Senior Cyber Security Operations Engineer I - Careem None Bookmark Share Print 135 0 0

Listing Description











KEY ACCOUNTABILITIES



Responsibilities and Tasks: 



  • Responsible for the validation and analysis of investigations within Security Operations Center (SOC) Analyst

  • Responsible for the monitoring, validation and analysis of investigations of events and alerts on AWS Cloud Infrastructure, SaaS applications and onprem infrastructure

  • Provide expert analysis of Cloudtrail, CloudWatch,  VPC Flow logs for event/incident analysis

  • Guide and support automate security alerts and use cases  in AWS cloud

  • Carry out triage of incoming issues (initial assessing the priority of the event, initial determination of incident to determine risk and damage or appropriate routing of security or privacy data request)

  • Proactively identify vulnerabilities across the entire infrastructure environments and suggest updating of SIEM use cases to generate alerts

  • ‘On Call’ availability for rare ‘fire drill’ scenarios, for example on high-critical incident response scenarios, or emergent imminent widespread threats requiring urgent action

  • Provide communication and escalation throughout the incident per the SOC guidelines.

  • Identify and manage a wide range of intelligence sources to provide a holistic view of the threat landscape and filter out noise in order to focus and execute upon actionable intelligence

  • Ensure that all security events and incidents (internal / external) are logged into Jira and regularly updated  and closed within the set SLA’s

  • Leading the development of actionable use cases to detect, triage, investigate and remediate based on latest threat actor trends, support teams with the technical implementation of parsing log sources creating, validating and testing alerting queries to reduce false positives



 
















 

Qualifications:




  1. Minimum 3+ years of operational experience preferred in security operations center, threat intelligence, insider threat operations, threat management, cyber security, information security or related functions.





  1. Bachelor's degree in Computer Science, Management Information Systems, Information Systems, or a related field/experience is required. Experience within financial services areas is preferred.





  1. Strong knowledge of Security Methodologies and Frameworks.



Experience



Must have experience: 



  • Experience in Highly available 24x7 Enterprise Operational Environment


 



  • Familiarity with cloud architecture/infrastructure and general networking principles.





  • Experience with virtualization technologies, especially with AWS services.





  • Strong demonstrated knowledge of web protocols, common attacks, and an in-depth knowledge of Linux/Unix tools and architecture.





  • System administration, configuration and patch management, zone security, firewall and IAM





  • SOC / Pen-Tester / Purple Team / Threat Intelligence / Threat Hunting or similar background, or demonstrable experience through self study





Proven success in working  SOC function/team, including (but not limited to):



  • Experience maintaining metrics, reporting and SLAs

  • Security operations experience with operating systems, AWS cloud infrastructures

  • Familiarity or experience in Intelligence Driven Defense, Cyber Kill Chain methodology, and/or MITRE ATT&CK framework

  • Strong analytical skills and attention to detail

  • Experience around security processes and technologies

  • Ability to research, analyze, and resolve complex problems with minimal supervision and escalate issues as appropriate

  • Thorough documentation skills

  • Outstanding written and verbal communication skills

  • Must be a  highly motivated individual with the ability to self-start, prioritize, and multi-task



 


Listing Details

  • Citizenship: Not Provided
  • Incentives: Not Provided

 

  • Education: Not Provided
  • Travel: Not Provided
  • Telework: Not Provided



About Us

NinjaJobs is a community-run job platform developed by information security professionals. Our unique approach of focusing strictly on cybersecurity positions allows us to personalize the user experience.

Our Contacts

1765 Greensboro Station Pl.
Suite 900
Tysons Corner Va 22102

(703) 594-7765