OverviewSecurity Operations Engineer participates in the operation and maintenance of the information security system of the organization. Investigates and responds to enterprise security events, incidents, and requests.
The Security Operations Engineer conducts computer and network intrusion detection, incident response, contributes to forensic investigations, data recovery and electronic discovery under guidance and cooperates with multiple departments within the organization.
The Security Operations Engineer conducts small scale threat analysis for the environment and leads smaller security initiatives contributing to security program implementation. Performs troubleshooting and small to medium scale threat analytics and hunting for the environment.
Responsibilities- Understands the purpose of and contributes to the implementation of elementary physical and technical security controls.
- Prioritizes and diagnoses incidents according to agreed procedures. Performs incident response, investigates causes of incidents and seeks resolution. Escalates unresolved incidents. Documents and closes resolved incidents according to agreed procedures.
- Performs maintenance tasks related to security and compliance management program of the organization
- Contributes to the implementation of company level controls aligned with information security standards applicable to the organization
- Contributes to Security Operations standardization by contributing to development of Standards, Procedures and Processes.
- Contributes to the remediation of identified vulnerabilities by coordinating with relevant stakeholders
- Supports the identification of areas for improvement in operations proposing actionable items
- Contributes to digital forensic investigations. Processes and analyses evidence in line with policy, standards and guidelines and supports production of forensics findings and reports.
- Some travel may be required
Qualifications- Associate or Bachelor's degree in computer science or related field preferred. Combination of formal education training and practical experience sufficient to acquire knowledge and skills generally equivalent to those possessed by an associate degree individual may be considered.
- Industry recognized certifications such aa CEH, CompTia CySA+ is a plus
- Scripting knowledge preferably in KQL, or basic scripting and programing knowledge in Python, PowerShell
- Has a basic understanding of endpoint and network behavior analysis techniques and tools. Capable of using various detection systems and software.
- Has basic knowledge of several of the following: network foot-printing, port scanning, and enumeration techniques, specific operating system vulnerabilities, web server vulnerabilities, application level exploits, worms, viruses, and Trojans, network vulnerabilities, sniffing, wireless sniffing, IP spoofing, etc.
- Understanding and demonstrated technical skills and abilities in the technical information security operations domain
- Works under general direction. Uses discretion in identifying and responding to complex issues and assignments. Receives specific direction, accepts guidance and has work reviewed at agreed milestones.
- Determines when issues should be escalated to a higher level.
- Performs a range of work, sometimes more complex and non-routine, in a variety of environments.
- Has the general, domain knowledge necessary to perform effectively in the organization typically gained from recognized bodies of knowledge and organizational information. Demonstrates effective application of knowledge.
- Takes action to develop own knowledge.
- Plans, schedules and monitors own work competently within limited deadlines and according to relevant, standards and procedures.
- Contributes fully to the work of teams. Appreciates how own role relates to other roles and to the business of the employer or client.