What are the responsibilities and job description for the Senior SOC Analyst position at h3 Technologies?
Title : Senior SOC Analyst
Location : 2 Broadway, NY (Hybrid 3 days a week onsite)
Duration : 6 Months contract
One of 3 shifts a day in a 24 / 7 operation (
- consultant needs to be flexible enough to fill any of the 3 shifts as needed) :
Shift 1 = 12am - 8 : 30am
Shift 2 = 8am - 4 : 30pm
Shift 3 = 3 : 30pm - 12am
SUMMARY OF THE FUNCTION / ROLE :
The IT Cyber Security Operations Monitoring Team is seeking consultants to perform Tier 2 SOC follow-up and remediation activity on escalated incidents. The Tier 2 level Analyst (Senior Analyst) should have the ability to respond to a wide range of escalated Incidents and follow through with incident lifecycle through completion. Some of the areas we are looking for candidates to have experience in include but are not limited to :
Critical Key requirements :
RESPONSIBILITIES :
a. SIEM : The ability to conduct correlated searches and analysis utilizing a Security Incident & Event Management system.
b. Network : The ability to Analyze and dissect packets and validate threat signatures
c. Endpoint : Ability to perform basic static forensic analysis of Systems and Files
d. Email : Demonstrated ability to analyze email attributes such as Headers, and the ability to apply appropriate countermeasures to enhance email defense
e. Cloud : The ability to analyze anomalous detected traffic based on defined attack policies, ability to validate the treat and then determine remediation steps and present findings)
f. User & Entity Behavior Analytics : demonstrated capability to recognize and respond to various anomalous patterns of User's and Entity's activity to detect malicious intent.
g. Web Application : familiarity with various types of code-based attacks and the ability to detect and respond to them
h. Data Loss Prevention : Demonstrated capability to analyze DLP events and the ability to detect Data exfiltration through covert channels.
i. Document As-Is and To-Be playbooks for existing and future processe.
j. Coordinate and facilitate meetings such as process reviews, requirements, and various status reports
QUALIFICATIONS EXPERIENCE & EDUCATION :
Additional Skills and Information :
Security Event Monitoring, Network Event monitoring, Email Header Analysis, Packet Capture inspection, Malware Triage & Analysis, SIEM (Splunk) & TIP Experience