助理SOC工程师 | 远程,美国
Associate SOC Engineer | Remote, USA
助理SOC工程师负责更新客户工单并按照操作流程执行MSS支持任务,包括健康检查、报告、工单确认与分配、基本故障排除以及其他为确保MSS服务健康和运行所需的任务。助理SOC工程师将参与知识库和故障排除信息的开发,以提升MSS服务的效率和性能。该职位要求能够掌握多种安全产品技能,并与更高级别的员工、服务交付团队和客户紧密合作,提供持续的状态沟通和对MSS服务工单的及时响应。
这是一个第三班次岗位,工作时间为周日到周三夜间。
你将产生的影响:
- 作为网络安全运营客户系统的首要响应者,负责客户配置问题并跟踪至解决
- 作为其他工程师(助理工程师)的升级点,提供指导和辅导
- 向技术人员和相对非技术人员提供建议,说明SIEM和企业安全产品的最佳实践
- 通过互动客户会议提供远程咨询服务,协助多个产品供应商和技术的实施
- 在大型企业环境中实施和配置专用软件和设备产品
- 开发和维护内容和报告
- 为授权支持客户提供Tier 1和Tier 2的升级支持,按照流程并在需要时与客户和合作伙伴进行适当互动
- 向客户提供关于安全和系统配置意识的知识转移
- 执行其他指派的任务
- 遵守所有政策和标准
我们寻找的人选:
- 需要信息系统、安全或网络专业的学士学位,或上述领域的副学士学位并具有同等经验
- 需要2-4年的相关领域经验
- 入职时具备一般安全知识(IT知识、网络故障排除、云认证和其他IT经验)优先
- 入职时具备CCNA、SentinelOne、CrowdStrike、MS Sentinel、Splunk或MCSE优先
- 入职时具备CompTIA Security+和/或Network+优先
- 具备在内部和客户工单及知识库系统中处理事件和问题跟踪以及流程的经验(例如)
查看英文原文
The Associate SOC Engineer will be responsible for updating customer work requests and following operating procedures to perform MSS support tasks including health checks, reporting, work ticket acknowledgment and assignment, basic troubleshooting and other tasks as required for MSS service health and operation. The Associate SOC Engineer will contribute to the development of knowledge base and troubleshooting information to expand the efficiency and performance of MSS services. This role requires the ability to develop skills on multiple security products and work closely with the staff of higher tiers, Service Delivery, and clients to provide ongoing communication of status and timely response to MSS service tickets.
This is a third shift position working overnight Sunday-Wednesday.
How you'll make an impact:
- Serve as a primary responder for Cyber Operations client systems, taking ownership of client configuration issues and tracking through resolution
- Act as a point of escalation for other Engineers (Associate Engineer) and provide guidance and mentoring.
- Advise best practice on SIEM and Enterprise Security products to both technical and relatively non-technical personnel
- Provide remote consulting services via interactive client sessions to assist with implementation of multiple product vendors and technologies
- Implement and configure discipline software and appliance-based products in large enterprise environments
- Develop and maintain content and reporting
- Provide escalation support to Tier 1 and 2 for Authorized Support Customers, following processes and interacting appropriately with both customers and partners when required
- Perform knowledge transfers to clients regarding security and system configuration awareness
- Performs other duties as assigned
- Complies with all policies and standards
What we're looking for:
- Bachelor's Degree in Information System, Security or Networking or Associate’s degree in above field with equivalent experience required
- 2-4 years experience in discipline domain required
- General security knowledge (IT knowledge, Network Troubleshooting, Cloud Certification, and other IT experience) Upon Hire preferred
- CCNA, SentinelOne, CrowdStrike, MS Sentinel, Splunk or MCSE Upon Hire preferred.
- CompTIA Security+ and/or Network+ upon hire preferred
- Experience working with Internal and client Ticketing and Knowledge Base Systems for Incident and Problem tracking as well as procedures. (i.e. Service Now, Jira, Confluence, etc.)
- Practical knowledge and sufficient experience with TCP/IP networking and network protocols (basic understanding of OSI model)
- Knowledge of Linux and Windows Operating Systems
- An understanding of a wide array of server grade applications such as: DBMS, DNS, SMTP, IIS, Apache, SharePoint, Active Directory, Identity Management, Patch Management, LDAP, SQL, AntiVirus.
- Training and experience in one or more non-SIEM network security products to include: Enterprise endpoint security products, such as SentinelOne, CrowdStrike, Carbon Black, Cortex XDR.
- Professional experience working with networks and network architecture
- Confident presentation, written and oral communication skills
- Customer Support
- Desire to learn additional subject matter areas
What you can expect from Optiv
- A company committed to our inclusive value through our Employee Resource Groups
- Work/life balance
- Professional training resources
- Creative problem-solving and the ability to tackle unique, complex projects
- Volunteer Opportunities. “Optiv Chips In” encourages employees to volunteer and engage with their teams and communities.
- The ability and technology necessary to productively work remotely/from home (where applicable)
EEO Statement
Optiv is an equal opportunity employer. All qualified applicants for employment will be considered without regard to race, color, religion, sex, gender identity or expression, sexual orientation, pregnancy, age 40 and over, marital status, genetic information, national origin, status as an individual with a disability, military or veteran status, or any other basis protected by federal, state, or local law.
Optiv respects your privacy. By providing your information through this page or applying for a job at Optiv, you acknowledge that Optiv will collect, use, and process your information, which may include personal information and sensitive personal information, in connection with Optiv’s selection and recruitment activities. For additional details on how Optiv uses and protects your personal information in the application process, click here to view our Applicant Privacy Notice. If you sign up to receive notifications of job postings, you may unsubscribe at any time.
Originally posted on Himalayas