Security Operations Center Analyst
Role details
Job location
Tech stack
Job description
- Responsible for cybersecurity threat intelligence data collection via open intelligence sources.
- Organizes, documents, and collaborates discovered intelligence via information sharing platform.
- Research threat actors, malware, attack vectors, and other threat information, collects indicators of compromise, documents and advises management on prevention and remediation strategies.
- Continually evaluates accuracy of open source threat intelligence and evolves intelligence collection strategies as sources deteriorate or conflict.
- Maintains and updates past intelligence with new information is provided.
- Produces well-written reports outlining current industry threats, findings on managed network, and best practices following detected threats.
- Collaborates with other teams to locate and remediate threats based on intelligence collected and communicated.
- Must be able to work in a fast-paced ever-changing environment.
Requirements
BS/BA (or equivalent) degree in IT Security or related field, and 2-4years related experience ; or 4+years related experience with 2 years post-Secondary/AA-AS degree; or 8+ years related experience with no degree.
-
Understanding of various Operating Systems.
-
Understanding of system logs and familiarity with log analysis.
-
Understanding of cyber-attack vectors (Buffer Overflow, Phishing, etc.)
-
Ability to obtain and maintain a FAA public trust clearance This is an operations center staff position that supports the Enterprise Security Operations Control Center (SOCC), * 2+ years related experience with BS/BA (Bachelors) in Information Technology/Computer Information Systems or Cyber/Information Security; or 4-6 years related experience with 2 years post-Secondary/AA-AS degree; or 8+ years related experience with no degree.
-
Understanding of various Operating Systems.
-
Understanding of system logs and familiarity with log analysis.
-
Understanding of cyber-attack vectors (Buffer Overflow, Phishing, etc.)
-
Ability to obtain and maintain a FAA public trust clearance.
Preferred Additional Skills:
- Information Security experience.
- Security+ Certification or equivalent certification preferred.
- Understanding of system vulnerabilities and exploitation.
- Understanding of vulnerability mitigation.
- Knowledge of SIEM functions threat hunting, correlation of events, and metrics development.
- Must have strong written and oral communication skills, be self-motivated and a self-starter, maintain a curiosity and desire to learn, and be able to work well in a team environment.
- Ability to prioritize vulnerability mitigation efforts based on risk assessments.