Job Summary
The Security Analyst provides dedicated technical client support such as monitoring and analysis capability for SOC operations and Incident Response. The Analyst conducts analysis of security events to include validation, investigation, escalation, and reporting of events of interest based on the guidelines and event handlers provided. The Analyst will be responsible for all such events of interest and will make sure they are continuously monitored and reviewed. The Analyst upholds defined service level agreements (SLA) and customer service excellence.
Key Responsibilities
- Monitoring and analysis of cyber security events
- Fully operate from Cradle to Grave the incident response process
\- Excellent understanding of Windows and Linux OS internals
- Excellent knowledge of protocols like HTTP, HTTPS, TCP/IP, WebSocket, SSH, SFTP, RDP etc.
- Good understanding of industry models such as the Cyber Kill Chains, Model and MITRE ATT&CK framework
- Practical hands‑on experience analysing Windows & Linux artifacts from digital forensics and incident response
- Good understanding of cyber threat landscape, TTPs, threat actors and groups
- Ensure Security Incidents are raised and managed in line with defined processes
- Escalate incidents and appropriately manage and record them
- Handle security incidents and take ownership
- Proactively manage internal and external security services to identify threats to infrastructure and services including Log Management
- Proficiency with the following tools
- EDR
- Anti‑Viral/NGAV
- HIPS, ID/PS, DLP, WAF
- SIEM – Log Rhythm, QRadar and Splunk
- Experience with SIEM technologies (Splunk etc), Threat hunting, monitoring and investigations
- Communicate new ideas or suggestions for analysis/process improvement
- Deep understanding of logging mechanisms of Windows, Linux platforms
- Participate in a 24x7 (On‑Call) coverage model to prevent and remediate security threats
\- Knowing how to script in languages such as Python, PowerShell, Bash to build incident response workflows and automation is a plus
- Have excellent written and verbal communication skills
- Possess good technical understanding, take initiative to remain up to date with cyber security skills and foster an attitude of continual learning/adapting
- Possess the ability to adjust and adapt to changing priorities in a dynamic environment
- Knowledge of and experience with Palo Alto, Checkpoint or Cisco firewalls is a plus
- Ability to work with minimum guidance
Experience
Security Operations Centre (SOC) environment experience with at least 3+ years of experience detecting and responding to cyber intrusions in an Operations Technology environment.
Bachelor’s degree or equivalent combination of education and 3 years of experience in computer science, computer engineering, or related field.
Certifications
List of certificates are knowledge equal to it.
SANS GIAC; GCED; GCIH; GCFA; GREM; GIAC GOLD. ISC CCFP; CSIH. EC Council ECSA; CHFI; ECIH, CompTIA CYSA+; Sec+, N+, Palo Alto, Cisco and Checkpoint certificates.
It’s good to have at least anyone of the above listed certs “is a plus”, but not mandatory.
Physical Requirements
Provide 24x7 support coverage and work on weekends and STATE Holidays.
CDW is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status or any other basis prohibited by state and local law.