Security Events Monitoring: Use SIEM technologies and other native tools to perform the monitoring of security events on a 24x7 basis and perform analysis, while integrating the results and information needed to proactively protect the enterprise. Inbound Requests Management: Manage inbound requests via the ticketing system, as well as via telephone calls, and provide security notifications via three methods: logging incident tickets, sending emails, and placing telephone calls. Log Analysis: Assist in performing analysis on logs produced by network devices utilized within the infrastructure such as firewalls, content filtering, syslog from various sources/devices, assorted Intrusion Detection capabilities, substantiating vulnerability scanner results, directory services, DHCP logs, Secure Email Gateway logs, and approved applications. Defect/Threat Identification: Assist in security events analysis and support to include identifying potential threat, anomalies, and infections, documenting findings, providing recommendations within the incident management system, performing triage of incoming security events, performing preliminary and secondary analysis of those events, and validating the events. Root-cause Analysis: Assist in cybersecurity root-cause analysis in support of any tickets for which it fails to meet the Acceptable Quality Levels. This root-cause analysis will include documenting recommendations for corrective action.
Current Degree Pursuit: Pursuing a bachelor’s degree or above in Computer Science, Systems Engineering, Cybersecurity, Information Technology, or related area. Tech-Savvy: Experience/ knowledgeable in using numerous security tools and technologies to include some of the following technologies: SIEM, IDS/IPS, Web application firewalls, Antivirus, Proxy and URL filtering, DLP, Vulnerability scanner. Understanding of basic network services, TCP/IP, IP Routing, attacks, exploits and vulnerabilities. Knowledgeable in troubleshooting Microsoft products and Operating system (i.e., MAC OS & Linux) would be desirable. Experience with VPN, SSL, other encryption methodology / technology a plus.
#LI-CT1