Cyber Security Analyst
Fully Remote Remote Worker - N/A, PHL Security Incident Response
Job Type
Full-time
Description

 POSITION SUMMARY 

The Cyber Security Analyst is a front-facing role, working directly with incoming alerts, reports, and metrics to monitor and maintain the security of Sourcepass' clients. The Analyst performs triage to filter out non-actionable information so that clients can continue to focus on running their businesses. The Analyst performs minor response to non-serious, non-complex events and escalates anything else to senior security team staff. This position reports to the SOC Team Lead. 

RESPONSIBILITIES

Monitor incoming alerts, reports, and metrics from a variety of a systems to perform triage
Perform minor response to non-serious, non-complex events (malware, data leakage, account misuse, etc.)
Perform automated or manual patching of discovered vulnerabilities or misconfigurations.
Escalate more serious or complex events to senior security team staff
Clearly explain event sources and resolutions to clients
Clearly document steps taken
Follow documented procedures to drive resolution
Make recommendations for improvements to processes and tools 


Requirements

 DESIRED SKILLSET/EXPERIENCE  


Willingness to learn and improve both core function skills and potential additional security role skills 

Both strong written and strong verbal communication skills, both internally and client-facing Basic understanding of SOC practices and processes Strong understanding of incident response practices and processes 

Strong understanding of the Windows operating system (Linux and Macintosh a plus) 

Strong understanding of the Windows ecosystem (Active Directory, Azure, Microsoft365)  

Experience with ticketing and tracking systems Basic knowledge of networking protocols and topologies, as well as network analysis.  

Basic understanding of malware analysis Analytical, problem solving, critical thinking skills 

Basic understanding of OS and network auditing  

Knowledge of scripting languages (PowerShell, batch, etc.) a plus Security+, E|CIH, & GCIH certifications (or equivalents) all preferred