网络安全分析师 (法语使用者)
Cyber Analyst ( French Speaker )
开发工程职能支持限定地区(需当地身份)日间重叠约 2 小时,需偶尔早起或晚睡
公司TechBiz Global
薪资未公开
工作地点France
地域资格限定地区(需当地身份)
时区要求日间重叠约 2 小时,需偶尔早起或晚睡
用工类型Full Time
发布时间今天
数据来源Himalayas
注意地域限制:该职位明确限定在 France 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:日间重叠约 2 小时,需偶尔早起或晚睡。
在TechBiz Global,我们为来自我们客户组合中的顶级客户提供招聘服务
我们正在寻找一位积极主动、注重细节的网络安全分析师,加入其中一家客户的团队。如果您正在寻找一个在创新环境中成长的 exciting 机会,这可能是您的理想选择
职位职责
- 监控和管理EDR(端点检测与响应)和XDR(扩展检测与响应)平台,实时识别、分析和响应安全威胁
- 在安全运营中心(SOC)环境中执行持续的安全监控,处理来自端点、网络和云基础设施的大量警报
- 分析安全日志、警报和遥测数据,以检测可疑活动、恶意软件和潜在泄露
- 调查、分类并响应安全事件,遵循既定的事件响应流程和升级路径
- 执行威胁分析和根本原因调查,确定影响范围和补救措施
- 与SOC团队成员及其他IT/安全团队协作,遏制、修复并防止重复发生事件
- 保持准确的事件文档,并确保在工单系统中进行适当的案件管理
- 编制每日和每周安全报告,总结警报、事件、趋势和响应行动,供管理层和相关方参考
- 持续调整和优化检测规则、警报和工作流程,减少误报并提高检测效率
- 关注新兴威胁、攻击技术及行业最佳实践,以提升整体安全态势
任职要求
- 精通EDR/XDR平台,用于持续的端点监控、行为分析和通过SIEM工具进行事件关联
- 具备威胁狩猎、警报分类、误报评估以及初始补救措施(如端点隔离或域名阻断)的专业技能
- 了解网络协议、日志(Syslog、Windows事件)、脚本(PowerShell)和网络威胁情报(CTI),用于威胁上下文分析
- 信息安全、IT或相关领域的学士或硕士学位(相当于Bac+3),并持有认证,如ESET、Trellix、Barracuda、SentinelOne、Fortigate等厂商认证
- 2-5年SOC一级/二级岗位经验,具备在EDR/XDR控制台上处理警报的实际经验,以减少噪音
- 持续接受高级威胁(EDR、XDR、MDR)方面的培训
查看英文原文
At TechBiz Global, we are providing recruitment service to our TOP clients from our portfolio.
We are currently looking for a highly proactive and detail-oriented Cyber Analyst to join one of our clients' teams. If you're looking for an exciting opportunity to grow in a innovative environment, this could be the perfect fit for you.
Job Responsibilities
- Monitor and manage EDR (Endpoint Detection and Response) and XDR (Extended Detection and Response) platforms to identify, analyze, and respond to security threats in real time.
- Perform continuous security monitoring within the Security Operations Center (SOC) environment, handling a high volume of alerts from endpoints, networks, and cloud infrastructures.
- Analyze security logs, alerts, and telemetry data to detect suspicious activity, malware, and potential breaches.
- Investigate, triage, and respond to security incidents, following established incident response procedures and escalation paths.
- Conduct threat analysis and root cause investigations to determine impact, scope, and remediation actions.
- Collaborate with SOC team members and other IT/security teams to contain, remediate, and prevent recurring incidents.
- Maintain accurate incident documentation and ensure proper case management within ticketing systems.
- Produce daily and weekly security reports, summarizing alerts, incidents, trends, and response actions for management and stakeholders.
- Continuously tune and optimize detection rules, alerts, and workflows to reduce false positives and improve detection efficiency.
- Stay informed on emerging threats, attack techniques, and industry best practices to enhance overall security posture.
Requirements
- Proficiency in EDR/XDR platforms for continuous endpoint surveillance, behavioral analysis, and event correlation via SIEM tools.
- Expertise in threat hunting, alert triage, false positive qualification, and initial remediation like endpoint isolation or domain blocking.
- Knowledge of network protocols, logs (Syslog, Windows Events), scripting (PowerShell), and Cyber Threat Intelligence (CTI) for threat contextualization
- Bachelor's or Master's degree (Bac+3 equivalent) in cybersecurity, IT, or related fields, plus certifications, vendor-specific ESET, Trellix, Barracuda, SentinelOne, Fortigate.
- 2-5 years in SOC Tier 1/2 roles, with hands-on experience triaging alerts on EDR/XDR consoles to minimize noise.
- Ongoing training in advanced threats (EDR, XDR, MDR) to progress to senior positions.
Originally posted on Himalayas
本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。
本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。
该公司其他在招职位
高级AI DevOps / LLMOps
AI开发工程职能支持未标注地域
全栈开发工程师(AI辅助开发)
AI开发工程未标注地域
高级技术客户经理
开发工程市场运营职能支持限定地区(需当地身份)
初级招聘专员
其他未标注地域
中级合同律师 (俄语使用者)
职能支持未标注地域