SOC Analyst II

Insight Global
United States
2 days ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Software System Penetration Testing Unix Cyber Security Data Security Internet Security Intrusion Detection and Prevention Intrusion Detection Systems Network Security Security Information and Event Management Web Applications Computer Networking Systems
+6 more
Malware Firewalls (Computer Science) Cybercrime Web Technologies Splunk Vulnerability Analysis

Job description

he Security Operations Center Information Security Analyst II will be part of the SOC Team. This center monitors, analysis and responds to infrastructure threats and vulnerabilities on a 24x7 basis.

  • Lead the analysis and investigation of information security events (IDS/Proxy/SIEM/etc.) in a 24X7 SOC environment to immediately detect, verify, and respond swiftly to cyber threats, and remove false positive. Strong networking background.

  • The analyst performs monitoring, research, assessment and analysis which requires demonstrable security incident response experience.

  • Serve as a technical point of escalation and provide mentoring for L1 Security Operations Center (SOC) analysts.

  • Handling security alerts on Splunk SIEM and Raise tickets based on the alerts.

  • Follow ups with respective team to close the alerts, tickets.

  • Analyze and assess security incidents and escalate to appropriate internal teams for additional assistance.

  • Responsible for investigating incidents, analyzing attack methods, researching new defense techniques and tools, developing security policy, and documenting procedures for SOC.

  • Malware analysis and other attack analysis to extract indicators of compromise. Perform data security event correlation between various systems.

  • Prepare reports, summaries, and other forms of communication that may be both internal and client facing.

  • Maintain familiarity with industry trends and security best practices.

  • Ensure compliance to SLA, process adherence and process improvisation to achieve operational objectives.

  • Periodic upgradation/creation of correlation rules based on emerging threats and requirement following MITRE Attack US-Cert and other TTP sources.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global’s Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Requirements

  • 5+ years working in the Security operations Centre.

  • Bachelor’s degree in engineering or higher preferred

  • Excellent knowledge of Intrusion Detection (deep TCP/IP knowledge, and Cyber security), various operating systems (Windows/UNIX), and web technologies (focusing on Internet security)

  • Ability to read and understand packet level data Intrusion detection and prevention and Network Security Products (IDS/IPS, firewalls, etc) Host Security Products (HIPS, AV, scanners, etc)

  • Knowledge of cutting edge threats and technologies effecting Web Application vulnerabilities and recent internet threats

  • Exposure on Vulnerability assessment as well as penetration testing or forensic analysis fields are an advantage

  • Experience working as part of a global team, spanning multiple time zones and cultures. * Certifications preferred: CEH

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:03 min

Microsoft integrating native Unix coreutils into Windows environments

Chris Heilmann +2 · LIVE

14:14 min

Addressing audience inquiries on analytical implementation and career growth

Julian Joseph · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

Videos

See all

Related articles

See all