Programming & Development
Location: New York
Experience: 12 + Yrs
Project Duration: Contract (Extension Mode)
Job Details:
Essential Job Functions
•Monitor open and restricted sources of information as well as consult with other departments, agencies, and peers. The position also requires cultivating relationships with the aim of gathering intelligence relevant to the environment and its periphery.
•Provide cyber threat analysis and reporting to support SOC and the program’s situational awareness.
•This person is a member of a high-tech Security Operations Center and will actively monitor security threats and risks, provide in-depth threat analysis, and evaluate security incidents.
•Utilize the latest in security technology to assist in incident response.
Roles & Responsibilities
•Collects, analyzes, and disseminates technical cyber threat intelligence including the timely collection of advanced warning of impending IT vulnerabilities or threats, a thorough correlation, analysis and storage of threat intelligence information, and operational support of the incident response process
•Collect, analyze, catalog, and assist in the deployment of indicators of compromise (IOCs) to help refine detection and response efforts.
•Collect, analyze, catalog, and store IOCs from internal security events detected.
•Leverage online research expertise to identify and navigate relevant online forums, including web sites, social media, and traditional sources to support research and analysis.
•Conduct research on emerging security threats, extract tangible behaviors, locations, indicators, vectors, and other methods to be used for hunting previously unidentified intrusions or intrusion attempts.
•Maintain a knowledge database to identify threats by behaviors, identify motives, and identify emerging threats and trends.
•Maintain knowledge of the tools available to the SOC in order to utilize them for research and suggest methods by when to employ actionable intelligence.
•Continuously increase knowledge of new attacks and methods and use it to mature the program’s countermeasure capabilities.
•Develop threat trend analysis reports and metrics.
•Work closely with the other teams to assess risk and provide recommendations for improving our security posture.
•Assist in after-action analysis to computer security incidents by utilizing event documentation and supplementing with available logs if needed
•Assist SOC analysts with monitoring network traffic for security events and perform triage analysis to identify security incidents when needed.
•Author and update Standard Operating Procedures (SOPs) and training documentation.
Required Skills, Experience, & Qualifications:
•Bachelor’s degree (preferred) in Computer Science, Cyber Security, Intelligence Studies or related field and/or work experience.
•Must have at least one (1) certification in the field of information security from a respectable security organization. Desirable certifications include, but not limited to: FOR578 (Cyber Threat Intelligence), GCIH, GCIA, Security +, Network +, CEH, CISSP, CCNA (Security) or equivalent Certifications.
•Minimum of two (2) years of directly related experience.
•Strong understanding of security monitoring methodologies such as packet capture, patterns, watch lists, black lists, log parsing, correlation, classification, event generation, and filtering.
•Working knowledge of any of the following tools is preferred: Splunk, McAfee ePO, RSA Security Analytics, Wireshark.
•Excellent written and oral communication skills.
•Excellent presentation skills.
•Self-motivated and able to work in an independent manner.
•Candidates must be willing to work a determined shift in a 15/5 shift schedules working Mon-Fri, with shifts between 6:00am to 9:00pm in the SOC operational support environment. Candidate’s shift will be determined based on business needs and current shift openings and may include a requirement to rotate shifts on a periodic basis (e.g. every three months).
Desired Skills & Experience:
•SOC/CSIRT experience.
•Cyber Threat and Intelligence gathering and analysis.
•Network defense environments and Intelligence Community capabilities.
Education and Experience Required:
Requires a Bachelor’s degree in Engineering, Computer Science, or a related field with up to 12 years of relevant experience.
If you are interested in exploring this opportunity, please send your updated resume to shweta.kapoor@cyberradarsystems.com and can call me at (919) 747-3600. ... Show more