Your Role:
The Information Security Analyst will participate in security-related projects and initiatives. The Analyst will assist with risk analysis and assessments on existing and proposed systems, document and report on key metrics and objectives, monitor and analyze security technologies such as IDS, IPS, Firewalls, Anti-Malware and provide security-related guidance and support. They will also monitor and analyze security events, learn about new security tools and take ownership of day-to-day security operations.
Your Opportunity:
Analyze and investigate events from Cybersecurity appliances or reported incidents
Document standard operating procedures matching day-to-day InfoSec operations
Establish and maintain strong working relationship with all team members and all business units
Take part in new vulnerability detection and remediation efforts across the enterprise
Assist engineering group in evaluating and deploying new solutions
Perform day-to-day analysis of logs to detect anomalies or events that could lead to incidents
Use threat intelligence to develop new detections and preventative measures across the enterprise
Responding swiftly and effectively to potential security incidents reported to InfoSec
Flexible and adaptive to changing situations in relation to incident handling
Communications skills with individuals of varying technical skills
Promote security awareness throughout the organization
Perform other duties as assigned
What You'll Need:
Able to work hybrid/onsite location at HQ in Columbia MD
BA/BS in Computer Science, Information Technology, SANS training or equivalent experience
Self-motivated while demonstrating a passion for Cybersecurity
Ability to work independently with minimal supervision in a highly controlled and sensitive environment
1-4 of experience in Information Security
Familiar with Cloud Security Alliance and SANS top 20 critical controls
Must have strong communication and teamwork skills
Perficient in technical writing. Mainly for SOPs, ticket annotations, and generating reports
Understand how to read and apply threat intelligence, both indicators and techniques
Understanding of Cloud Security, including how to identify attacks and what controls prevent those attacks
Understand how to use a SIEM to find attacks, tune out noise, and build security visibility into the environment.
Knowledge of different attack vectors such as endpoint compromise, web application attacks, and phishing.
A desire to learn continuously, and a strong interest in cybersecurity best practices
Ability to automate using Python, Powershell, Perl or similar.
Familiarity with Anti-Virus, Firewalls, IDS/IPS, NAC, WAS, Tenable products, Splunk, SIEM, OSI model and CIA triad
Familiar with LINUX/UNIX/Windows/Powershell command line
#LI-MM1
#LI-Hybrid