MDR Enhanced Senior Threat Analyst 1
Role Summary
- Real-time threat analysis
- Reference and apply Sophos internal and other Intelligence
- First point of contact for customer interactions; conducted in a professional manner with emphasis on customer satisfaction
- Point of coordination and collaboration with Incident Response, Product Support and other roles within Sophos and the customer environment
- Provide Advanced Intrusion Analysis
Role Summary
- Real-time threat analysis
- Reference and apply Sophos internal and other Intelligence
- First point of contact for customer interactions; conducted in a professional manner with emphasis on customer satisfaction
- Point of coordination and collaboration with Incident Response, Product Support and other roles within Sophos and the customer environment
- Provide Advanced Intrusion Analysis
What You Will Do
-
Review security-related events via cases and assess their risk and validity based on available telemetry from network, endpoint, and global threat intelligence information to provide customers with concise, detailed, and well-written incident reports, root causes identification, and remediation recommendations
-
Provide customers with understandable context around their security environment and threats
-
Interface with customers to address their issues, concerns, and questions, and drive to satisfactory closure any issues that impact the service and its value
-
Work with customer and internal Sophos incident response teams to resolve ongoing intrusions, malware outbreaks, and other security incidents
-
Use the Sophos platform to proactivity hunt for and investigate activity within the customer environment
-
Review security-related events via investigations and assess their risk and validity based on available telemetry from network, endpoint, and global threat intelligence information to provide customers with concise, detailed, and well-written incident reports, root causes identification, and remediation recommendations
-
Provide customers with understandable context around their security environment and threats
-
Interface with customers to address their issues, concerns, and questions, and drive to satisfactory closure any issues that impact the service and its value
-
Work with customer and internal Sophos incident response teams to resolve ongoing intrusions, malware outbreaks, and other security incidents
What You Will Bring
-
At least 5 years of experience working in a SOC environment or computer security team in an IT environment
-
Endpoint and network security experience required; IDS, IPS, EDR, ATP, Malware defenses and monitoring experience
-
Experience with threat hunting
-
Experience administering and supporting Windows and Unix bases Operating Systems, including both workstations and servers
-
Knowledge of common adversary tactics and techniques, e.g., obfuscation, persistence, defense evasion, etc.
-
Fundamental understanding of network traffic analysis including TCP/IP, routing, switching, protocols, etc.
-
Strong understanding of Windows event log analysis
-
Experience with basic Python scripts (reading and understanding)
-
Working knowledge of incident response procedures
-
Excellent troubleshooting and analytical thinking skills
-
Must be able to thrive within a team environment as well as on an individual basis
-
Customer service-oriented with strong documentation and communication skills
-
Passion for all things information technology and information security
-
Natural curiosity and ability to learn new skills quickly
-
Ability to think outside the box
-
Innovative mindset and driven to contribute to a team providing a best-in-class cybersecurity service
-
Bachelors in Information Technology, Computer Science or a related field; or relevant commensurate work experience
-
Willingness to participate in rotating weekend and holiday coverage (our MDR service is 24x7x365)
Desirable
-
Knowledge of MITRE ATT&CK framework
-
Experience with enterprise information security data management - SIEM experience
-
Experience with CQL query construction
-
Experience with OS Query Programming and scripting skills - proficient knowledge of PowerShell
-
Advanced Cyber Security certifications (CompTIA, SANS)