Security Operations Analyst at KUBRA ensuring data protection and responding to security incidents. Join a dynamic team focused on continuous improvement in cybersecurity.
Responsibilities
Security Infrastructure Management: Maintain and optimize the security infrastructure (Firewalls, IDS/IPS, AV, SIEM, FIM, servers, etc.) with a specific focus on maintaining Exabeam SIEM and CrowdStrike (managing EDR, FIM, and DLP modules).
Cloud Security Operations: Execute AWS cloud security operations, monitoring specific services (e.g., GuardDuty, Security Hub, CloudTrail) to secure cloud workloads and respond to cloud-native threats.
Incident Response: Monitor systems, software, and skills to stay ahead of emerging threats: Lead or participate in security investigations and Assist during Incident Response and Recovery activities.
Data Pipeline Management: Manage and optimize security data pipelines using Cribl to ensure efficient log routing, parsing, and data reduction before ingestion.
Infrastructure as Code (IaC): Utilize IaC principles (specifically Terraform) to deploy, maintain, and audit security configurations and infrastructure.
Network Security: Perform firewall operational tasks as approved.
Governance & Risk: Maintain and enforce KUBRA’s IT management control framework that defines the institution’s overall approach to IT risk and control.
Incident Management: Participate in on-call rotation to respond, investigate and resolve Security Incidents.
Alert Coordination: Track and action alerts to ensure proper response is taken by coordinating the work efforts of internal teams and actions required of external service providers.
SIEM Optimization: Apply understanding of environment and operational issues to work with external or internal parties for implementation or optimization of specific Exabeam SIEM use cases to help improve detection and response.
Threat Intelligence: Maintain the vulnerability security digest, monitor threat feeds, and provide regular threat intelligence updates.
Access Reviews: Conduct access control reviews on a case-by-case basis to systems and work with internal and external resources to update user control lists and provide reports.
Audit & Compliance: Assist in remediation tasks related to audits/penetration tests.
Training & Testing: Participate in internal and external table-top exercises related to cybersecurity.
Documentation: Assist in development of process and procedure documents for Security Operations.
Policy Guidance: Evaluate and provide guidance to exemption requests as per corporate policy and standards, to advise of risk involved.
Requirements
A minimum of 2 years of experience operating and working in a functional SOC environment.
A minimum of 2 years of experience in a Security Operations role.
2+ years of experience in Incident Management and related processes.
Exabeam: Proven experience operating Exabeam SIEM is required.
CrowdStrike: Hands-on experience with CrowdStrike EDR, FIM (File Integrity Monitoring), and DLP (Data Loss Prevention) is required.
AWS Security: Strong operational knowledge of AWS Cloud Security operations is required.
Cribl: Experience with Cribl for log shaping and routing is highly desirable.
Terraform: Knowledge of Terraform or other Infrastructure as Code (IaC) tools is considered a strong asset.
SOC analyst monitoring and responding to cyber threats for Wepoint’s digital transformation clients. Investigating escalated alerts and improving 24×7 security operations.
SOC cybersecurity analyst monitoring and responding to cyber threats for Wepoint’s digital transformation clients. Improving 24×7 detection, investigation, and incident response capabilities.
Senior Security Operations Engineer monitoring incidents and leading forensics for Samsara’s IoT - connected operations platform. Building security automation and supporting insider - threat investigations.
Senior SOC analyst leading threat detection, investigations, and incident response for Financeit, a Canadian point - of - sale financing provider. Building its new SOC’s automation, AI - threat coverage, and operational standards.
Security Operations Engineer securing Tailscale’s networking platform through device, identity, access, and vulnerability management. Supporting distributed teams and automating security operations across core business systems.