Job Details

ID #12215756
State Texas
City Plano
Job type Contract
Salary USD Depends on Experience Depends on Experience
Source Sensiple Inc.
Showed 2021-04-14
Date 2021-04-13
Deadline 2021-06-12
Category Et cetera
Create resume

Hiring - Incident Detection Specialist - Position

Texas, Plano, 75023 Plano USA

Vacancy expired!

Sensiple Inc., service offerings include contingent Staff Augmentation of IT professionals, Permanent Recruiting and Temp-to-Hire. In addition, our industry expertise and knowledge within financial services, Insurance, Telecom, Manufacturing, Technology, Media and Entertainment, Pharmaceutical, Health Care and service industries ensures our services are customized to meet specific needs. For more details please visit our website:We have been retained for providing recruiting assistance, for direct hires, by one of the world-leading information technology consulting, services, and business process outsourcing organization that envisioned and pioneered the adoption of the flexible global business practices that today enable companies to operate more efficiently and produce more value.Sensiple, Inc. is an Equal Opportunity Employer and all qualified applicants will receive consideration for employment without regard to gender, race, color, religion, sex, national origin, veteran or disability statusOur client is looking for an

Incident Detection

in Plano TX. This is a Contract to Hire role. Please find below the details of the position.

Job DescriptionPosition Title:

Incident DetectionLocation :

Plano TXLength: Contract

Role:
  • Conducts Event Detection, Incident Triage, Incident. Handling, Hunting activities by leveraging our detection/response platforms
  • Continuously monitors levels of service as well as interpret and prioritize threats through use of cyber threat intelligence, intrusion detection systems, firewalls and other boundary protection devices, and any security incident management products deployed
  • Provide 24x7 incident detection and monitoring service, and performance report on regular basis
  • Escalates cyber security events according to playbook and standard operation procedures (SOPs).
  • Remediate non-compliance with technical and security requirements.
  • Escalates high or critical severity level incidents to Incident Investigators.
  • Assists with containment of threats and remediation of environment during or after an incident
  • Performs triage of service requests from customers and internal teams
  • Develop and implement remediation plans in response to incidents
  • Updates procedures and configure tools for Monitoring Analysts consumption
  • Consumes threat intelligence and disseminate findings to relevant parties
  • Conducts hunting activities based on internal and external threat intelligence
  • Integration of additional supported log source/device and development of new use cases as required

MINIMUM QUALIFICATION
  • Has to be flexible and be available for the various shift (our day shift is: 6am to 6pm, and the night shift is: 6pm to 6am as we run 24/7 SOC operation, and that includes on weekends as well. It will be 2 days off then 2-3 days on. Day and night shift would rotate every few months.)
  • 8+ years cyber security experience required
  • 3+ years of experience in incident response handling
  • BA/BS in Engineering, Computer Science, Information Security, or Information Systems or related work experience
  • 2+ years of experience using event escalation and reporting procedures, managing security alerts within enterprise SIEM systems, and performing network monitoring in a Cyber SecurityOperations environment
  • Working knowledge of security technologies such as Active Directory, anti-malware tools, forensics tools, firewalls, identity access management, IDS / IPS, multi-factor authentication, network devices, SIEM, threat intelligence, vulnerability scanners, monitoring tools, and web filters on premise and in cloud environments required
  • Demonstrated analytical, problem-solving, and critical thinking skills required
  • Ability to work with little supervision and consistently deliver results required
  • Familiarity with network technologies and protocols (switches, routers, firewalls, VPNs, remote connection technologies, and multiple domain environments) strongly preferred

PREFFERED QUALIFICATION
  • Experience with Splunk and other SIEM platforms, Enterprise Intrusion Prevention Systems, Endpoint Detection tools, and other security products
  • Experience conducting incident handling and response efforts in large enterprise environments
  • Experience supporting incident investigations
  • Experience working in a 24/7 SOC environment
  • Security certifications (e.g. Security+, Network+, CEH, SANS etc.)
View Less

SkillsSPLUNK, INCIDENT HANDLING, SIEM, INCIDENT RESPONSE, SOC, MALWARE DETECTIONIf you find yourself suitable for this position, kindly send your updated resume and expected hourly rate to or reach us @ Ext 551ThanksPriyaLead AssociateSensiple Inc. (F.k.a EPro Inc) PhExt: 551

Vacancy expired!

Subscribe Report job