Vancouver, BC, V5Y 2E2, CAN
12 hours ago
Tier 2 Security Operations Analyst (VAN or SEA)
Job Description The Cyber Security Analyst will help the team to perform Security Operations Center (SOC) duties, which include incident response, malware analysis, and monitoring. This role will work with the team to implement processes and practices designed to protect networks, devices, and data from malicious attack, damage, or unauthorized access. • Triages alerts/incidents and performs deep analysis; correlates with threat intelligence tools, tactics and procedures (TTP) in indicators of compromise (IOCs) to identify the threat actor, nature of the attack, and systems or data affected. • Prioritizes and triages alerts or issues to determine whether a real security incident is taking place and escalate incidents to Tier 3 if remediation cannot be closed within SLA time. • Performs analysis, triage and remediation of low/medium priority alerts. • Analyzing logs, network traffic, and other data sources to identify the source of incidents. • Record identified vulnerabilities, create remediation tickets and track their status. • Build internal scripts, tools, and automation processes to enhance detection and response capabilities. Adjusting security tools and processes, e.g. EDR alerting modifications, updating detection rules conditions, etc. We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/. Skills and Requirements • Bachelor’s in: Computer Science, Information Security, Cybersecurity, or a related degree. • 2-4 year experience in one or more areas: Security Operations, Incident Response • Strong security concepts of threat categories (such as malware, phishing attacks, Defense-in-Depth, MITRE ATT&CK framework, etc.) • Strong knowledge of M365 Security tools, • Azure and/or AWS • Working experiences to security tools such as SIEM (Sentinel preferred) EDR, firewalls, IDS/IPS, anti-spam, content management, server and network device hardening, etc. • Strong knowledge of Windows, Linux and/or Mac OS and comfortable with looking at, understanding, and investigating Security Event logs. • Good knowledge of networking protocols (SMTP, HTTP, HTTPS, FTP, DNS, DHCP, etc). • Experiences of any query language and scripting language • Experience in using security orchestration, automation, and response tools • Experience with query languages and scripting languages null We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion,sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military oruniformed service member status, or any other status or characteristic protected by applicable laws, regulations, andordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to HR@insightglobal.com.
Confirmar seu email: Enviar Email