TekWissen ® · 19 hours ago
Threat Incident Response Analyst
Maximize your interview chances
Insider Connection @TekWissen ®
Get 3x more responses when you reach out via email instead of LinkedIn.
Responsibilities
Conducts data security incident analysis in support of client's Insider Threat Management Program, working to help develop and maintain 'playbooks' to ensure effective and efficient response processes and procedures.
Handle escalations from internal and external sources to quickly triage and respond to potential insider threat incidents, as needed.
Develop and present comprehensive reports for both technical, executive, and non-security stakeholder audiences.
Provide technical subject matter expertise related to projects and initiatives that advance the maturity and capability of client's security program.
Develop and follow detailed operational processes and procedures to appropriately analyze, escalate and assist in the remediation of information security-related incidents.
Apply technical acumen and analytical capabilities to speed and enhance response.
Work in a flexible environment, including shift work, as required to meet business and operational needs.
Qualification
Find out how your skills align with this job's requirements. If anything seems off, you can easily click on the tags to select or unselect skills to reflect your actual expertise.
Required
5+ years of experience in Information Security
3+ years of experience in cybersecurity and/or insider threat incident response that must include experience in:
Experience with data loss/information protection solutions (Splunk, Netskope, Microsoft O365, etc.)
Identification of potential insider threat tools, tactics, and procedures (TTPs)
Security data analysis from a variety of sources and tools, including contributing to DLP policy/alert creation and maintenance.
1 year of experience with Windows log analysis and memory forensics Network traffic analysis
Undergraduate degree in computer science or related field, or equivalent work experience
Ability to work flexible schedule that may include shift work.
Preferred
Development of incident response assessments and other similar reporting (demonstrated writing & comms skills).
Experience in a similarly sized organization with significant complexity.
Strong time management skills to balance multiple activities.
Security Certification (i.e., GCIH, GCFA, CCSP, OSCP, etc.)
Experience with DLP tools and/or methodologies to enhance insider threat incident response procedures.
Experience responding to cyber events in public cloud environments such as AWS, Azure, Google Cloud, etc.
Company
TekWissen ®
Welcome to our company, your premier partner in technology consulting, workforce solutions, payroll services, procurement, managed services, global capability centers, and venture capital support, specifically tailored for startups in the human capital sector.
H1B Sponsorship
TekWissen ® has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2023 (9)
2022 (9)
2021 (11)
2020 (22)
Funding
Current Stage
Late StageCompany data provided by crunchbase