
Security Specialist
- Cisco
- HPE
- Oracle
- VMware
- ServiceNow
- Epic
- React.js
- SIEM
- Threat Intelligence
- triage
- Azure
- Active Directory
- Linux
- Nessus
- Risk Management
- ITIL
- CompTIA A+
- CISSP
- Excel
Logicalis employees are innovative, smart, entrepreneurial and customer centric, with a shared ambition of making Logicalis the worlds leading IT Solutions provider!
We offer speedy decision-making, opportunities for personal development, and a supportive, inclusive environment that celebrates our diversity.
Join us and become a part of something epic!
ROLEPURPOSE
The Security Operations Centre will provide defence against security breaches and actively isolate and mitigate security risks. The Security Specialist forms part of the security operations centre SOC team. The SOC Team will identify, analyse, and react to cyber security threats using a reliable set of processes and security technologies. The SOC Team includes the SOC Manager, SIEM Platform Manager, Case Manager, SOC Tier 1,2 and 3 Analysts and Security Specialists. They work with IT operational teams to address security incidents and events
quickly. The SOC Team will provide a critical layer of analysis needed to seek out any irregular activity that could suggest a security incident.
ROLE AND DELIVERYRESPONSIBILITIES:
The job role includes actively participating in the incident detection process asfollows:
- Possesses in-depth knowledge of network, endpoint, threat intelligence, forensics and malware reverse Analysis, as well as the functioning of specific applications or underlying IT infrastructure
- Acts as an incident āhunter,ā not waiting for escalatedincidents
- Closely involved in developing, tuning, and implementing threat detectionanalytics
- Acts as the escalation for Tier 1 and 2 SOCAnalysts
- Responds to and oversees the remediation of a declared securityincident
- Completes the Root Cause Analysis Report for P1 toP4
- Provides guidance to Tier 1 and 2 SOCAnalysts
- Uses threat intelligence such as updated rules and Indicators of Compromise (IOCs) to pinpoint affected systems and the extent of the attack
- Monitors shift-related metrics ensuring applicable reporting is gathered and disseminated to the SOC Manager
- Make recommendations to the SOCManager
- Oversees the analysis on running processes and configs on affectedsystems.
- Undertakes in-depth threat intelligence analysis to find the perpetrator, the type of attack, and the data or systems impacted
- Oversees the containment andrecovery
- Oversees the deep-dive incident analysis by correlating data from varioussources
- Validates if a critical system or data set has beenimpacted
- Provides support for analytic methods for detectingthreats
- Conducts advanced triage based on defined run books ofalerts
- Undertakes threat intelligence research if needbe
- Validates false positives, policy violations, intrusion attempts, security threats and potential compromises
- Undertakes security incident triage to provide necessary context prior to escalating to relevant Security Specialists to perform deeper analysis when necessary
- Further analyses alarms by method e.g. credentials compromised and by assetclass
- Based on the correlation rules and alarms within the SIEM and run books, further analyses anomaly tactic using the MITRE ATT&CK framework
- Analyses event and process metadata in real-time or retrospectively, and identify suspicious files/scripts seen for the first time
- Closes tickets in the SIEM platform ā this would be automatically created into ServiceNow
- Manages security incidents using the SIEM platform and defined operationalprocedures
- Performs a further investigation of potential incidents, and escalate or close events asapplicable
- Validates investigation results, ensuring relevant details are passed on to Tier 2 SOC Level 2 for further event analysis
- Closes out deeper analysis and reviewactivities
- Assist senior SOC staff with operationalresponsibilities
PERSONREQUIREMENTS:
EXPERIENCE:
- Strong knowledge and experience working with SIEM Solutions, QRadar, McAfee ESM, Azure Sentinel
- Proven experience with Office 365, Active Directory, Azure and MicrosoftExchange.
- Strong knowledge and experience working with Linux Operatingsystems
- Good experience working with Nessus orQualys
- Good understanding of the MITRE ATT&CKframework
- Good understanding of the ITILFramework.
- Brilliant with a support ticketing system and experience in meeting SLAtargets.
- Familiarity with risk management and quality assurancecontrol.
- Excellent interpersonal skills and professionaldemeanor
- Excellent verbal and written communicationskills
- Candidate must be eligible to obtain National SecurityClearance
QUALIFICATIONS:
- Grade12
- SIEM Technologycertification.
- AZ500,SC100
- ITIL Foundationqualification
- Degree or Diploma in ComputerTechnology
- CompTIA A+, N+S+
- CompTIA CySa, CISSP and CASP+advantageous
ADDITIONALSKILLS/ATTRIBUTES:
- Advanced Microsoft Excel experience, specifically datainterpretation
- Good understanding of ITinfrastructure
- A high command of the English language both written and verbal is essential.
- Self-motivated with the ability to workunsupervised.
- Attention todetail
- Punctuality
- Excellent verbal and written communicationskills
- Ability to remain flexible and adapt to changing priorities with promptness, efficiency, and ease
- Possess proficient analytical and decision-makingskills
- Demonstrated capacity for gathering and scrutinizing data to identify issues, opportunities, and patterns
- Proficient relationship building skills ā predict customer behavior and respondaccordingly
- A strong service-oriented (ācan-doā) culture, with a strong focus on the āinternal customerā approach, committed to exceeding customer expectations
- Good communicator with the customerenvironment
- Dynamic but aware of the views and feelings of others
- Able to operate as a good teamplayer
- Drive andEnergy
- Demonstrate clear purpose, enthusiasm, andcommitment
Security Specialist Ā· Logicalis Australia