About the job
Description:
The Security Analyst I position plays a vital role within our organization. The primary responsibility involves monitoring customer environments for security incidents. This entails assessing the scope of threats, evaluating their business impact, and recommending the best course of action to mitigate and resolve issues. The Cybersecurity Technician will act as an escalation point for complex cybersecurity incidents and will need to effectively communicate with all relevant stakeholders during event management.
Responsibilities:
- Oversee security event monitoring and incident response ticket queues, ensuring adherence to service level agreements.
- Timely transfer cybersecurity tickets to relevant clients or internal contacts.
- Clearly communicate indicators of compromise, isolation measures, and remediation strategies.
- Analyze system, security, and application logs to diagnose issues, identify unusual behavior, and eliminate false positives.
- Utilize End Detection and Response tools to investigate alerts and anomalies, constructing accurate timelines related to potential compromises.
- Follow established protocols for investigating, escalating, containing, or eradicating malicious activities.
- Prepare and present comprehensive reports to clients, team members, and management to share security information and performance metrics.
- Contribute insights and suggestions for enhancing internal processes and procedures related to SOC operations.
- Engage in threat-hunting exercises and other special projects as needed.
- Adhere to our established standards and processes to ensure predictable outcomes for clients.
Additional Responsibilities:
- Maintain accurate and up-to-date timesheets, documenting all troubleshooting and communication with clients.
- Receive mentorship and constructive feedback from peers and supervisors.
- Escalate complex issues to more senior resources or appropriate teams when necessary.
- Collaborate with management to review ticket statuses.
