Senior Incident Response Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+21 more
Job description
Among the key duties of this position are the following:
- Performs daily operations of the incident detection and response program, which includes finding evidence of threats or suspicious behavior and leveraging data to improve controls and processes.
- Monitors information security incidents throughout Rutgers’ computing environment.
- Serves as an escalation point for Incident Response Analysts.
- Provides expert-level analytic, investigative and forensic support of complex security incidents to detect and remediate security threats on networks, workstations, servers, and other connected devices.
- Provides expert level advice and services to business units throughout the University while participating in all phases of Rutgers’ Integrated Incident Response Program (Prepare, Detect & Analyze, Contain, Eradicate, Recovery, Report, Remediate)., Working Hours Standard Hours 37.50 Daily Work Shift Work Arrangement Consistent with the current application of Rutgers Policy 60.3.22 or the applicable provisions of relevant collective negotiations agreements, this position may be eligible for a hybrid work arrangement. Flexible work arrangements are not permanent, subject to change or discontinuation, and contingent on the employee receiving approval in the FlexWork@RU Application System. Union Description Admin Assembly (MPSC) Payroll Designation PeopleSoft Seniority Unit Terms of Appointment Staff - 12 month Position Pension Eligibility ABP
Requirements
- Bachelor’s degree or equivalent education and experience plus five years relevant experience in specialty area
- 5+ years of information security experience; vulnerability scanning, penetration testing and/or security operations
- 5+ years of experience working in an enterprise technical environment, preferably in a customer-service based organization
Certifications/Licenses Required Knowledge, Skills, and Abilities
- Knowledge in a wide array of cybersecurity tools and their capabilities as they pertain to the detection and mitigation of Cyber Threats (SIEM, EDR, NGFW, DLP, IPS/IDS, etc.)
- Knowledge of industry standard cybersecurity frameworks (Mitre ATT&CK, NIST Incident Response, etc.)
- Understanding of complex enterprise networks to include routing, switching, firewalls and common networking protocols (HTTP, DNS, SMB, etc.)
- Experience with Regex and at least one common scripting language (PERL, Python, PowerShell)
- Experience with an enterprise SIEM platform
- Excellent verbal and written communication skills
- Ability to communicate technical problems succinctly and accurately
- Ability to handle multiple, shifting priorities and a large volume of technical problem resolution
- Ability to apply and document new technical knowledge and procedures
- Ability to work well with peers and junior staff in a team oriented, cooperative spirit, * Degree in a related field such as Information Security.
- 3+ years of experience in incident response, threat hunting, SOC operations, digital forensics, or detection engineering.
- Relevant certifications such as GCFA, GCIH (or other SANS certifications), CISSP, CySA+
- Experience as a key member of a cybersecurity team (SOC, Incident Response, Threat Intel, Malware Analysis, Live Forensics, IDS/IPS Analysis)
- Experience investigating identity-centric attacks, cloud compromise, phishing, business email compromise, and SaaS-based incidents.
- Knowledge of TTPs related to cyber-crime, malware, botnets, social engineering, APTs and other threats.
- Experience developing, tuning, and maintaining detection content including SIEM correlation rules, behavioral analytics, dashboards, and automation workflows.
- Expertise in network and host-based analysis and investigation
Equipment Utilized
- Vulnerability analysis/Penetration testing
- Packet capture and Netflow
- Firewalls/IPS/IDS/EDR
- Syslog/SIEM/Dashboards & Alerting/SOAR
- Threat hunting/Malware Analysis
- Windows/Linux/macOS
Physical Demands and Work Environment
- Must be able to lift up to 50 pounds for the purpose of moving computer equipment.
Benefits & conditions
Grade 07 Salary Details Minimum Salary 108147.000 Mid Range Salary 136809.000 Maximum Salary 165471.000, Rutgers provides a comprehensive benefits package to eligible employees. The specific benefits vary based on the position and may include:
- Medical, prescription drug, and dental coverage
- Paid vacation, holidays, and various leave programs
- Competitive retirement benefits, including defined contribution plans and voluntary tax-deferred savings options
- Employee and dependent educational benefits (when applicable)
- Life insurance coverage
- Employee discount programs
About the company
Rutgers, The State University of New Jersey, is a leading national research university and the State of New Jersey’s preeminent, comprehensive public institution of higher education. As one of the largest employers in the State of New Jersey, Rutgers University is committed not only to the students and the State that we serve, but also to the faculty and staff who work on our campuses.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Walking Into The Era of Supply Chain Risks
Understanding and Mitigating Common Web Vulnerabilities
Is Software Engineering Over-Saturated?