Source description
About the role
Use the SIEM tool to receive security alerts, perform initial investigations, and provide damage assessments based on findings
Review the latest alerts/events from various sensors to determine relevancy and urgency.
Enrich incidents with open source and/or other sources of information to handle incidents accurately.
Appropriately document all alerts/incidents in the approved ticketing system.
Analyze and elevate as appropriate for IHT2 review.
Preserve evidence integrity according to CSOC standard operating procedures or national standards.
Monitor network activity using cybersecurity tools to protect against malware. (Endpoint protection, restrict/prevent external devices, spam filters, Network access controllers, ACLs)
Recognize and categorize types of vulnerabilities and associated attacks (threat hunting and sharing)
Use CSOC security tools to Identify, capture, contain, and report on malware-related activity
Provide feedback to improve techniques and procedures used for detecting host and network-based intrusions
Use CSOC SOPs/procedures and suggest recommendations to fine-tune these processes to Tier 2 analyst
Handle incident handling tasks from Tier 2 analysts, CSOC manager and leadership
Handle other tasks that a Tier 1 level of experience and talent can complete.
Under supervision, may manage and configure security monitoring tools (SIEM, IDS, Firewall, Access Control Lists, etc.) to mitigate existing threats/vulnerabilities.
More at ARSIEM
Related open roles
Network Based Systems Analyst III
United States · Onsite
Network Based Systems Analyst III
United States · Onsite
Security Specialist
Remote · United States
Incident Manager III
United States · Onsite
382 - Analytic Developer
United States · Onsite
378 - Information System Security Engineer
United States · Onsite
