Cybersecurity Operations Analyst Ii
hace 1 semana
Purpose Statement: The Security Operations Analyst uses advanced network and host-based tools to search through datasets to detect and respond to imminent and potential threats that evade traditional security solutions. The Security Operations Analyst is responsible for day-to-day security threat monitoring, analysis, and response. Responsible for managing security incidents and reviewing security alerts, known or suspected security threats, as part of the incident response lifecycle. The Security Operations Analyst is focused on adhering to threat intelligence gathering and integration, forensics, incident response, & vulnerability management best practices.
Key Job Accountabilities:
- Conduct operational monitoring and investigate incidents using SIEM and UEBA technologies, packet captures, reports, data visualization, and pattern analysis. Perform real-time alert monitoring and risk mitigation.
- Serve as an escalation point for other analysts during the course of advanced incident investigation and provide Incident Response (IR) support when analysis confirms actionable incident.
- Use logs & forensic data to develop timeline for an incident to understand what happened in detail.
- Investigate, document, and report on information security issues and emerging trends.
- Provide intermediate-level event analysis, incident detection, and guidance on response action plans for events and incidents. Support the analysis of the results of a wide range of threat detection and incident response platforms.
- Leverage threat intelligence (to include Open-Source Intelligence (OSINT)) to identify and search for new malicious Indicators of Compromise (IOCs).
- Leverage security tool stack to implement new or enhanced threat detection logic, signatures, and/or IOCs.
- Leverage variety of security tools and offensive security techniques to assist in the planning & executing of ethical penetration tests for the evaluation of cybersecurity risk.
Additional Accountabilities:
- Maintain knowledge of cybersecurity best practices and emerging technology, including frameworks and regulations & current threat trends.
- Provide threat and vulnerability analysis as well as security advisory services. Analyze and respond to previously undisclosed software and hardware vulnerabilities.
- Develop and implement appropriate security operations documentation, including runbooks, playbooks, and procedures.
- Creation of operational dashboards and will regularly report key performance indicators and metrics.
- Collect and analyze artifacts including malicious executables, scripts, documents, and packet captures.
- Exhibit strong critical thinking and problem solving skills with sound judgement.
- Maintain or develop professional contacts within the various communities in support of operations.
- Configuration & sustainment of data sources; fine tuning of alerts to enable operational monitoring.
- Additional duties as required.
Education/Experience Qualifications:
- A minimum of a _Bachelor’s degree_ is required; a _Bachelor’s degree in IT or cybersecurity related field_ is preferred.
- _ 3-5 years_ or more years of related experience is required.
An equivalent combination of education, certifications, or experience sufficient to successfully perform the key job accountabilities may be considered.
Other Qualifications:
- Experience analyzing possible attack activities such as network probing/ scanning, DDOS, malicious code activity and possible abnormal activities, such as worms, Trojans, viruses, etc.
- Foundational knowledge of advanced cyber threats, threat vectors, attacker methodology to include, tools, tactics, and procedures and how they tie into the Cyber Kill Chain or ATT&CK framework.
- Experience with premium threat intelligence tooling and/or open source intelligence techniques.
- In depth
- hands on experience with technical security solutions (firewalls, SIEM, NIDS/NIPS/HIDS/HIPS, AV, DLP, proxies, network behavioral analytics, endpoint, and cloud security).
- GCIA, GCIH, GCFE, GCFA, OSCP, GPEN, or CEH not required, but is preferred
Work Environment:
- The work setting should consist of an office environment with suitable lighting, comfortable temperatures, and a low noise level.
- This document does not represent a contract of employment and is not intended to capture every possible assignment the incumbent could be asked to perform._
-
Cybersecurity Operations Analyst I
hace 4 semanas
Guadalajara, México Plexus A tiempo completoPurpose Statement:The Cybersecurity Operations Analyst supports Plexus’ overall cybersecurity strategy by defining and implementing access management controls, concepts, and best practices to reduce cybersecurity risk while collaborating with global teams to enable strategic business initiatives. The Cybersecurity Operations Analyst supports the...
-
Cybersecurity Analyst I
hace 2 semanas
Guadalajara, México Plexus A tiempo completo**Purpose Statement**:The Cybersecurity Analyst is responsible for daily monitoring and response of cybersecurity events and customer support. This role will collaborate with others to detect and respond to cybersecurity incidents, while maintaining and following procedures for cybersecurity monitoring and incident response escalation. Additionally, this...
-
Cybersecurity Analyst I
hace 5 días
Guadalajara, México Plexus A tiempo completoPurpose Statement: The Cybersecurity Analyst is responsible for daily monitoring and response of cybersecurity events and customer support. This role will collaborate with others to detect and respond to cybersecurity incidents, while maintaining and following procedures for cybersecurity monitoring and incident response escalation Additionally, this role...
-
Cybersecurity Awareness Analyst
hace 2 semanas
Guadalajara, México Finastra A tiempo completo**Who are we?**:**What will you contribute?**We are evolving the Human Risk Management program, and this role is central to that transformation. As a Cybersecurity Awareness Analyst, you will ensure the smooth execution of phishing simulations, manage awareness platforms, and support initiatives that strengthen security culture across the organization.This...
-
Operations Analyst
hace 1 semana
Guadalajara, Jalisco, México Aspiria A tiempo completoAspiria es una Institución Financiera Digital que ayuda a incrementar el acceso a capital a los negocios de México a través de su plataforma en línea. Nosotros buscamos como hacer llegar el capital de manera sencilla y rápida a los negocios mexicanos, los cuales son el motor de la economía. Aspiria te invita a formar parte de su equipo de trabajo como:...
-
SOC Analyst
hace 1 semana
Guadalajara, México Valce Talent Solutions A tiempo completoThe SOC Analyst is responsible for monitoring, analyzing, and responding to security events across the organization’s technology environment. This role operates as the first line of defense, ensuring early detection of threats and proper escalation of incidents based on established procedures.The position involves continuous monitoring of security alerts...
-
SOC Analyst
hace 3 días
Guadalajara, México Valce Talent Solutions A tiempo completoThe SOC Analyst is responsible for monitoring, analyzing, and responding to security events across the organization’s technology environment. This role operates as the first line of defense, ensuring early detection of threats and proper escalation of incidents based on established procedures.The position involves continuous monitoring of security alerts...
-
CyberSecurity Intern
hace 4 días
Guadalajara, Jalisco, México Avertium A tiempo completoAvertium is a cyber fusion and MXDR leader, delivering comprehensive security and compliance services to mid-market and enterprise customers. Our unique "Assess, Design, Protect" methodology addresses and improves security strategy, reduces attack surface risk, strengthens compliance, and provides continuous threat protection. Avertium maximizes customer...
-
CyberSecurity Intern
hace 5 días
Guadalajara, Jalisco, México Avertium A tiempo completoAvertium is a cyber fusion and MXDR leader, delivering comprehensive security and compliance services to mid-market and enterprise customers. Our unique "Assess, Design, Protect" methodology addresses and improves security strategy, reduces attack surface risk, strengthens compliance, and provides continuous threat protection. Avertium maximizes customer...
-
CyberSecurity Intern
hace 2 días
Guadalajara, Jalisco, México Avertium A tiempo completoAvertium is a cyber fusion and MXDR leader, delivering comprehensive security and compliance services to mid-market and enterprise customers. Our unique "Assess, Design, Protect" methodology addresses and improves security strategy, reduces attack surface risk, strengthens compliance, and provides continuous threat protection. Avertium maximizes customer...