Padmi
ARSIEM logo
ARSIEM

Microsoft 365 development · Power Platform and SharePoint

Incident Handler Tier I

United States · Onsite$82k–$91k/yrPosted 30 months ago
SecurityJuniorFull Time
Apply at ARSIEM

Opens the source posting on jobs.lever.co

Source description

About the role

View original

Use the SIEM tool to receive security alerts, perform initial investigations, and provide damage assessments based on findings

Review the latest alerts/events from various sensors to determine relevancy and urgency.

Enrich incidents with open source and/or other sources of information to handle incidents accurately.

Appropriately document all alerts/incidents in the approved ticketing system.

Analyze and elevate as appropriate for IHT2 review.

Preserve evidence integrity according to CSOC standard operating procedures or national standards.

Monitor network activity using cybersecurity tools to protect against malware. (Endpoint protection, restrict/prevent external devices, spam filters, Network access controllers, ACLs)

Recognize and categorize types of vulnerabilities and associated attacks (threat hunting and sharing)

Use CSOC security tools to Identify, capture, contain, and report on malware-related activity

Provide feedback to improve techniques and procedures used for detecting host and network-based intrusions

Use CSOC SOPs/procedures and suggest recommendations to fine-tune these processes to Tier 2 analyst

Handle incident handling tasks from Tier 2 analysts, CSOC manager and leadership

Handle other tasks that a Tier 1 level of experience and talent can complete.

Under supervision, may manage and configure security monitoring tools (SIEM, IDS, Firewall, Access Control Lists, etc.) to mitigate existing threats/vulnerabilities.

More at ARSIEM

Related open roles

View all roles