Cyber Security Analyst Level 2
Summary
L2 Cyber Security Analyst in a 24x7x365 SOC, monitoring and analyzing security events, handling L1 escalations, performing threat hunting, and fine-tuning SIEM rules using QRadar/Sentinel/Splunk.
Salary: $90,000 – $110,000 per year
The eir evo Security Team is responsible for protecting and monitoring our clients' organisations. We provide 24x7x365 capabilities to protect, detect, analyse, and respond to cybersecurity incidents using a combination of technology solutions and a strong set of processes.
This is a significant, established team based in Ireland and New Zealand supporting a range of enterprise client organisations.
The SOC staff work closely with our customer and the eir evo Network Operation Centre (NOC) team to ensure security issues are addressed quickly upon discovery.
The Cyber Security Analyst Level 2 monitors and analyses activity on networks, servers, endpoints, databases, applications, websites, and other critical systems, looking for anomalous activity that could be indicative of a security incident or compromise.
This is a permanent position based in our Auckland office
We are looking for a Cyber Security Level 2 Analyst to perform the following duties
Continuously support the customers security infrastructure via SIEM, EDR, VA, SOAR etc
Handle escalation from L1 Analysts,
Provide guidance to L1 Analysts,
Perform advance triage and threat hunting using SIEM, EDR, SOAR etc
Interact with customers to gather requirements and address them accordingly,
Provide recommendation of use case design and fine tuning to correlation engineer,
Actively fine-tune rules on QRadar/Sentinel/Splunk and test them accordingly
Develop case studies and monthly threat reports,
Perform Vulnerability Assessment,
Assist in the development of policy, process, and technology,
Qualifications and Certifications:
Education: Bachelor's Degree or equivalent preferably
Beneficial Certifications: Palo Alto Networks Certified XSOAR Engineer, IBM Security QRadar SIEM Administration and other related to IT Security (CompTIA Security+, CCNA Security, Microsoft Security Operations Analyst SC-200, AZ500, etc.)
Experience:
2+ years of experience in information security sphere
1+ year of experience in supported technology (Palo Alto Cortex XSOAR and/or IBM Security QRadar SIEM and/or ArcSight and/or Splunk)
Linux/Unix basics
Experience in investigating security devices (SIEM, IDS/IPS, firewall, endpoint security systems, etc.)
Familiar with any of AQL, KQL, regex, python experience preferred
Knowledge of Vulnerability Assessment
Knowledge of routing protocols and technologies
Passionate and Professional security mind set
Strong customer service skills to follow-up with clients and handle escalations
Capability to ensure confidentiality and discretion in performing sensitive tasks
Work Conditions:
Work hours will be a regular 5 day work week of 7.5 hours per day during regular business hours. Out of hours and on call support as required.
Our company has an agile work policy where engineers can opt to work 2 to 3 days per week from home.
Office based in Grafton, Auckland.
Sufficient parking available for all employees