Job Code | : | 12261 |
Experience | : | 3-5 Years |
Location | : | Costa Rica |
We are looking for a Senior SOC Analyst with hands on experience security tools such as end point protection/EDR, SIEM, IPS/IDS, HIDS/NIDS, WAFs, Edge/DNS security, vulnerability scanning, malware analysis tools, networking tool for full packet analysis, data loss prevention (DLP)
• Monitor our alert channels, SIEM/SOAR notifications and EDR/IDS/IPS solutions for detections/incidents and threat hunt for malicious activity.
• Investigate, contain, triage and mitigate as needed; as well as continuously tune rules to reduce false positives.
• Provide incident response and be a key point of contact during all incidents; which includes investigation, correlation, triage, response, mitigation, ticketing, documentation and postmortem analyses.
• Work an alert from start to finish, including any containment, investigation and mitigative actions needed.
• Assist in the tuning of EDR/IDS/IPS solutions to improve detection, reduce noise, add IOAs, etc.
• Work with the security engineering team to improve tool usage and workflows, as well mature monitoring and response capabilities.
• Work with developers on the InfoSec team to build security automation workflows, enrichments and mitigations.
• Evaluate SOC policies and procedures and recommend updates to management where appropriate.
• Grow and mature our threat intelligence program – gather, analyze and assess threat intelligence to report on the current and future threat landscape, and provide a realistic overview of risks and threats in the enterprise environment.
• Enhance our detection capabilities with correlation, situational awareness and intel enrichment.
• Proficient operator of security tools such as end point protection/EDR, SIEM, IPS/IDS, HIDS/NIDS, WAFs, Edge/DNS security, vulnerability scanning, malware analysis tools, networking tool for full packet analysis, data loss prevention (DLP), etc.
• Following certifications: CEH, CISM, GIAC, GCIH, GCIA, GSLC, GICSP, GSEC, CEH, GWAP, CompTIA Net+, CompTIA A+, CompTIA Security+, CASP CE, SEC+, Splunk Core, OSCP, etc.
• Linux/Unix OS, Windows and Mac administration skills
• Intimate understanding of technology and be motivated to constantly learn new technologies.
• Strong ability to learn and research new things, including tools, languages, frameworks, etc.
• Excellent verbal and written communication skills
• Collaborative mindset that thrives in fast paced environment
• Programming/scripting experience (bash, python, PowerShell) good to have
• Forensics or malware analysis experience is good to have.