Overview
The Cyber Intrusion Analyst II within the Monitoring and Response team supports global enterprise information security services under the Chief Security Officer. The Analyst leads one or more enterprise security services including cybersecurity monitoring & analysis, incident response, investigations & data forensics, insider threat & threat intelligence, cybersecurity automation & development, and cloud security.
Responsibilities
- Operate and monitor network intrusion detection and prevention sensors and other information security monitoring infrastructure.
- Collect, assess, and report relevant threat intelligence and actionable security information; modify tactical operations accordingly.
- Perform analysis and response to Tier I & II security relevant alerts and events.
- Assess network traffic patterns and session data for indicators of malicious activity.
- Support rapid and effective response to information security incidents.
- Perform operational assessment, prioritization, and remediation of enterprise vulnerabilities and exposures.
- Generate, edit, and deliver reports derived from security tools and GSOC activities.
- Support forensic investigations and penetration testing activity.
- Assist the automation and improvement of the overall cloud security posture at Asurion.
- Assist with executing remediation plans for gaps reported in audits or recommended process improvements.
- Update job knowledge by tracking emerging security practices, participating in education, reading professional publications, and engaging in professional organizations.
- Perform other related duties as assigned.
Qualifications
- BA or BS in Computer Science, Management Information Systems, or related field; MS or additional certifications is a plus.
- At least 3 years of progressive experience in computing and information security, with experience in internet technology, security technology, issue resolution, and leading cross‑functional teams in a global setting.
- Certifications such as CISSP, GSEC, GCIA, GCIH, GCFA, EnCE or related credentials are desired.
- Solid understanding of core network protocols (TCP/IP, ICMP, DHCP, DNS, etc.).
- Familiarity with key security technologies: SIEM tools (Splunk, ArcSight, LogLogic), network intrusion detection/prevention tools, DLP packages, host IDS, AV & EDR, endpoint management, network anti‑malware (FireEye, Palo Alto), forensic tools (EnCase, FTK, etc.).
- Familiarity with common object‑oriented programming languages (Python, Java, C#, etc.) is desirable.
- Strong analytical, problem‑solving, communication (oral, written, presentation), interpersonal, and consultative skills.
- Ability to operate under ambiguous circumstances, address uncomfortable issues, and use data to make informed decisions.
- Availability for weekend, evening, and off‑hour assignments.
Equal Opportunity Statement
Asurion is an equal opportunity employer. We hire the best available person for the job regardless of marital status, sex, gender orientation, age, religious belief, race, nationality and ethnic origin, color, or disability.