Senior Soc Analyst
Current• Monitor and analyze security events and alerts from multiple sources, including security information and event management (SIEM) software, EDR solutions, network and host-based intrusion detection systems, firewall logs, system logs (Windows and Unix), and databases• Separate true threats from false positives using network, log, and EDR analysis and escalate possible intrusions and attacks• Initiate tickets, document, and escalate to higher-level security analysts if appropriate• Serve as the technical escalation point and mentor for lower-level analysts• Develop technical training materials for newly onboarded analysts• Perform shadowing/reverse shadowing as part of the training process for newly hired analysts• Regularly communicate with customer IT teams to inform them of issues, help them remediate, and ensure that they continue to operate business as usual• Perform triage of incoming issues (assess the priority, determine risk)• Work with customers to deploy hardware and software monitoring systems• Perform malware static, behavioral, and dynamic analysis in a virtualized environment• Perform audits to ensure analysis quality and in order to present facilitate the development of analyst skill sets• Participate in the Detection and Analysis, as well as Containment and Eradication phases of the incident response process under the guidance of senior analysts