Overview
The role of Information Security Analyst involves analyzing security events from various sources, detecting and investigating incidents, and proposing incident response actions. The analyst will work closely with customers to communicate detected incidents and suspicious activities.
Responsibilities
- Analyze security events from endpoints (Windows, Mac, Linux), Network IDS, Web-proxies, Mail-gateways, Active Directory infrastructure
- Detect and investigate information security incidents
- Propose Incident response actions and remediation plan
- Identification of potential vectors of attacks, develop detection methods of these attacks by existing technological solutions
- Adjust detection logic to fit Customer needs (filter out false positives, customize correlation rules, etc)
- Communicate with Customers regarding detected incidents and suspicious activities
Required Skills and Qualifications
Practical experience in the identification and investigation of information security incidents, development of recommendations to prevent similar incidents in the futureUnderstanding of the methods, tools, and processes to respond to information security incidentsExperience in network traffic and log-files analysis from various sourcesKnowledge of current threats, vulnerabilities, typical of attacks on information systems and tools to implement them, as well as methods for their detection and responseKnowledge of network protocols, the architectures of modern operating systems, and information security technologiesExperience in work with ELK stack is welcomeCertifications (Offensive Security, GIAC) are welcomeBenefits
This role offers the opportunity to work with cutting-edge technology, collaborate with experienced professionals, and contribute to the improvement of information security measures.
#J-18808-Ljbffr