Incident Response Specialist, Analyst

Remote Full-time
About the position In this role you will focus on researching potential cybersecurity threats to various systems, technologies, operations, and programs throughout multiple environments. You will perform analysis based on this research to determine the risk to the organization and take appropriate actions based upon that analysis. Responsibilities include rapidly responding to potential incidents and events to minimize risk exposure and ensure the confidentiality, integrity, and availability of assets and business processes. Additionally, you will proactively monitor internal and external-facing environments, seek opportunities to strengthen and automate detection and remediation capabilities, reduce response times for incidents, and produce analyses of cybersecurity events that include perspectives on the behavior of adversaries. Responsibilities • Conduct analysis of artifacts to determine methods of intrusion and best course of resolution while driving security improvement • Strong Incident Response knowledge and experience • Theoretical and practical knowledge with Mac OS, Linux, Windows operating systems and clouds • Experience with security data collection, analysis and correlation • Well-developed analytic, qualitative, and quantitative reasoning skills • Demonstrated creative problem-solving abilities • Security event monitoring, investigation, and overall incident response process • Investigate potential cybersecurity events across multiple environments using various tools and techniques • Development of information security policies, standards, and procedures • Understanding of offensive security to include common attack methods • Understanding of how to pivot across multiple datasets to correlate artifacts for a single security event • A diverse skill base in both product security and information security including organizational structure and administration practices, system development and maintenance procedures, system software and hardware security controls, access controls, computer operations, physical and environmental controls, and backup and recovery procedures. • Knowledge and experience in security and regulatory frameworks (ISO 27001, NIST 800 series, FFIEC, SOC2, FedRAMP, STAR, etc.) • Support inquiries from compliance teams such as IT risk management and internal and external auditors to ensure documentation is complete and processes are in compliance with information security policies • Support the development of security operations detections, playbooks, and automations to ensure threat detection, monitoring, response, and forensics activities align with best practices, minimize gaps in detection and response, and provide comprehensive mitigation of threats • Reviews internal logs and alerts to identify potential cybersecurity events. • Triage cases based on output from automated alerts, and determine when to escalate to other teams • Analyzes security data from all systems in real time to spot and thwart potential threats, attacks, and other violations • Analyzes compromised systems and remediates to a clean state • Performs breach indicator assessments to investigate network traffic for malicious activity • Assists with internal or third-party employee investigations • Assists in the production of various reports which identify and analyze relevant upcoming and ongoing threats to the enterprise • Research evolving threats, techniques, tools, and vulnerabilities in support of information security efforts • Stays current with information security program developments, industry frameworks, changes in the company, industry trends, and current security practices Requirements • Bachelor’s degree in Information Technology, Cyber Security, Computer Science, or related discipline • 2 + years of experience working in the Cybersecurity Operations or Information Security Nice-to-haves • Relevant technical and industry certifications, such as CISSP, ISSMP, SANS, GIAC, GCIA, CISM, CEH, GCFA, GCFE, GCIH, or GSEC are preferred • Experience in one or more security domains including Incident Response and Forensics, Security Governance and Oversight, Security Risk Management, Network Security, or Threat and Vulnerability Management preferred • Experience with information security risk management, including information security audits, reviews, and risk assessments • Understanding of enterprise detection and response technologies and processes (advanced threat detection tools, intrusion detection/prevention systems, network packet analysis, endpoint detection and response, firewalls, Anti malware/anti-virus, Security Information and Event Management tool) • Experienced with CrowdStrike, Tanium, Proofpoint, WAF, O365 security, AWS Security, Wireshark, tcpdump, and open-source incident response and forensic tools • Ability to perform risk analysis utilizing logs and other information compiled from various sources • Understanding of network protocols, operating systems (Windows, Unix, Linux, Databases), and mobile device security • Knowledge in one or more security domains including Security Governance and Oversight, Security Risk Management, Network Security, Threat and Vulnerability Management, or Incident Response and Forensics • Knowledge of cloud security, networks, databases, and applications • Knowledge of the various types of cyber-attacks and their implementations • A fundamental understanding of enterprise cybersecurity frameworks such as MITRE ATT&CK and Cyber Kill Chain • Ability to document and explain technical details in a concise, understandable manner • Experience in operational processes such as security monitoring, data correlation, troubleshooting and security operations Benefits • comprehensive health and wellness benefits • retirement plans • educational assistance and training programs • income replacement for qualified employees with disabilities • paid maternity and parental bonding leave • paid vacation, sick days, and holidays Apply tot his job
Apply Now

Similar Opportunities

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote Full-time

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote Full-time

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote Full-time

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote Full-time

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote Full-time

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote Full-time

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote Full-time

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote Full-time

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote Full-time

USPS Office Helper

Remote Full-time

Netflix Remtoe Job (Full Stack Software Engineer L5 – Data Architecture & Integrations) – Job ID – 106

Remote Full-time

English Language Co-Teacher and Youth Educator

Remote Full-time

Experienced Full Time Remote Data Entry Specialist – Accurate Information Management and Entry for Blithequark

Remote Full-time

Experienced Long-Term Substitute Elementary Teacher for Grade 5 - Toquam Magnet Elementary School, Stamford Public Schools

Remote Full-time

Monitor Technician I, Centralized Monitoring

Remote Full-time

Webflow Developer for Ongoing Client Projects

Remote Full-time

Experienced Remote Data Entry Specialist - Customer Service Focus - $30/H - Flexible Work from Home Opportunities with blithequark

Remote Full-time

Experienced Cybersecurity Analyst – Part Time Remote Opportunity for Career Growth and Development in a Dynamic Industry

Remote Full-time

**Job Title:**

Remote Full-time

Part Time blithequark Customer Service Representative – Flexible Work from Home Opportunity

Remote Full-time
← Back to Home