
Information Security Analyst
Mondelēz International
full-time
Posted on:
Location Type: Remote
Location: Philippines
Visit company websiteExplore more
About the role
- Contribute measurably to goals of enhancing our security posture and protecting MDLZ infrastructure
- Be adept at technical writing
- Capable of communicating with both technical and nontechnical stakeholders across all levels including C-suite with ability to scope, tailor, and triage information shared to the roles and business priorities of audiences
- Contribute to comprehensive containment, eradication, and recovery strategies, prioritizing business continuity and minimizing disruption to business processes.
- Help to coordinate response activities with incident response teams, internal stakeholders, and external partners.
- Follow established and best-practice incident response procedures while iterating as necessary for novel events.
- Collaborate closely with a wide range of technical and non-technical teams across business functions and geographies.
- Assist with scoping, tailoring, and triaging of event/incident information for diverse audiences, including C-suite executives, providing clear, concise, and timely updates.
- Contribute to in-depth malware analysis, network forensics, log analysis, and reverse engineering to identify root causes, establish timelines, and uncover Indicators of Compromise (IOCs) and Tactics, Techniques, and Procedures (TTPs) both independently and in partnership with security, technology, and business roles.
- Contribute to the continuous review, refinement, and expansion of incident response playbooks, runbooks, and Standard Operating Procedures (SOPs), aligning them with industry best practices (e.g., NIST, MITRE) and our unique global context.
- Embody a passion for growth and a drive for continuous learning
- Act as a peer and partner with other analysts, contributing to the overall uplift of our global cybersecurity capabilities through effective teamwork.
- Contribute to "lessons learned" reviews for significant incidents, identifying systemic weaknesses and assisting with generation of recommendations for security control improvements, architectural enhancements, and organizational changes to prevent recurrence.
- Contribute to team’s expansive skill set and work to expand your own skills across topics like reverse-engineering, cloud security, process development, scripting in Python, PowerShell, Bash, C/C++, ICS protocols, AI-based automation, and more
- Monitor computer environments for security issues
- Perform Threat Analysis on events reported by security tools, external parties, and internal SMEs
- Assist team with investigation of security breaches and other cybersecurity events and incidents
- Contribute to Root Cause Analysis, Lessons Learned, and Corrective Action Reporting
- Contribute to executive summaries, status reports and supply metrics to relevant stakeholders
- Participate in special projects as needed
Requirements
- Bachelor’s Degree in Information Technology, Cybersecurity, Computer Science or similar.
- Hold professional certifications through certifying bodies like: CompTIA: Security+, CySA + SANS-GIAC: GCIH, GDAT, GPEN, GCFE, GRID ISC2: CISSP Offsec: OCSP, OSIR
- 3-6+ years experience in Incident Response, Information Security, SOC, Forensics, Purple-teaming, or related field
- Knowledge/Experience in: SIEM (ie Splunk, Humio), SOAR (ie Cyware, Splunk, XSOAR), Endpoint Security (EDR) (ie CarbonBlack, Crowdstrike, Defender), Email Security (ie Proof point, O365 ATP), Firewalls, WAF, IDS/IPS, Web Content Filtering, Proxies, Database, Data Loss Prevention (DLP), Identity and Access Management (IAM), Cloud Computing Services, Scripting, MITRE ATT&CK Framework and Incident Response, NIST, Cloud Compute (ie AWS, GCP, Azure), Cloud Native Application Protection (ie Forcepoint ONE, Wiz, Orca)
Benefits
- 📊 Check your resume score for this job Improve your chances of getting an interview by checking your resume score before you apply. Check Resume Score
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
malware analysisnetwork forensicslog analysisreverse engineeringincident responsethreat analysisscriptingcloud securityroot cause analysisdata loss prevention
Soft Skills
technical writingcommunicationteamworkproblem-solvingadaptabilityorganizational skillsstakeholder engagementcontinuous learningcollaborationcritical thinking
Certifications
CompTIA Security+CySA+GCIHGDATGPENGCFEGRIDCISSPOCSPOSIR