Source description
About the role
Perform the detailed and repeatable execution of all operational tasks as documented in SOC processes and subordinate procedures. Monitor the SOC Triage Channel for security events. Close or escalate security events as necessary. Update all relevant documentation such as shift logs and tickets. Identify the impact of incidents on systems, and using available tools determine if data was exfiltrated. Document and maintain a knowledge base of alarms (false positives and false negatives, blacklists, whitelists) that IDS and IPS encounter. Perform Triage and investigations on DLP alerts. Serve as work area experts for security/information assurance policy recommendations. Gather intelligence from sources outside the SOC (both internal and external sources) and leverage for operations. Escalate incidents to applicable entities for remediation. Build relationships with other business units to strengthen security posture throughout the organization. Ensure security events and incidents are detected and escalated in a timely manner. Provide analysis and investigation to determine if alerts or security events warrant incident classification. Work under supervision. Travel and/or relocation to unanticipated client sites throughout USA is required.
More at NGTalentTech Group