Security Analyst - Incident Response
- respond, analyze and resolve events and incidents that are reported by end users or are observed through proactive network and system monitoring.- create and update IR policies and plans - perform or participate in vulnerability assessment and handling, artifact analysis, computer forensics evidence collection and analysis, systems and network monitoring, security policy development, and security and awareness training and education- provide input into or participate in security audits or assessments -coordinate and support the implementation of the response strategies with other parts of the enterprise or constituency, including IT groups and specialists, physical security groups, information security officers (ISOs), business managers, executive managers, public relations, human resources, and legal counsel- coordinate and collaborate with external parties such as vendors, ISPs, other security groups and CSIRTs- Maintain a repository of incident and vulnerability data and activity related to the constituency that can be used for correlation, trending, and developing lessons learned to improve the security posture and incident management processes