My direct client has an immediate need for a Cyber Incident Response Security Analyst
Location: Houston, TX
Duration: 2 year contract
Start Date: ASAP
Interview Process: 2 Phone Screen's
Responsible for maintaining the integrity and security of enterprise-wide cyber systems and networks. Supports cyber security initiatives through both predictive and reactive analysis, articulating emerging trends to leadership and staff.
Coordinates resources during enterprise incident response efforts, driving incidents to timely and complete resolution. Employs advanced forensic tools and techniques for attack reconstruction, including dead system analysis and volatile data collection and analysis.
Supports internal HR/Legal/Ethics investigations as forensic subject matter expert. Performs network traffic analysis utilizing raw packet data, net flow, IDS, and custom sensor output as it pertains to the cyber security of communications networks. Reviews threat data from various sources and develops custom signatures for Open Source IDS or other custom detection capabilities. Correlates actionable security events from various sources including Security Information Management System (SIMS) data and develops unique correlation techniques. Utilizes understanding of attack signatures, tactics, techniques and procedures associated with advanced threats. Develops analytical products fusing enterprise and all-source intelligence. May conduct malware analysis of attacker tools providing indicators for enterprise defensive measures, and reverse engineer attacker encoding protocols. Interfaces with external entities including law enforcement organizations, intelligence community organizations and other government agencies
Responsibilities include the acquisition, vetting, and validation of cyber threat intelligence from various internal and external sources. This individual focuses on the fidelity and contextual analysis of indicators of compromise and attacker TTPs (tactics, techniques and procedures) in support of security operations. The successful candidate will be responsible for creating and executing incident response plans, processes, and procedures and performing root cause evaluations. Needs to be able to define events vs. alerts vs. incidents for the organization, and create incident classification, severity, and priority tables in line with all threats, risks and vulnerabilities.
Must be able to identify and document incident trends and compromise patterns. The successful candidate will be located at the customer site in a leadership role representing Commercial Cyber Solutions. He or she should be able to mentor and coordinate tasking for team members.
The Analyst would have the following experience:
Five or more years of technical experience in the information security field
Three or more years of incident response, analysis and escalation experience
Familiarity with security regulatory requirements and standards (such as NIST 800 series, ITIL, PCI)
Advanced knowledge and experience with the multiple operating systems (Windows, *nix, OSX, IOS and other
infrastructure device OS)
Advanced experience with security technologies including Intrusion Detection & Prevention Systems (IDS/IPS), Firewalls & Log Analysis, SIEM, Network Behavior Analysis tools, Antivirus, and Network Packet Analyzers, and Malware analysis and forensics tools
Advanced knowledge of the TCP and IP protocol suite, security architecture, and remote access security techniques and products
The Analyst would be responsible for:
Support cyber security initiatives through both predictive and reactive analysis.
Coordination of resources during enterprise incident response efforts, driving incidents to resolution.
Employing advanced forensic tools and techniques for attack reconstruction and intelligence gathering.
Perform network traffic analysis utilizing raw packet data, net flow, IDS, and custom sensor output as it pertains to the cyber security of communications networks.
Utilize understanding of attack signatures, tactics, techniques and procedures associated with advanced threats.
Strong communication skills both written and oral
-Advanced understanding of networking, system of systems architecture
-In-depth knowledge of architecture, engineering, and operations of at least one enterprise SIEM platforms (e.g.,
Nitro/McAfee Enterprise Security Manager, ArcSight, QRadar, LogLogic, Splunk)
- Correlate actionable security events from various sources and develop unique correlation techniques.
- Review threat data from Client feeds and develop custom signatures for detection capabilities.
- Experience with malware analysis concepts and methods.
If qualified and interested, please send your most current resume as a word document to Jason Weinstein at email@example.com