Neu Job vor 6 Std. bei Jobleads gefunden
Cyber Incident Handling Analyst
• Wiesbaden, Hessen
SOSi is seeking a Cyber Incident Handling
Analyst to support our customer in Wiesbaden, Germany. The Cyber Incident Handler will perform analytic analysis of cyber related events to detect and deter malicious actors using SIEM technologies, which correlate multiple security tool alerts and logs. Essential Job Duties Work as a member of the Cyber Incident Response Operations Team to increase the security posture of the customers
network. Monitor SIEM platforms for alerts, events, and rules providing insight into malicious activities and/or security posture violations. Review intrusion detection system alerts for anomalies that may pose a threat to the customers network. Identify and investigate vulnerabilities, assess exploit potential and suggest analytics for automation in the SIEM engines. Report events through the incident handling process of creating incident tickets for deeper analysis and triage activities. Coordinates and distributes directives, vulnerability, and threat advisories to identified consumers. Issue triage steps to local touch labor organizations and Army units to mitigate or collect on-site data. Perform post intrusion analysis to determine shortfalls in the incident detection methods. Develop unique queries and rules in the SIEM platforms to further detection for first line cyber defenders. Monitor the status of the intrusion detection system for proper alert reporting and system status. Respond to the higher headquarters on incidents and daily reports. Provide daily updates to Defensive Cyber Operations staff on intrusion detection
operation and trends of events causing incidents. Prepare charts and diagrams to assist in metrics analysis and problem evaluation and submit recommendations for data mining and analytical solutions. Draft reports of vulnerabilities to increase customer situational awareness and improve the customers cyber security posture. Assist all sections of the Defensive Cyber Operations team as required in performing Analysis and other duties as assigned. May perform documentation and vetting of identified vulnerabilities for operational use. May prepare and present technical reports and briefings. Utilize a solid understanding of networking ports and protocols, their uses, and their potential misuses. Minimum Requirements An active in scope Top Secret/ SCI clearance is required. Bachelor in related discipline +3, AS +7, major certification +7 or 11+ [...]