Search

Security Operations Analyst

PublishedPublished: 6/14/2022
Real Estate

Job Description

Job DescriptionApply now: Security Operations Analyst, location is hybrid . The start date is ASAP for this 6 month contract position. Job Title: Security Operations Analyst Location-Type: Hybrid onsite in Needham, MA (Candidate must currently reside permanently local to MA, not open to relocation at this time) Start Date Is: ASAP Duration: 6 Month Contract Compensation Range: 60-70/hr W2 Benefits: Eligible for Health, Dental, Vision, 401K Must be authorized to work in the U.S. This position is not eligible for sponsorship .

Position Overview

This role is ideal for a hands-on security professional who can take a security alert from initial detection through investigation, scoping, remediation, and final resolution. The successful candidate will be highly investigative, technically strong across endpoint and network security, and comfortable collaborating with infrastructure, networking, IT, and business teams.

Responsibilities

  • Investigate, analyze, coordinate, and report on security events and incidents.

  • Own security alerts through analysis, diagnosis, containment, remediation, and resolution.

  • Perform threat analysis, incident investigation, and root-cause analysis.

  • Investigate and respond to security alerts across endpoints, networks, cloud environments, and identity systems.

  • Determine the scope and impact of suspected security incidents.

  • Coordinate containment, remediation, and recovery efforts with cross-functional IT teams.

  • Perform network security assessments and review systems for evidence of vulnerabilities or compromise.

  • Assist with vulnerability assessment, remediation, and mitigation activities.

  • Operate, tune, validate, and improve security monitoring tools.

  • Participate in the evaluation and implementation of new security technologies and products.

  • Create, evaluate, and implement security policies, processes, and procedures.

  • Participate in security tool validation and testing programs.

  • Serve as a technical resource for proactive and reactive security issues.

  • Participate in security engineering projects outside of day-to-day alert monitoring.

  • Collaborate with infrastructure, networking, cloud, desktop, and other IT teams.

  • Communicate security findings and recommendations to technical and non-technical stakeholders.

  • Maintain accurate incident documentation and reporting.

Required Qualifications

  • 3 years of experience in Security Operations, SOC, incident response, or a closely related cybersecurity role. Exceptional candidates with less experience may be considered.

  • Experience working in an enterprise-level environment.

  • Demonstrated hands-on experience investigating and responding to security alerts.

  • Ability to own incidents end-to-end, from initial alert through investigation, scoping, remediation, and resolution.

  • Strong experience with SIEM and EDR technologies.

  • Experience with one or more of the following or comparable technologies:

    • Microsoft Sentinel

    • Splunk

    • CrowdStrike

    • SentinelOne

    • Microsoft Defender for Endpoint

    • Zscaler

    • Cloudflare

    • Comparable web/email gateway or cloud security platforms

  • Strong understanding of endpoint, network, operating system, and cloud security.

  • Knowledge of TCP/IP, networking, routing, switching, firewalls, and network security concepts.

  • Experience with vulnerability assessment and remediation.

  • Scripting experience using PowerShell, Python, or similar technologies.

  • Experience with security tool configuration, tuning, implementation, or validation.

  • Strong analytical and investigative skills.

  • Ability to identify root cause and determine the scope of security incidents.

  • Strong communication and cross-functional collaboration skills.

  • Demonstrated curiosity, tenacity, and willingness to investigate beyond the initial alert.
  • Must currently reside permanently local to MA, not open to relocation at this time)

Preferred Qualifications

  • Security engineering experience in addition to SOC/incident response responsibilities.

  • Threat hunting experience.

  • Experience with security automation or SOAR.

  • Experience implementing or validating security tools.

  • Experience with cloud security platforms.

  • Experience developing or improving security processes and procedures.

  • Familiarity with MITRE Telecommunication&CK and common incident-response methodologies.

Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...