Principal Duties and Responsibilities:
- Provide timely detection, identification and alerting of possible attacks, anomalous activities and misuse activities and distinguish them from benign activities.
- Use cyber defense tools to monitor and analyze system activity continuously to identify malicious activity.
- Assess the adequacy of access controls against organizational policies.
- Perform system administration on specialized cybersecurity applications and systems.
- Triage incidents to identify specific vulnerability, determine scope, urgency and potential impact, make recommendations that enable expeditious remediation.
- Track and document cyber incidents from initial detection to final resolution.
- Employ defense-in-depth principles and practices in line with organizational policies.
- Coordinate, validate and manage the organization's cyber threat intelligence sources and feeds.
- Capture and analyze network traffic associated with malicious activities using network monitoring tools
Key Accountabilities:
- Carry out daily operations assigned for the department to comply with the company s standards.
- Prepare timely and accurate department reports to meet the requirements, objectives, and standards of the company and the department.
- Ensure the satisfaction of internal and external customers to address their needs in a courteous and timely manner.
- Follow all relevant policies, procedures, and processes in order for the work to be carried out in a controlled and consistent manner.
- Contribute to the identification of opportunities for continuous improvement of processes and practices, work processes, cost effectiveness, and productivity enhancement.
- Promote to other employees within the organization the implementation and adherence to policies, procedures, processes, and instructions.
- Maintain a good and respectful relationship with other colleagues and represent the company in a good image.
Education and Certifications:
- Bachelor s degree in Information Technology, Computer Science, or equivalent is required
- Master s degree in Information Technology, Computer Science, or equivalent is preferred
- Certified Information Systems Security Professional (CISSP) certificate or equivalent is preferred
Knowledge and Experience:
- 6 + years of experience in Cybersecurity Operations is required.
- Knowledge of network components, their operation and appropriate network security controls and methods
- Knowledge of cybersecurity related threats and vulnerabilities
- Knowledge of the likely operational impact on an organization of cybersecurity breaches
- Knowledge of best practices for incident response and incident management
- Knowledge of host-based and network-based intrusion detection methodologies and techniques
- Knowledge of best practice network traffic analysis methods
- Knowledge of the components of a network attack and their relationship to threats and vulnerabilities
- Knowledge of best practice incident response methods, roles and responsibilities
Skills Required:
- Skill in determining the normal operational state for security systems and how that state is affected by change
- Skill in developing policies which reflect the organization's business and cybersecurity strategic objectives.
- Skill in evaluating the viability and legitimacy of suppliers and products.
- Skill in negotiating vendor agreements