Unknown Company

Senior Information Security Analyst

fort worth, tx • Posted 6 days ago
Onsite Full Time General

Information Security ProfessionalRequirements:10 or more years of full-time professional experience in the Information Security fieldExperience working in a Security Operations Center (SOC), Managed Security Service (MSS), or enterprise network environment.Investigate events and incidents to gather evidence and analyze in a comprehensive, consistent, and measurable manner.Evaluate, respond, and mitigate alerts that originate from the SIEM and other security tools.Hunt for suspicious and malicious threats within the environment.Identify common false positives and make suggestions on tuning to reduce alert-fatigue.Join forces with the internal Security Incident Response Team (SIRT) during investigations.Author investigation reports for technical and non-technical audienceQualifications:Queue managementExperience with SIEM platforms preferredFamiliarity with web-based attacks and the OWASP Top 10 at a minimumAttack vectors and exploitationDirect (E.g. SQL Injection) versus indirect (E.g. cross-site scripting) attacksFamiliarity with SANS top 20 critical security controlsUnderstand the foundations of enterprise Windows security including:Active DirectoryWindows security architecture and terminologyPrivilege escalation techniquesCommon mitigation controls and system hardeningExperience monitoring EDR, Anti-Virus (AV) and Host Based Intrusion Prevention (HIPS)Experience in monitoring at least one commercial AV solutionAbility to identify common false positives and make suggestions on tuningUnderstanding of root causes of malware and proactive mitigationPropagation of malware in enterprise environmentsFamiliarity with web-based exploit kits and the methods employed by web-based exploit kitsFamiliarity with concepts associated with Advanced Persistent Threats and “targeted malware”Understanding of malware mitigation controls in an enterprise environment.Network Based Attacks / System Based AttacksDenial of Service AttacksHTTP Based DoS AttacksNetwork Based DoS AttacksBrute force attacksCovert channels, egress, and data exfiltration techniquesDesired Qualifications:Experience working with Incident Ticketing SystemsGeneral security knowledge (GCIA, CISSP or other security certifications)

Back to Job Search