IT Security AnalystReporting to the IT Security Manager the IT Security Analyst is a position based in North CarolinaResponsibilitiesHands on experience on security testing tools such as Burp Suite Mimikatz Cobalt Strike PowerSploit Metasploit Qualys Web Inspect or other tools included within the Kali Linux distributionExperience in security assessment activities within a clients environment emphasizing manual stealthy testing techniques using commercially freely available offensive security tools and utilities built into operating systemsWork closely with technical teams to assess the security posture of systems and applications through vulnerability assessments and penetration testingGood understanding of cloud technologies and its security best practicesFinetune WAF policies and configurations to optimize security while minimizing false positivesConfigure deploy and maintain Web Application Firewalls WAF in production and development environmentsCoordinating investigations and reporting of security incidents related to Network Systems and applicationsCoordinate and execute IT security projects for Arista at multiple locationsEngage in security research in keeping abreast of the latest security issues for Cloud enabled enterprises including SAAS and IAASMonitoring system compliance with the IT framework for controls and levels of access recommending improvementsCollaborate with other groups inside Arista to manage security vulnerabilities and help manage risksAdminister security dedicated systems Software Firewall management EDR NDR log collection reporting analytics Cloud Security consoles as appropriateExperience with CSPM tools such as WIZLacework Google Security Command CenterTerraform CloudFormation Forseti and other similar tools experience is highly desiredConduct and collaborate on laptop and server forensics as well as Cloud Service Provider forensics with the global security teamPerform other related duties as assignedQualificationsBA or BSc in Computer Science Management Information Systems Information Assurance or related fieldAdvanced degree desirableMust have 6 years of progressive experience in computing and information securityKnowledge of common adversary tactics and techniques eg obfuscation persistence defense evasion etcKnowledge of Mitre ATTCK framework preferredGood knowledge of security fundamentals Networking protocols TCPIP stack systems architecture and operating systemsMust have practical experience in Privacy Controls and implementing them in a corporate environmentExpert knowledge is desired of laptop operating systems MacOS Windows and LinuxProven project management experience a bonus specifically experience in managing remote office configuration and bringing up and working with remote offsite vendorsExperience working in a large cloud or Internet software companyBusiness Application security analysis and practical experience is a plus eg SFDC NS SiSenseCISSP GIAC or other security certifications desiredKnowledge of information security standards eg ISO etc rules and regulations related to information security and data confidentiality eg FERPA HIPAA etc and desktop server application database network security principles for risk identification and analysisThis position requires some weekend and evening assignments as well as availability during offhours for participation in scheduled and unscheduled activities