Tech Stack
CloudCyber SecuritySpring
About the role
- Oversee monitoring of security alerts and events from various security tools and partners (e.g., SIEM, GuardDuty, MSSP).
- Conduct advanced analysis of security events to identify and mitigate potential threats.
- Provide guidance and support to junior analysts in their investigations.
- Lead the response to complex security incidents, including identification, containment, eradication, and recovery.
- Conduct root cause analysis and develop remediation plans.
- Document incident details and maintain comprehensive incident response records.
- Lead the integration of threat intelligence into security operations processes and provide threat intelligence insights to improve security posture.
- Stay updated on advanced threat landscapes and emerging security threats.
- Oversee management, optimization, deployment, and configuration of security tools and technologies used within security operations.
- Evaluate and recommend new security technologies and solutions.
- Maintain detailed documentation, prepare regular reports on security activities, incidents, and metrics for management.
- Develop and maintain security operations procedures and playbooks.
- Mentor and train junior security analysts; lead security operations team meetings and provide regular feedback.
- Develop and implement training programs to enhance analysts' skills and collaborate with other teams to integrate cybersecurity best practices.
Requirements
- Bachelor’s degree in Information Security, Cybersecurity, Information Technology or equivalent education.
- In lieu of a degree, minimum of 7 years of work related experience.
- Minimum of 5-7 years of experience in security operations or related fields.
- Extensive hands-on experience with security tools and technologies.
- Proven experience in leading and managing security operations teams is plus.
- Certifications preferred: CompTIA Security+, Certified Ethical Hacker (CEH), Certified Cloud Security Professional (CCSP), Certified Information Systems Security Professional (CISSP).
- Ability to work in a fast-paced and dynamic environment.
- Remote - US Only (must be located in the United States).