Summary:
We are seeking a highly motivated and results-oriented Security Analyst to join our dynamic security team. You will play a critical role in safeguarding the organization's IT infrastructure by leveraging your expertise in SIEM and EDR tools to detect, investigate, and respond to security threats.
Responsibilities:
- Demonstrated a proven track record of utilizing QRadar (SIEM) and Carbon Black (EDR) to expertly monitor security alerts, significantly improving threat detection and mitigation capabilities.
- Streamlined the security alert investigation process by effectively reducing response times through diligent triaging and in-depth analysis, resulting in faster incident resolution.
- Conducted comprehensive analyses of network traffic and system logs to identify and neutralize advanced persistent threats (APTs), proactively protecting the organization from sophisticated attacks.
- Collaborated effectively with Incident Response teams to enhance investigation efforts, contributing to more thorough and effective incident resolutions.
- Revolutionized SOC operational playbooks with automation and process optimizations, reducing redundant tasks and mitigating alert fatigue, leading to a more efficient and streamlined security posture.
Skills and Qualifications:
- Minimum 2 years of experience in a Security Operations Center (SOC) environment.
- Strong understanding of security concepts, frameworks, and best practices (e.g., SIEM, EDR, MITRE ATT&CK).
- Expertise in using SIEM (e.g., QRadar) and EDR (e.g., Carbon Black) tools for security event monitoring, investigation, and analysis.
- Excellent analytical and problem-solving skills with the ability to think critically and identify the root cause of security incidents.
- Proven ability to work independently and manage multiple priorities in a fast-paced environment.
- Strong communication and collaboration skills to work effectively with security teams and other IT departments.
- Ability to document technical findings and procedures clearly and concisely.
- A passion for cybersecurity and a desire to learn about emerging threats and vulnerabilities.
Bonus Points:
- Experience with scripting languages (e.g., Python, PowerShell) for automation.
- Experience with vulnerability scanning tools and penetration testing methodologies.
- Knowledge of cloud security concepts and best practices.