CSOC Analyst
Optomi, in partnership with a national leader in renewable energy, is seeking a Cyber Security Analyst to join their team in their uptown Security Operations Center.
The Cyber Security Analyst is responsible for detecting, assessing and responding to cybersecurity events and incidents across the client's environment. The Analyst will work closely with peers, other internal/external teams and management in a 24x7 Cybersecurity Operations Center (CSOC) environment. This Analyst also is responsible for following processes and procedures as defined by Cybersecurity Leadership and the Computer Incident Response Team (CIRT).
What the right professional will enjoy:
· Work in a state-of-the-art Security Operations Center
· Receive education/certification reimbursements
· Help secure one of the nation’s largest power grids
· Gain exposure to industry leading cybersecurity practices and procedures
· Work for an organization with tons of room for career growth and development
What to expect in this role:
· Conduct network, endpoint, and log analysis by utilizing various consoles on a regular basis to analyze and triage cybersecurity events (e.g., SIEM, IPS, firewall, etc.) and perform continuous hunt across the environment.
· Reconstruct cyber events, assess cyber threat and scope of impact, identify and track any internal lateral or external movement, and develop response solutions.
· Interact with the security community to obtain technical cyber threat intelligence.
· Track cyber threat actors/campaigns based on technical analysis and open source/third party intelligence.
· Research and track new exploits and cyber threats.
· Conduct cursory and/or in-depth computer forensic investigations (i.e. packet captures, endpoint behaviors, etc.), or collaborate with peers when appropriate for hand-offs/escalations.
· Conduct analysis of malicious code and weaponized documents through behavioral analysis or reverse engineering.
· Enhance and tune detections and alerts and other cyber event correlation rules to reduce false positives.
Apply today if your background includes:
· Previous exposure to cybersecurity operations
· Knowledge of network monitoring, analysis, troubleshooting, and configuration control technologies
· Demonstrated understanding of the life cycle of network threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs).
· Preferred Experience with forensics and malware analysis concepts and methods.
· Familiarity or experience with the Cyber Kill Chain methodology
· Knowledgeable in the NIST Cybersecurity Framework
· Willingness to pursue industry standard certifications such as Security+, SANS GIAC/GCIA/GCIH/GCFA, CISSP, etc. or other networks/system security certifications.
· Bachelor Degree in Cybersecurity, Computer Science, MIS or other degrees with a high-level understanding of network and application security and information systems
**No sponsorship available. No Corp to Corp