Monitors and analyzes Intrusion Prevention Systems (IPS) and Security Information and Event Management (SIEM) to identify security issues for remediation
Performs network and endpoint security monitoring and incident response
Maintains records of security monitoring and incident response activities, utilizing case management and ticketing technologies
Creates, modifies, and updates Security Information Event Management (SIEM) rules
Escalates alerts regarding intrusions andpromises to the network infrastructure, applications and operating systems.
Assists with analysis of threat data obtained from proprietary and open source resources to provide indication and warnings of impending attacks against networks within the relevant vertical
Prepares briefings for SOC Manager and reports of analysis methodology and results
Creates and maintains standard operating procedures and other similar documentation
Generates end-of-shift reports for documentation and knowledge transfer to subsequent analysts on duty
Work independently with or without direction and / or supervision
Demonstrate effective teamwork and working relationships with others, both from CITCO and security vendors
Other projects and responsibilities, as assigned by direct supervisor
Qualifications :
2 to 4 years of experience in an in-house Security Operations Center team, or in an Security Consulting firm with an understanding of networking principles in a global environment across multiple data centers
Candidates must be able to work a flexible schedule within a 24x7x365 Security Operations Center (SOC) environment, as well as may be expected to work holidays.
A strong candidate is expected to have some or all of the following traits : Excellent analytical and problem-solving skills and interpersonal skills to interact with team members and upper management An understanding of cyber security incident response and network security monitoring Fundamental understanding ofputer networking (TCP / IP), knowledge of windows, Linux and palo alto operating systems and information security principles Knowledge of intrusion detection / prevention systems (IDS / IPS) and SIEM technologies in an enterprise environment Good knowledge of endpoint protection (EPP) and endpoint defense and response (EDR) solutions Drive to learn and a desire and motivation to achieve IT security related certifications