Senior Insider Threat Security Analyst
Senior Insider Threat Security Analyst
ROLE DESCRIPTION SUMMARY
SES’s Senior Insider Threat Security Analyst focuses on advancing SES’s Information Security threat and compliance program by security monitoring, threat & vulnerability management, and delivering professional reports including findings and recommendations. The Senior Insider Threat Security Analyst is expected to be fully aware of the enterprise’s security goals as established by its stated policies, procedures, and guidelines and to actively work towards upholding those goals.
PRIMARY RESPONSIBILITIES / KEY RESULT AREAS
- Lead incident response in response to Insider security events and incidents.
- Correlation and trend analysis of security logs, network traffic, security alerts, events, and incidents. Perform in-depth root cause analysis and diligently gather information prior to escalation for future root cause analysis. Event and incident handling consistently with applicable plans and processes.
- Analyzing, triaging, aggregating, escalating, and reporting on Insider security events including investigation of anomalous network activity, and responds to cyber incidents within the network environment.
- Continuous & persistent monitoring of security technologies/tool data and network traffic which result in security alerts generated, parsed, triggered, or observed on in-scope networks, systems, or security technologies.
- Rapidly assess network traffic, detect data anomalies, and provide detailed reporting on the same.
- Correlation and trend analysis of security logs, network traffic, security alerts, events, and incidents. Perform in-depth root cause analysis and diligently gather information prior to escalation for future root cause analysis.
- Insider threat event and incident handling consistent with applicable plans and processes. Integration of activities with standard reports, such as Insider security metrics reports.
- Lead team/project meetings and technical meetings appropriate for the content.
- Ensure tasks and projects are completed on schedule.
COMPETENCIES
- Strong organizational skills and ability to stay focused while managing multiple tasks concurrently.
- Understanding of current attack tools, tactics, procedures, and how to detect and/or mitigate them.
- Strong critical thinking/analytical skills, creativity, and a proven drive for quality
QUALIFICATIONS & EXPERIENCE
- Must Have
- Four-year college degree in the technical field of study or equivalent work experience
- Technical knowledge and aptitude in the areas of networks, network topologies, remote network access, servers, applicable software and troubleshooting techniques required.
- Experience working in a SOC or similar environment.
- Experience with reviewing IDS/IPS, EDR, Firewall and other security/audit logs
- Experience monitoring and analyzing Security Information and Event Management (SIEM) to identify security issues for remediation, and rules fine tuning.
- Consolidate and conduct comprehensive analysis of Insider threat data obtained from security tools and make recommendations for optimizing various tools.
- Nice to Have
- Participates in the planning, design, and implementation of enterprise security architecture.
- Experience with Insider threat management tools and experience working on an Insider threat management team.
- One or more of the following security certifications: Security+, CEH, CYSA+, GCIA, GSEC, GCIA, GMON and GCDA
SES and its Affiliated Companies are committed to providing fair and equal employment opportunities to all. We are an Equal Opportunity employer and will consider all qualified applicants for employment without regard to race, color, religion, gender, pregnancy, sex, sexual orientation, gender identity, national origin, age, genetic information, protected veteran status, disability, or any other basis protected by local, state, or federal law.
For more information on SES, click here .
Recommended Jobs
Area Safety Manager
ABOUT GREYSTAR Greystar is a leading, fully integrated global real estate company offering expertise in property management, investment management, development, and construction services in ins…
Full Stack Software Engineer
Threat Tec, LLC, a rapidly growing Veteran-Owned Business, is the leader of Operational Environment (OE) replication and Threat Emulation/Wargaming solutions. Threat Tec brings innovative thinking an…
ServiceNow - Solution Architect for ITSM/HRSD/CSM/Creator
Job Description Job Description Solution Architect – ITSM/HRSD/CSM/Creator Location: Richmond, VA; Atlanta, GA; Remote Veracity by RGP™ is a next-generation consulting firm that delivers…
Stock Associate - Leesburg
Job Description Job Description OUR HERITAGE AND PASSION TO EMPOWER YOUR TALENT AND CREATIVITY Salvatore Ferragamo S.p.A. is the parent Company of the Salvatore Ferragamo Group, one of the wor…
IT Technician 3 with POR (Program of Record) experience and Secret Clearance
Job Description Job Description JOB DESCRIPTION Watershed Security, is a Veteran Owned Small Business with over 20 years Cybersecurity and Government Contracting experience. Watershed is looki…
High Performance Compute (HPC) Engineer TS/SCI CI poly
TENICA is looking to hire High Performance Compute (HPC) engineer Job location: Springfield, VA High Performance Computer (HPC) Engineer -A strong experience with working on Linux systems -Expe…
Senior Business Banker - Greater DC / Northern, VA
Senior Business Banker - Greater DC / Northern, VA The Senior Business Banker plays a critical role in driving the growth and profitability of the bank by generating new deposits, business …
GEOINT Collections Instructor (TS/SCI)
GEOINT Collections Instructor Springfield, VA $85,000 Bring your GEOINT tradecraft and instructional expertise to a role where you can both teach and do, blending tradecraft expertise with ins…
Direct Support Professionals
Job Description Job Description Provide support needs to individuals diagnosed with autism, intellectual and developmental disabilities at home.
Cloud Engineer I - Reston, VA (NO REMOTE)
Short Description: Bowman has an opportunity for a Cloud Engineer I to join our team in Reston, VA. This position is in office in Reston, VA. No remote work possible. At Bowman, we believe in crea…