Full Job Description
Job Summary
We are seeking a highly skilled and experienced Senior Information Security Operations Analyst to join our team at NCR VOYIX Corporation. In this role, you will play a critical part in protecting our digital assets by actively monitoring, detecting, and responding to security incidents, and contributing to the continuous improvement of our security posture.
Job Responsibilities
• Lead and perform in-depth analysis of security events, alerts, and incidents from various security tools (SIEM, EDR, IDS/IPS, firewalls, etc.) to identify true positives and potential threats.
• Conduct incident response activities, including containment, eradication, recovery, and post-incident analysis, ensuring timely and effective resolution.
• Develop and implement security playbooks, procedures, and runbooks for common incident types and security operations tasks.
• Contribute to the continuous improvement of our security monitoring capabilities, including SIEM rule tuning, dashboard creation, and alert optimization.
• Perform vulnerability management activities, including scanning, assessment, and coordination of remediation efforts.
• Participate in security assessments, penetration testing, and red team exercises, providing insights and recommendations.
• Mentor junior security analysts, sharing knowledge and best practices in security operations.
• Research and stay current on the latest security threats, vulnerabilities, and industry best practices.
• Collaborate with various IT and business teams to ensure security requirements are met and integrated into operational processes.
• Generate comprehensive reports on security incidents, trends, and key performance indicators.
Job Qualifications
• Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field; or equivalent practical experience.
• 4+ years of experience in the role or a related field.
• In-depth knowledge of security frameworks and standards (e.g., NIST, ISO 27001).
• Expertise with Security Information and Event Management (SIEM) platforms (e.g., Splunk, QRadar, Azure Sentinel).
• Proven experience with Endpoint Detection and Response (EDR) solutions and incident response methodologies.
• Strong understanding of network protocols, operating systems (Windows, Linux), and cloud security concepts (AWS, Azure, GCP).
• Experience with scripting languages (e.g., Python, PowerShell) for automation and analysis.
• Relevant industry certifications such as CISSP, GCIH, CEH, or equivalent are highly desirable.
• Excellent analytical, problem-solving, and communication skills, with the ability to articulate complex security issues to both technical and non-technical audiences.
• Ability to work independently and as part of a team in a fast-paced, dynamic environment.
This job description outlines the primary duties and responsibilities of the role and is not intended to be exhaustive. The employee may be required to undertake additional duties and projects that are consistent with their skills, capabilities, and the overall purpose of the position
Offers of employment are conditional upon passage of screening criteria applicable to the job