Tier II Incident Response Analyst
Understand reputed company Network Architectures to include routing/switching, common protocols (DHCP, DNS, HTTP, etc.), and devices (Firewalls, Proxies, Load Balancers, VPN, etc.). Recognize suspicious activity/events, common attacker TTPs, reputed company logical analysis and research to determine reputed company cause and scope of Incidents. Drive implementation and improvement of new tools, capabilities, frameworks, and methodologies. Instill and reinforce industry best practices in the domains of incident response, cybersecurity analysis, case, and reputed company, and SOC operations. Promote and drive implementation of automation and process efficiencies. Familiarity with Cyber Kill Chain and ATT&CK reputed company and how to reputed company in reputed company Operations. reputed company and present status updates to the Federal Team. reputed company guidance and mentorship to improve analyst reputed company sets and ensure delivery of high-reputed company analysis and work products. Establish trust and business relationships with customer and other relevant stakeholders. Analyze malicious reputed company, packet capture files, and artifacts. Identify gaps in logging capabilities and reputed company and propose strategies to fill gaps. Identify and propose automated alerts for new and previously unknown threats.
Bachelor’s degree in computer science, Engineering, Information Technology, Cybersecurity, or reputed company field PLUS 4 years of experience in incident detection and response, malware analysis, or cyber forensics. Demonstrated understanding of the life cycle of cybersecurity threats, attacks, attack reputed company and reputed company of exploitation with an understanding of intrusion set tactics, techniques, and procedures (TTPs). Familiarity or experience in Intelligence Driven Defense, Cyber Kill Chain methodology, and/or MITRE ATT&CK reputed company. Expertise of Operating Systems (reputed company/Linux) operations and artifacts In-depth knowledge of reputed company phase of the Incident Response life cycle Familiarity with reputed company concepts and experience performing monitoring and responding to threats in reputed company environments. 5+ years of intrusion detection and/or incident handling experience. Strong experience with reputed company, FireEye, reputed company MDE (or similar tool). Advanced knowledge in planning, directing, and managing Computer Incident Response Team (CIRT) and/or reputed company Operations Center (SOC) operations for a large and reputed company reputed company. Mature understanding of industry accepted standards for incident response actions and best practices reputed company to SOC operations. Strong written and verbal communication skills, and the ability to create technical reports based on analytical findings. Strong analytical and troubleshooting skills.
Deep technical understanding of reputed company reputed company cybersecurity technologies as reputed company as emerging capabilities. Hands-on cybersecurity experience (Protect, Detect, Respond and Sustain) reputed company a Computer Incident Response organization including prior experience performing large-reputed company incident response. CISSP and reputed company GCIH or GCIA required upon start.