
A Senior Security Analyst is responsible for safeguarding an organization’s computer systems and networks from cyber threats. This role involves identifying vulnerabilities, monitoring suspicious activities, and implementing robust security measures.
Key Responsibilities:
• Security Monitoring & Incident Response:
o Triage security alerts from SIEM, EDR, IDS/IPS, and other security tools.
o Investigate and analyze security incidents to determine the scope, impact, and remediation steps.
o Lead incident response efforts, including containment, eradication, and recovery.
• Threat Hunting & Intelligence:
o Perform proactive threat-hunting activities to identify hidden threats in the environment.
o Analyze threat intelligence and apply findings to enhance detection and response.
o Develop use cases, detection rules, and correlation searches in SIEM.
• Forensics & Malware Analysis:
o Conduct memory, disk, and network forensics to investigate security breaches.
o Analyze malware behavior and reverse engineer threats as needed.
• Security Automation & Optimization:
o Develop and improve security playbooks, scripts, and automation to enhance SOC efficiency.
o Work with SOAR (Security Orchestration, Automation, and Response) to automate responses.
• Compliance & Reporting:
o Ensure adherence to security frameworks (MITRE ATT&CK, MITRE D3FEND, NIST).
o Document and report incidents, investigations, and security improvements.
o Identify, recommend, and implement corrective actions in response to security violations.
o Analyze and configure authentication and access systems to meet security architecture requirements.
Required Skills & Qualifications:
• Experience:
o 3+ years in a SOC, cybersecurity, or incident response role.
o Hands-on experience with SIEM (Splunk, ELK, etc.), EDR, IDS/IPS, and firewalls.
• Technical Skills:
• Strong understanding of network protocols, operating systems (Windows/Linux), and security architectures.
• Proficiency in log analysis (Windows, Sysmon, FW, Audit, WAF), threat intelligence, and attack techniques (MITRE ATT&CK, MITRE D3FEND).
• Experience with scripting (Python, PowerShell, Bash) and security automation.
• Knowledge of cloud security (Azure, Kubernetes) and container security.
• Familiarity with Application Security, including understanding security best practices for software development and deployment.
• Familiarity with threat modeling and risk management frameworks.
• Proven experience with incident response and mitigation of security incidents.
ثبت مشکل و تخلف آگهی
ارسال رزومه برای اسنپ مارکت
مقایسه من با سایر متقاضیان