ years of Information Security experience • Expertise experience in Splunk preferred • Strong understanding of security principles such as attack frameworks, threat landscapes, attacker TTPs, etc. • Working experience with integration with different security systems and devices • 3+ years coding and scripting experience in Python, Linux shell scripting or Windows PowerShell scripting etc. • Working experience and knowledge of SOAR platforms and solutions • 2-4 years of systems analysis • Working knowledge of Linux and syslog from CLI • Proven ability and past experience performing moderately complex security analysis for information technology is required • Excellent writing and communications skills • Familiarization with a variety of information and network security monitoring tools (ArcSight SIEM, QRadar SIEM, Splunk, Arbor DDoS Mitigation, Cisco IDS/IPS, Netcool, and Imperva WAF, among others) • Ability to work in a dynamic team-centered environment

Education Preferred: • Bachelor’s Degree in Computer Information Systems or related field

Industry Certifications: All Analysts should possess the background and experience necessary to obtain Industry or SOC specific certifications as instructed by management. Possible applicable certifications include, but are not limited to: • Certified Information Systems Security Professional (CISSP) • Information Systems Security Engineering Professional (CISSP-ISSEP) • Systems Security Certified Practitioner (SSCP) • CompTIA Security+ • Certified Ethical Hacker (CEH) • Certified Security Analyst (ECSA) • Certified Incident Handler (ECIH) • CompTIA Cybersecurity Analyst (CSA+) • Information Technology Infrastructure Library (ITIL) • Cisco CCNA • Cisco CCNP + Security • GSEC • GCIH • GCIA • MCSE • Linux+

Work Experience: • 2-3 years of Managed Security Service Provider (preferred) • 3-4 years of senior SOC analyst experience • Threat Intelligence or Forensic background is a plus

","employmentType":"CONTRACTOR","hiringOrganization":{"@type":"Organization","name":"MSRT"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","streetAddress":null,"addressLocality":"Remote","addressRegion":"SC","postalCode":"66212","addressCountry":null}},"title":"IT Security Analyst III","url":"https://www.msrtechnologies.com/careers/?cjobid=&rpid=548863&postid=lJvS3MYu4Io","identifier":{"@type":"PropertyValue","name":"MSRT","value":"MK255630111"}}

One address, no account. We’ll tell you when matching roles go live.

More at MSR Technology Group

Related open roles

View all roles