Obsidian Insurance Holdings, Inc ยท 4 hours ago
Incident Response Analyst
Maximize your interview chances
Insurance
No H1BU.S. Citizen Only
Insider Connection @Obsidian Insurance Holdings, Inc
Get 3x more responses when you reach out via email instead of LinkedIn.
Responsibilities
Coordinate investigation and response efforts throughout the Incident Response lifecycle
Correlate and analyze events and data to determine scope of Cyber Incidents
Acquire and analyze endpoint and network artifacts, volatile memory, malicious files/binaries and scripts
Recognize attacker tactics, techniques, and procedures as potential indicators of compromise (IOCs) that can be used to improve monitoring, analysis, and Incident Response.
Develop, document, and maintain Incident Response process, procedures, workflows, and playbooks
Tune and maintain security tools (EDR, IDS, SIEM, etc) to reduce false positives and improve SOC detection capabilities
Document Investigation and Incident Response actions taken in Case Management Systems and prepare formal Incident Reports
Create metrics and determine Key Performance Indicators to drive maturity of SOC operations
Develop security content such as scripts, signatures, and alerts
Qualification
Find out how your skills align with this job's requirements. If anything seems off, you can easily click on the tags to select or unselect skills to reflect your actual expertise.
Required
5-8 years of industry experience
Expertise of Operating Systems (Windows/Linux) operations and artifacts
Expertise of Enterprise Network Architectures to include routing/switching, common protocols (DHCP, DNS, HTTP, etc.), and devices (Firewalls, Proxies, Load Balancers, VPN, etc.)
Ability to recognize suspicious activity/events, common attacker TTPs, and perform logical analysis and research to determine root cause and scope of Incidents
Expertise with Cyber Kill Chain and have utilized the ATT&CK Framework
Have scripting experience with Python, PowerShell, and/or Bash
Ability to independently prioritize and complete multiple tasks with little to no supervision
Flexible and adaptable self-starter with strong relationship-building skills
Strong problem-solving abilities with an analytic and qualitative eye for reasoning
Strong verbal and written communication skills
Ability to communicate with all levels of audiences (subordinates, peers & leadership)
Candidate must have technical hands-on experience in the areas of incident detection and response, malware analysis, or computer forensics.
Must Be Willing to Obtain One of the Following Certifications: CISSP, OSCP, GCIH, GCIA, GCFA, GPEN, GCFE, GREM
Department of Homeland Security ESOC employees are required to obtain an Entry on Duty (EOD) clearance to support this program
US Citizenship (Required)
Incident response: 4 years (Required)
Splunk or other relative SIEM tools: 4 years (Required)
Benefits
401(k)
401(k) matching
Dental insurance
Health insurance
Health savings account
Life insurance
Paid time off
Professional development assistance
Referral program
Vision insurance
Company
Obsidian Insurance Holdings, Inc
Obsidian Insurance Company is a Property & Casualty insurance fronting platform built solely to support the increasing market need of managing general agents, risk aggregators, managing general underwriters, and program administrators.
Funding
Current Stage
Early StageRecent News
2022-08-08
Company data provided by crunchbase