Security Operations Center Analyst III

Sysco, Inc.
Houston, TX, United States
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Interoperability Intrusion Detection and Prevention Intrusion Detection Systems Network Security Security Information and Event Management In-Plane Switching (IPS) Tanium Platform Expertise Vulnerability Analysis

Job description

  • Receive, characterize, and analyze endpoint and network alerts from various sources within the enterprise and determine possible causes of such alerts to identify anomalous activity and potential threats to network resources and users

  • Provide timely detection, identification, and alerting of possible attacks/intrusions, anomalous activities, and misuse activities and distinguish these incidents and events from benign activities

  • Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack

  • Serve as an escalation point to SOC Analysts providing support, guidance, as well as work and track security incidents through final resolution

  • Create and maintain incident response processes, procedures and blueprints. Documenting and maintaining knowledge base of incident methodologies and plans

Requirements

  • Security Certification

Education Preferred:

  • Security+, CEH, OSCP/OSCE, CISSP, CISA, or GIAC

Experience Required:

  • Minimum 7 years in IT 5 years in Incident Response

Experience Preferred:

  • 10 years in IT, Minimum 7 years in Incident Response

Licenses/Certification Required:

  • Security Certification

Licenses/Certification Required:

  • Security+, CEH, OSCP/OSCE, CISSP, CISA, or GIAC

Skills and Abilities:

  • 5+ years of cybersecurity incident response experience with excellent background in networking and security to include intrusion detection/prevention

  • Excellent knowledge of security applications such as IDS, IPS, EDR, SIEM, next-gen AV and anomaly detection tools

  • Knowledge of cyber attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks.)

  • Excellent knowledge of the 6 phases in Cyber incident response plan

  • Wide knowledge of application and IT product diversity, interoperability, and extensive knowledge in IT security

  • Ability to configure and conduct vulnerability scans using VM tools such as Tenable.io and Tanium

About the company

Applicants must be currently authorized to work in the United States. We are proud to be an Equal Opportunity and Affirmative Action employer, and consider qualified applicants without regard to race, color, creed, religion, ancestry, national origin, sex, sexual orientation, gender identity, age, disability, veteran status or any other protected factor under federal, state or local law. This opportunity is available through Sysco Corporation, its subsidiaries and affiliates.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com

Good distractions

Talks and stories from around this role β€” technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman Β· WWC 2022

4:08 min

Introduction to interoperable apps on Bitcoin

Aaron Russell Β· LIVE

1:16 min

Securing internal pod communication with network security policies

Marc Nimmerrichter Β· WWC 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler Β· LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger Β· LIVE

Videos

See all

Related articles

See all