Security analys (soc) -advanced english (c1)

807168

CRC ¢ 1 a 1,5 millones

Costa Rica Toda Costa Rica

Publicado 12 Jul 2021

Sistemas / Otras

3 Vacantes

Informática y Computación / Otras

Infotree Global Solutions
Industria de la empresa:
Servicios

Descripción general

our company is ramping up the Security Operations Center and has a need to extend the L3 incident resolvers team. The person working in L3 SOC team receives incidents escalated from L2 SOC, gets to manage most complex findings and work towards remediation of the incidents found.

He/she continuously operates the Security Incident process, driving the resolution of identified issues, as part of the team, bringing the necessary experience and expertise above the existing L2 SOC level.

The main responsibilities of an Information Security Consultant:

• Monitoring and analysis of cyber security events with use of QRadar (SIEM), IDS, Cylance, RedCloak, McAfee antivirus
• Security Event Correlation as received from L2 SOC or Incident Response staff or relevant sources to determine increased risk to the business
• Recognize potential, successful, and unsuccessful intrusion attempts/compromises thorough review and analysis of relevant event detail and summary information
• Development and execution of SOC procedures
• Triage security events and incidents, detect anomalies, and report/direct remediation actions.
• Ensure confidentiality and protection of sensitive data
• Analysis of phishing emails reported by internal end users
• Working with remediation (IT Infra & Ops) teams on events and incident mitigation
• Follow up on remediation activities
• Update Security Operations reporting
• Support the SOC Manager in his duties (e.g. extension of SOC services to new sites)

Requisitos para aplicar

Requirements:

• Willingness to work overtime and adjust to reasonable demands from management in case of critical incidents being escalated to L3 for immediate handling.
• Must have cybersecurity incident discovery and event management, network forensics, IPS/IDS, firewalls, content filtering technology, DLP, configuration management and monitoring, endpoint protection, database security, and log collection and analysis understanding.
• Strong working knowledge of security-relevant data, including network protocols, ports and common services, such as TCP/IP network protocols and application layer protocols (e.g. HTTP/S, DNS, FTP, SMTP, Active Directory etc.).
• Experience and keen understanding of cybersecurity tools, including SIEM, IDS/IPS, antivirus and endpoint detection & response solutions.
• Experience with leading security incident response
• Involvement in threat intelligence and cybersecurity communities
• Able to multitask and give equal and/or required attention to a variety of functions while under pressure
• Ability to work independently and take ownership of projects and initiatives
• Excellent written and verbal communication skills required. Must be able to communicate technical details clearly
• Experience in developing and maintaining Play/Run-Books and/or Standard Operating Procedures in a SOC environment
• Strong troubleshooting, reasoning, and analytical problem-solving skills
• Ability to communicate technical details effectively in writing and verbally to junior IT personnel and management
• Team player with the ability to work autonomously

Datos complementarios

807168

Coordinador supervisor o especialista

Ingeniero

Bachillerato universitario

Industria farmacéutica

4 años de experiencia

Contrato Indefinido

807168

Últimos anuncios publicados

CONSULTORES DEL TALENTO
CONSULTORES DEL TALENTO
Salario confidencial
Cooperativa de Ahorro y Crédito ANDE Número Uno RL
Cooperativa de Ahorro y Crédito ANDE Número Uno RL
Salario confidencial
UNIVERSIDAD FIDELITAS
UNIVERSIDAD FIDELITAS
Salario confidencial