Logo
Allen Rose Group

Senior Cyber Security Ops Center Analyst

Allen Rose Group, New Haven, Connecticut, us, 06540


Job DescriptionWe are conducting a search for a Senior Security Operations Center (SOC) Analyst. The Sr. SOC Analyst will be responsible for the identification, quantification and reporting of cyber threats to the organization.Position Responsibilities (including but not limited to): Establish a baseline risk posture, identify current and future threats and recommend remedial actions Provide day to day management of SOC analyst and associated activity. Work as part of a 24/7/365 team delivering real time proactive monitoring and maintenance of supported security tools and associated rules and signatures. Tools include but are not limited to, SIEM, NIDS/NIPS, HIDS/HIPS, Endpoint protection suites, DLP. Maintain and grow the value of current and future partner relationships. Produce and maintain operational processes and procedures for use by all shift personnel. Carry out Triage on Security events, raise incidents and support the Incident Management process. Create and maintain SIEM correlation rules, signature creation for supported NIDS/NIPS, HIDS/ HIPS and Endpoint Protection products. Work within current change management processes to apply patches, provide 1st line support for supported Security tools. Remain up to date with current attack methods and characteristics to identify threats and advice on prevention, mitigation and remediation. Knowledge & Experience Required: Demonstrate experience of risk identification and remediation within a global SOC environment. In depth knowledge of two or more of the following: SIEM, NIDS/NIPS, Endpoint Security toolsets, DLP, Network security technologies. SCADA /ICS environments. Demonstrate in depth knowledge of desktop and server operating systems and associated log analysis. Demonstrate in depth knowledge of network packet analysis Experience of Security Incident Management processes. Demonstrate ability to formulate formal processes and procedures to support SOC operations. Experience of developing SIEM correlation rules and snort signatures. Degree level or demonstrable equivalent experience. GIAC/CEH