POSITION FOR TALENT POOL: Incident Response Analyst
Role Responsibilities
· Review security-related events and assess their risk and validity based on available telemetry from network, endpoint, and global threat intelligence information in order to provide clients with concise, detailed, and well-written incident reports, root causes identification, and remediation recommendations
· Provide customers with understandable context around their security environment and threats
· Interface with clients to address their issues, concerns, and questions, and drive to satisfactory closure any issues that impact the service and its value.
Experience, Skills and Abilities
· Significant experience with and expert understanding of:
· Two (2) or more of the following operating systems (Windows, Linux, Mac OS) at a filesystem level
· Fundamental Internet protocols, services and technologies (e.g. HTTP/HTTPS, DNS, SMTP, SSH, LDAP, TCP/IP, UDP, ICMP, JSON, REST, etc.)
· Common security controls (e.g. firewalls, proxies, IDS/IPS, WAF, etc.)
· Experience with and strong understanding of:
· Performing both endpoint and network-based investigations
· Reviewing logs to identify evidence of past intrusions
· Pivot off indicators within networks to identify the scope and breadth of attacks