Security Operations Analyst

CloudFlare
Needham, MA, United States
14 days ago
Apply on mondo.gosnaphop.com
Prepare application

Role details

Contract type
Temporary to permanent
Employment type
Part-time / full-time
Experience level
Expert
Experience required
3 years minimum
Compensation
$135,200.0 - $166,400.0
Working hours
Regular working hours

Tech stack

Testing (Software) Cloud Computing Security Cyber Security Identity and Access Management Python (Programming Language) Network Security Routing Performance Tuning Windows PowerShell Reliability Engineering Security Information and Event Management TCP/IP
+11 more
Scripting Firewalls (Computer Science) Azure Security Center Cybercrime Cloudflare Microsoft Sentinel Splunk SentinelOne Expertise Devsecops Security Orchestration, Automation & Response Vulnerability Analysis

Job description

This role is ideal for a hands-on security professional who can take a security alert from initial detection through investigation, scoping, remediation, and final resolution. The successful candidate will be highly investigative, technically strong across endpoint and network security, and comfortable collaborating with infrastructure, networking, IT, and business teams., * Investigate, analyze, coordinate, and report on security events and incidents.

  • Own security alerts through analysis, diagnosis, containment, remediation, and resolution.
  • Perform threat analysis, incident investigation, and root-cause analysis.
  • Investigate and respond to security alerts across endpoints, networks, cloud environments, and identity systems.
  • Determine the scope and impact of suspected security incidents.
  • Coordinate containment, remediation, and recovery efforts with cross-functional IT teams.
  • Perform network security assessments and review systems for evidence of vulnerabilities or compromise.
  • Assist with vulnerability assessment, remediation, and mitigation activities.
  • Operate, tune, validate, and improve security monitoring tools.
  • Participate in the evaluation and implementation of new security technologies and products.
  • Create, evaluate, and implement security policies, processes, and procedures.
  • Participate in security tool validation and testing programs.
  • Serve as a technical resource for proactive and reactive security issues.
  • Participate in security engineering projects outside of day-to-day alert monitoring.
  • Collaborate with infrastructure, networking, cloud, desktop, and other IT teams.
  • Communicate security findings and recommendations to technical and non-technical stakeholders.
  • Maintain accurate incident documentation and reporting.

Requirements

  • 3 years of experience in Security Operations, SOC, incident response, or a closely related cybersecurity role. Exceptional candidates with less experience may be considered.
  • Experience working in an enterprise-level environment.
  • Demonstrated hands-on experience investigating and responding to security alerts.
  • Ability to own incidents end-to-end, from initial alert through investigation, scoping, remediation, and resolution.
  • Strong experience with SIEM and EDR technologies.
  • Experience with one or more of the following or comparable technologies:
  • Microsoft Sentinel
  • Splunk
  • CrowdStrike
  • SentinelOne
  • Microsoft Defender for Endpoint
  • Zscaler
  • Cloudflare
  • Comparable web/email gateway or cloud security platforms
  • Strong understanding of endpoint, network, operating system, and cloud security.
  • Knowledge of TCP/IP, networking, routing, switching, firewalls, and network security concepts.
  • Experience with vulnerability assessment and remediation.
  • Scripting experience using PowerShell, Python, or similar technologies.
  • Experience with security tool configuration, tuning, implementation, or validation.
  • Strong analytical and investigative skills.
  • Ability to identify root cause and determine the scope of security incidents.
  • Strong communication and cross-functional collaboration skills.
  • Demonstrated curiosity, tenacity, and willingness to investigate beyond the initial alert.
  • Must currently reside permanently local to MA, not open to relocation at this time, * Security engineering experience in addition to SOC/incident response responsibilities.
  • Threat hunting experience.
  • Experience with security automation or SOAR.
  • Experience implementing or validating security tools.
  • Experience with cloud security platforms.
  • Experience developing or improving security processes and procedures.
  • Familiarity with MITRE Telecommunication&CK and common incident-response methodologies.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on mondo.gosnaphop.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · World Congress 2022

Videos

See all

Related articles

See all