Cyber Security Incident Response Team Analyst

Stellantis
Auburn Hills, MI, United States
13 days ago
Apply on jobs.mitalent.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours

Tech stack

Data Analysis Cyber Security Information Systems Databases Information Sciences Intrusion Detection and Prevention Log Analysis Performance Tuning Security Information and Event Management Web Services Firewalls (Computer Science) Information Technology
+2 more
Cybercrime Microsoft Sentinel

Job description

The Cyber Security Incident Response Team (CSIRT) Analyst is responsible for monitoring, detecting, analyzing, and responding to cybersecurity threats across the enterprise environment. The role focuses on proactive threat detection, incident investigation, SIEM monitoring, threat hunting, and coordination with global security and infrastructure teams to contain and remediate security incidents. The analyst will leverage enterprise security technologies including SIEM, EDR/XDR, threat intelligence platforms, and security monitoring tools to identify malicious activity, investigate anomalies, and support continuous improvement of the organization’s security posture. Role Description:

The ideal candidate will have experience in a variety of technologies essential to identifying threats to the Stellantis environment, specifically SIEM Microsoft Sentinel, and use those skills to perform the following:

Daily use of SIEM Tool, to analyze data flows and identify potential threats and anomalies. Ability to provide a detailed analysis of logs from security infrastructure (Firewall, IPS, etc). Provide internal threat hunting and policy abuse management based on information gathered in SIEM. Understand how to gather threat intelligence data. Recognize potential successful and unsuccessful intrusion attempts and compromises. Log incidents and track them via incident management tool (Resilient). Provide suggestions for Microsoft Sentinel optimization and source log parsing., Define Sentinel use cases, dashboards, filters etc. as needed.

Requirements

Have a solid understanding of enterprise environments including networking, web services, database, operating systems, etc. Experience with MITRE Attack is a plus. Provide documentation as needed, such as playbooks, to be shared with other team members. Ability to work from high level direction and then collaborate with the rest of the CSIRT and other Products within CDOC team., BS/BA degree in Computer Science, Data Science, Engineering, Information Science, Statistics, Information Systems, or other relevant disciplines from an accredited university or recognized higher education institution. Equivalent international qualifications such as a BSc, MSc, or Diplome d’ingenieur (Europe), or regionally accredited degrees (North America) are also acceptable. Minimum 3 years of overall experience working as a Security Analyst in enterprise environments. Minimum 2 years of hands-on experience with SIEM Sentinel, including configuration, tuning, and incident investigation. Strong understanding of SIEM (Security Information and Event Management) concepts, architecture, and operational workflows. Proven experience supporting and maintaining SIEM platforms in complex, large-scale enterprise infrastructures. Excellent analytical and problem-solving skills, with the ability to troubleshoot and resolve security-related issues effectively. Strong communication skills, with the ability to clearly articulate technical concepts to both technical and non-technical stakeholders, including management and cross-functional teams., Have a solid understanding of enterprise environments including networking, web services, database, operating systems, etc. Experience with MITRE Attack is a plus. Provide documentation as needed, such as playbooks, to be shared with other team members. Ability to work from high level direction and then collaborate with the rest of the CSIRT and other Products within CDOC team. At Stellantis, we assess candidates based on qualifications, merit, and business needs. We welcome applications from all people without regard to sex, age, ethnicity, nationality, religion, sexual orientation, disability, or any characteristic protected by law. We believe that diverse teams reflect our identity as a global company, enabling us to better address the evolving needs of our customers and care for our future.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.mitalent.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg Ā· LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa Ā· LIVE

11:18 min

Addressing audience questions on security and microservice architectures

Reinhard Kugler Ā· LIVE

3:21 min

Introduction to automotive security and digital forensics

Martin Schmiedecker Ā· LIVE

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu Ā· World Congress 2022

11:26 min

Identifying system risks and collaborative ecosystem legal challenges

Hans-Jürgen Eidler · LIVE

Videos

See all

Related articles

See all