Soc Level I
Noc Smart Inc
Gaithersburg, Maryland, United States
• Perform Intrusion Detection System or Incident Response Team monitoring (IDS or IRT)Conduct network vulnerability assessments using tools to evaluate attack vectors, identify system vulnerabilities and develop remediation plans and security procedures.• Monitoring and analysis, analyze network traffic, log analysis, prioritize and differentiate between potential intrusion attempts and false alarms Familiarity with security test tools and responding to security findings.• Assess network activity and system configuration for anomalous activity to determine system security status Responsible for applying security updates and patches on servers, desktops, and laptops• Performed desktop support, server configuration and hardening.• Monitor the security of critical systems (e.g., e-mail servers, database servers, web servers, etc.) and changes to highly sensitive computer security controls to ensure appropriate system administrative actions, investigate and report on noted irregularities. • Provide network security monitoring, reporting, and incident handling use tools such as Splunk or ArcSight SIEM and Wireshark to examine anomalous network Activity • Assessment of IT systems and components with enterprise class security standards and practices and identifying appropriate design and mitigation actions. Using enterprise security tools (e.g.• Providing internal and external customers with a single point of contact, and handling & initial identification of security incidents/events.• Advise incident responders on the steps to take to investigate and resolve computer security incidents. Assist with security related issues.• Make recommendations for preventive measures as necessary• Comply with security systems according to industry best practices to safeguard information systems and databases• Provide technical consultation on highly complex tasks; may assist and/or provide direction to lower level technical personnel