事件响应分析师
Incident Response Analyst
开发工程职能支持未标注地域
公司SOFTSWISS
薪资未公开
工作地点Georgia
地域资格未标注地域
时区要求日间重叠约 5 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
概述:
SOFTSWISS 正在寻找一名事件响应分析师加入我们的轮班事件响应团队。在此职位中,您将对公司范围内的安全事件进行响应和调查,与相关团队协调事件响应,并帮助确保事件得到及时有效的解决。
主要职责:
- 参与安全事件响应
- 执行基本的初步事件响应措施/分类
- 根据计划结果执行(并监控执行)分配的任务
- 编写和更新警报验证的剧本
- 按照 SLA 监控警报
- 提出优化所用工具和流程的建议
- 该职位采用 2 值班 2 休息的轮班模式,包括 12 小时日班、次日 12 小时夜班,之后有 2 天休息
所需经验:
- 使用公开可用工具(VirusTotal、AnyRun 等)进行基本的恶意指标(IoC)分析技能
- 具备使用 Splunk/Clickhouse/SQL 编写简单搜索查询并解释结果的经验
- 具备使用 SOAR/IRP 的经验
- 了解当前网络威胁和主要攻击方法
- 具备 Python、PowerShell 或 Bash 的基本编程技能,用于自动化日常任务
- 具备初级系统管理员级别的操作系统(Linux/Windows)知识
- 理解 MITRE ATT&CK 框架和网络杀伤链
- 能够分析和处理大量数据,包括日志和初步分类
- 强大的沟通和团队合作能力:能够清晰表达想法,提出相关问题,并在不同团队之间有效协作,特别是在事件响应期间
- 分析性和灵活性思维:能够从不同角度看待问题,建立逻辑链条,做出明智决策,并独立提出解决方案
- 主动性和责任感:对决策和结果负责,仔细检查自己的工作,从错误和反馈中学习,并积极发展专业技能
加分项:
- 了解信息安全最佳实践(NIST、ISO)并在必要时引用的能力
- 了解 Docker 和 Kubernetes,了解其监控功能
- 具备在 SIEM 中编写关联规则的经验
- 具备使用 NTA(网络流量分析)工具的经验
- 具备使用在线声誉服务(VT、AnyRun、IPAbuseDB 等)的经验
查看英文原文
Overview:
SOFTSWISS is looking for an Incident Response Analyst to join our on-call incident response team. In this role, you will respond to and investigate security incidents across the company, coordinate incident response with relevant teams, and help ensure timely and effective resolution of incidents.
Key responsibilities:
- Participation in security incident response
- Performing basic primary incident response measures/triage
- Execution (and monitoring of execution) of tasks assigned based on planning results
- Development and updating of playbooks for alert verification
- Monitoring alerts in compliance with SLA
- Submitting proposals for optimizing tools and processes used
- The position operates on a 2-on-2-off shift pattern, encompassing a 12-hour day shift, a 12-hour night shift the next day, and 2 free days after that
Required Experience:
- Basic indicator of compromise (IoC) analysis skills using publicly available tools (VirusTotal, AnyRun, etc.)
- Experience working with Splunk/Clickhouse/SQL at the level of writing simple search queries and interpreting results
- Experience working with SOAR/IRP
- General understanding of current cyber threats and main attack methods
- Basic programming skills in Python, PowerShell, or Bash for automating routine tasks
- Knowledge of operating systems (Linux/Windows) at a junior system administrator level
- Understanding of the MITRE ATT&CK framework and Cyber Kill Chain
- Ability to analyze and process large volumes of data, including logs and triage
- Strong communication and teamwork skills: able to clearly articulate thoughts, ask relevant questions, and effectively collaborate with colleagues across different teams, especially during incident response
- Analytical and flexible mindset: able to approach issues from different perspectives, build logical chains, make informed decisions, and independently suggest solutions
- Proactivity and ownership: takes responsibility for decisions and results, double-checks own work, learns from mistakes and feedback, and actively develops professional skills
Nice to have:
- Knowledge of information security best practices (NIST, ISO) and ability to cite them when necessary
- Basic knowledge of Docker and Kubernetes, understanding their monitoring features
- Experience writing correlation rules in SIEM
- Experience with NTA (Network Traffic Analysis) tools
- Experience working with online reputation services (VT, AnyRun, IPAbuseDB, etc.)
- Experience developing instructions for alert verification and/or writing information security incident response scenarios
- Experience with Kafka, ELK, Graylog, etc
- Strong Linux system administration experience
- Expertise in network, host, and cloud-based analysis and investigation
- A strong understanding of attack pipelines (MITRE ATT&CK Framework, Cyber Kill-Chain)
- Familiarity with CI/CD, software development lifecycle, and Infrastructure-as-Code (Terraform/Ansible/etc)
- Proficiency in automation (Bash/PowerShell, Python)
- Experience with log collection, delivery, and normalization
- Strong knowledge of open-source solutions for endpoint & infrastructure security, such as Audit.d, Sysmon, AppArmor, SELinux, etc
- Fundamental static and dynamic malware analysis skills
- Offensive experience (penetration testing, red teaming)
Our Benefits:
- Private health insurance
- Sports benefits
- Comprehensive Mental Health Program
- Free English lessons (online)
- Local language courses
- Paid time off
- Maternity leave support
- Referral program rewards
- Upskilling, internal workshops, and participation in professional conferences and corporate events
Originally posted on Himalayas
本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。
本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。