Senior Cybersecurity Analyst
Role details
Job location
Tech stack
Job description
The Security Operations Center provides 24/7/365 monitoring, analyzes, and responds to cybersecurity alerts for the organization. Provides rapid response to incoming security alerts, enriches those alerts with an initial triage effort and ensures the proper team is engaged for response.
- Monitors work queues for alerts of potential network threats, intrusions, and/or compromises.
- Assess validity and scope to determine if the alert is actionable and determine remediation steps required.
- Confirm accuracy of the alerting information.
- Identify malicious behaviors.
- Determine remediation actions needed.
- Escalate incident to proper team for response and remediation.
- Participate in and provide leadership to specialized guild related activities and projects.
- Mentor and provide guidance to associate and cybersecurity analysts.
- Experience and knowledge conducting analysis of cybersecurity threats.
- Experience in cybersecurity event monitoring/analysis in a Security Operations Center environment.
- Efficient documentation of triage details, sources of information, and recommendations for response.
- Develop strong relationships with technical personnel from various disciplines to assist with projects, process improvements, and process documentation.
- Subject matter expert in specific processes, systems, and/or tools related to cybersecurity.
- Leverage enterprise-approved AI tools to streamline workflows, automate tasks, and drive continuous improvement
You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear directions on what it takes to succeed in your role as well as provide development for other roles you may be interested in.
Requirements
- HS Diploma required.
- 4 years of experience in Cybersecurity.
- Any one of the following Certification in cybersecurity required. (e.g. Security+, CCNA Cyber Ops, CCSP, GCIA, GCIH, CEH, CySA+, OSCP, etc.)
- 4 years of experience with any of the industry recognized analysis frameworks (Kill Chain, Diamond Model, MITRE ATT&CK, NIST Incident Response, etc.)
- 4 years of experience with fundamental security and network concepts (Operating systems, intrusion/detection, TCP/IP, ports, etc.)
- 4 years of experience with any one of the fundamental securities related to cloud platforms (AWS, Azure, GCP, etc.)
- 4 years of experience in demonstrating triage and investigative skills utilizing multiple security sensors including documentation and debriefing of incidents
- Willing to work in a team-oriented 24/7 SOC environment; flexibility to work on a rotating schedule (including occasional shift work)
Preferred Skills:
- Bachelor's degree preferred.
- Experience working with SOAR Automation and developing SOAR playbooks.
*All Telecommuters will be required to adhere to UnitedHealth Group's Telecommuter Policy.
Benefits & conditions
Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The hourly pay for this role will range from $91,700 to $163,700 per hour based on full-time employment. We comply with all minimum wage laws as applicable.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.