What are the responsibilities and job description for the Remote Role - Rapid7 InsightIDR & InsightConnect Specialist (SOC Specialist/SOC Analyst) position at Vinsys Information Technology Inc?
Job Description
Job Description
Introduction : We are looking for a skilled and experienced Rapid7 InsightIDR and InsightConnect Specialist to join our Security Operations Center (SOC) team. In this role, you will lead incident response activities, manage SIEM and SOAR tools, and contribute to the overall security strategy by automating workflows and optimizing security operations. If you have hands-on experience with Rapid7 solutions, automation, and orchestration, we want to hear from you!
Key Responsibilities :
- Incident Detection & Response : Lead incident response activities by ensuring rapid detection, analysis, and resolution of security incidents. Provide direct, hands-on support to the SOC team during high-priority events.
- SIEM & SOAR Management : Configure and manage Rapid7 InsightIDR and InsightConnect, including integrating log sources, developing custom parsers, and optimizing correlation rules and use cases for advanced threat detection.
- Threat Analysis : Conduct in-depth analysis of security events to identify and differentiate between successful intrusions, compromises, and false positives. Provide actionable insights to reduce noise and improve threat visibility.
- Automation & Orchestration : Use Ansible, Puppet, Python, and PowerShell to automate repetitive SOC tasks, enhance incident response processes, and increase operational efficiency.
- Configuration Management : Utilize Ansible and Puppet for configuration management, ensuring system consistency and automation across multiple environments.
- Investigation Management : Lead investigations into incidents escalated by Level 1 analysts, ensuring thorough documentation and efficient resolution of issues.
- Quick Mitigation Techniques : Implement temporary defensive measures and response actions until permanent solutions are deployed.
- Security Enhancements : Develop, maintain, and refine playbooks in Rapid7 InsightConnect to orchestrate and automate SOC processes, improving response times and operational efficiency.
- Gap Analysis & Recommendations : Identify gaps within the security infrastructure and recommend strategies for risk mitigation, continuous improvement, and enhanced security posture.
- Vulnerability Awareness : Stay updated on the latest vulnerabilities, threat advisories, and penetration techniques, actively contributing to proactive defense measures against emerging threats.
Desired Skills & Qualifications :
Preferred Qualifications :
Why Join Us? :