Experience in security operations and incident response disciplines
Experience detection/incident tooling or workflow optimization
Some experience working within cloud platforms, particularly AWS
Experience working & maintaining with SIEM; developing queries & alerts
Some Experience performing smaller investigations, analysis and communicating the events or incidents to proper stakeholders clearly
Experience deploying tooling to advance investigation tactics and incident response across different environments ie; corporate environments and cloud environments
An understanding of Windows & MacOS, Linux is nice to have
An understanding of various threats and how to investigate, detect and prevent them
Love to learn; you are motivated to learn about security and tinkering
Utilizing this knowledge in SecOps, or creatively using it in a response effort
Experience interfacing with technical and non-technical individuals. Ability to adjust the level of technicality depending on the group
GIAC, CEH, GSOC certificates
Position Expectations
Leveraging automation workflows, and enriching discoveries and detections
Assist with Incident Response and Investigation across different environments and platforms
Utilizing analysis frameworks (ie; MITRE) to better understand gaps, and working towards closing those gaps
Maintain, improve, and configure Information Security Operations tooling and alerts
Leverage threat intelligence for enrichment
Develop well written documentation and playbooks
Work cross functionally with multiple teams deploying tooling, establishing new processes, or improving existing processes
Ability to quickly learn new Information Security concepts and adapt to a modern, fast-paced organization
Help mentor and train others on the team
Participate in weekly on-call rotations
Success Measures
The Information Security Analyst will be successful in this role when they can execute the following strategic tasks:
3 Months
You will have familiarized yourself with much of the Information Security Operations documentation hub, and met everyone on the team. You will have the opportunity to identify any gaps and make improvements, leading to an understanding of the Security Operations departments process.
6 Months
You will have familiarized yourself with much of the data and tooling the entire Information Security team uses. You would have fully scoped and executed a medium to small project by now, that has positively impacted the company security posture.
12 Months
Fully understand our program, response process and operation of tooling., as well as learning more about workflow automation. You should be considered a subject matter expert in the realm of investigations for corporate security operations.