Security Operations Analyst
Trigyn has a contractual opportunity for a Security Operations Analyst. This resource will be working Remotely.
Job Description:
The incumbent will work under the supervision and guidance of the Head of Cyber Security
Operations to provide front-line support to client Partners in the area of information/cyber
security, risk management consulting, and security operations activities in collaboration with a team of information and cybersecurity experts.
The resource will be part of the 24x7 Security Operations Centre (CSOC) and will work in close collaboration with team members distributed around the globe to monitor, detect, triage, investigate and respond to cyber threats targeting its Clients and Partner Organizations.
Scope of Work / Duties of Consultant:
• Monitor and investigate alerts leveraging Microsoft Security Tools (e.g. M365, Cloud App
Security, Azure, Defender for Endpoint, Azure Security, Azure Sentinel and XDR)
• Monitor and triage AWS security events and detections
• Monitor and investigate alerts leveraging EDR and NDR solutions
Review security events that are populated in a Security Information and Event Management (SIEM) system
• Analyze a variety of network and host-based security appliance logs (Firewalls, NIDS, HIDS, Sys Logs, etc.) to determine the correct remediation actions and escalation paths for each incident
• Identify the incident root cause and take proactive mitigation steps
• Assist with incident response efforts
• Follows precise analytical paths to determine the nature and extent of problems being reported by tools, e-mails, alerts, etc.
• Integrate and share information with other analysts and other teams
• Determine and direct remediation and recovery efforts.
• Provide other ad hoc support as required
Required Technical Skills:
The resource MUST have the following skills and experience:
• Knowledge of Transmission Control Protocol / Internet Protocol (TCP/IP) protocols
• Deep knowledge of Microsoft Security Tools (e.g. M365, Cloud App Security, Azure, Defender for Endpoints, Azure Security, Azure Sentinel and XDR)
• Deep Knowledge of Cloud technologies (e.g. Azure, AWS and GCP)
• Deep knowledge of SIEM tools like Splunk, QRadar, ArcSight, MS Sentinel, ELK Stack
• Knowledge of at least one EDR solution (MS Defender for Endpoint, SentinelOne, CrowdStrike)
• Knowledge of email security, network monitoring, and incident response
• Knowledge of Linux/Mac/Windows;
• A minimum of five (5) years of relevant experience in the information technology field, including triage of alerts and supporting security incidents
• Proven experience with the usual toolbox available in a SOC (e.g., SIEMs, EDRs), able to autonomously perform technical analysis of security threats and collaborate with the Incident Response team
• Trouble ticket generation and processing experience
• Extensive Windows, Linux, Database, Application, Web server, etc. log analysis
• Expert knowledge of English, both written and spoken, is required
The resource SHOULD have the following skills and experience:
• Experience on an Incident Response team performing Tier I/II initial incident triage.
• Proven knowledge of monitoring AWS environment (IaaS, Saas, Paas)
• Knowledge of at least one general-purpose or shell scripting language (e.g. Ruby, Bash, PowerShell, Python, etc.)
Required Soft Skills:
• Excellent communication skills
• Customer-facing experience and oral communication skills
Ability to write documentation & reports
• Creativity/ ability to find innovative solutions
• Willingness to learn on the job
• Conflict management & cooperation
Desirable certifications:
• Technical certifications: MCSE, CCNA, Microsoft Azure (e.g., SC-200), GCIH, CEH, GCFA or any GIAC/similar certification
• Relevant industry certifications
Recommended Jobs
CDL A Truck Driver - Home Nightly
Oldcastle® APG, a CRH Company, is North America’s leading provider of innovative outdoor living solutions that enable customers to Live Well Outside. The manufacturer’s portfolio of premier bui…
Fleet Maintenance Mechanic
At East End Group we specialize in all aspects of building services, including general contracting, construction, facility management and utility work. We pride ourselves on our dynamic environment w…
Senior Rust Developer
Mastech Digital provides digital and mainstream technology staff as well as Digital Transformation Services for all American Corporations. We are currently seeking a Senior Rust Developer for o…
Automotive Finance Manager
Automotive Finance / Business Manager Top finance position for qualified candidate with a proven track record in the automotive industry. Commission, salary and excellent benefits package. Job …
Calling All Local Arts & Crafts, Clay, or STEAM Teachers! (Princeton)
About Togetherhood At Togetherhood, we're building something special: a vibrant marketplace where passionate educators meet schools and communities hungry for enrichment. Whether it's arts & craft…
Sales Representative
We are looking for a motivated Field Sales Representative to join our team at Graphic Makers & Printers . This person will be responsible for visiting local businesses, delivering brochures, samp…
Driver Lead - Manville School District
Job Description The Lead Dispatcher is a crucial support operations position with ultimate responsibility of each shuttle run being optimally scheduled and operated every single day. The Lead Disp…
Litigation Legal Secretary
Job Description Job Description Top law firm working for wonderful attorneys. Staff is warm and welcoming. Partner has a great sense of humor. Attorneys are a team of strong communicators and col…
Power Platform Developer
Design, build, and implement robust Power Apps (Canvas and Model-driven), Power Automate flows. Ensure that designs are scalable, secure, and efficient. Lead end-to-end solution developmentfrom re…
Director Rates and Regulatory
Share Our Purpose. Be Yourself. Feel Valued. People are the heart of our business. As an American Water employee, you will be offered a competitive salary and health benefits package, along with oppo…