Education:
Bachelor's Degree in Information Technology, Information Security, or relevant field.
Applicable security certification a plus (CISSP, GIAC, etc.)
Experience:
At least one year of experience in Information Security
Skills, Specialized Knowledge (Desired):
Experience with scripting (PowerShell, Python, JavaScript)
Familiar with NIST CSF, ISO27001, and other security standards;
Qualifications
Experience with EDR or equivalent tools used for investigation;
Experience with SIEM products, NGAV/EDR,SASE/Web Gateways, firewalls, network devices, and intrusion detection/prevention systems;
Familiarity with OSI Model/networking fundamentals;
Strong analytical, problem-solving, and critical thinking skills;
Excellent verbal and written communication skills
Summary of Duties and Responsibilities
Monitor and respond to alerts from key security technologies and other internal sources.
Tunes alerts, processing rules, maintenance jobs, etc. to minimize false positives and noise while ensuring relevant security information is captured and highlighted.
Develop and implement new relevant detections within company SIEM.
Research emerging threats, evaluating likelihood of occurrence, and recommend controls to mitigate them.
Communicates ongoing investigations clearly and timely;
Create and update incident response playbooks and other security operations documentation as needed.
Interface with technical personnel and other teams as required.
Prepare and publish incident reports.
Track relevant KRIs and KPIs to measure program effectiveness.