L2 SOC Analyst

L2 SOC Analyst

14 May 2024
North Carolina, Greensboro, 27401 Greensboro USA

L2 SOC Analyst

Job DescriptionInsight Global's client is seeking a SOC Tier II Analyst to be responsible for monitoring, analysis, response, and escalation of security incidents and events. The Security Operations Center is the first line of detection and defense which actively monitors the SIEM (Security Information & Event Management), reviews log and event data, and works tickets associated with said data. Providing research using internal and open source tools, resolving and escalating incidents using established policies and procedures.How You Will Make a Difference: Monitoring and analysis of logs, alerts, and external data sources to determine any security and/or operational impact to the organization. Performs research on security events and threat intelligence data using internal and open source tool. Performing proactive threat research and validation for security event data generated from monitoring tools and/or manual analysis. Creation of Reference Sets within the SIEM tool to assist Tier 1 SOC Analysts with threat research. Monitoring IPS (Intrusion Prevention System) events and performing analysis on the data providing recommended actions or escalating to incident analysts for further review. Trains all new SOC Tier I Analysts in the usage or all security tools and the execution of all SOC procedures. Acts as an escalation point for the Tier I SOC Analysts. Resolves or escalates cyber security incidents and events as part of the established policies and procedures. Assists with the containment of threats and remediation of the environment during or following an incident. Collaborates with technical teams to identify, resolve, and mitigate security events as part of the Incident Response Plan. Evaluates unwarranted changes within the environment as part of monitoring rules within the SIEM tool. Creates and executes SOC compliance reports as necessary for risk and compliance teams. Monitors SIEM environment for Global organization, providing resolution to events and incidents triggered within the SIEM tool as part of the day to day operations. Ensures that critical infrastructure is reporting into the SIEM and reports any systems that are not reporting to the appropriate team/s. Performs documentation of event analysis and records this data within our Incident Tracking tool. Ensuring all relevant data is captured within each incident. Assists with the triage of service requests from internal teams within the organization through our incident ticketing system. Enhances detections, alerts, and other cyber event correlation rules within the SIEM to reduce false positives. Approves various block requests originated by the Tier I SOC Analysts. Manages the SOC documentation repository by providing oversight of the annual SOC Documentation review process. Provides recommendations for procedural updates and improvements. Reviews recommendations proposed by Tier I SOC Analysts. Represent the Security Operations team in various SOC, Incident Response, and Cyber Security projects.We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com .   To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/ .Skills and RequirementsEducational Requirements: A bachelor's degree in computer science, information systems or other related field (preferred); or equivalent work experience.Years of Related Professional Experience: 3+ yearsPosition Requirements: Experience executing security incident handling processes and procedures. Working knowledge of Networking fundamentals including but not limited to; The OSI Model, TCP/IP, DNS (Domain Name System), HTTP, SMTP), System Administration and/or Architecture. Proficient understanding of various Operating Systems and their architectures: Windows, Unix/Linux and OSx. Previous experience operating and tuning SIEM tools, IBM QRadar experience preferred. Effective communication skills with the ability to work in a highly collaborative environment across many different disciplines. Strong relationship skills and collaborative style to enable success across multiple business partners with a focus on building partnerships. Excellent analytical and problem-solving skills. Professional security management certifications such as; Global Information Assurance Certification (GIAC) certifications such as GCIA, GCIH, Certified Information Systems Security Professional (CISSP) or other similar credentials are a plus. nullWe are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion,sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military oruniformed service member status, or any other status or characteristic protected by applicable laws, regulations, andordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to HR@insightglobal.com.

Related jobs

  • As part of the Global Compensation Team, the primary purpose of this position is to support various reoccurring and annual processes that assure external competitiveness and internal equity of our management, professional and hourly employees, thereby helping to assure that the best employees are attracted, retained and motivated by our compensation systems.

  • Description We are seeking a Financial Analyst for our manufacturing operations in Greensboro, North Carolina. This role involves processing customer credit applications, maintaining accurate customer credit records, and resolving customer credit inquiries. In addition, the candidate will be expected to monitor customer credit accounts and take appropriate action to collect delinquent payments.

Job Details

Jocancy Online Job Portal by jobSearchi.