Security Operations Centre Analyst
Confirmed
Location
Various locations
Security Clearance
EU / NATO clearance eligible
Skills, Knowledge, Experience Required
- Minimum 3 years of experience as a SOC Analyst and/or first line incident responder;
- Minimum 3 years of experience in the security analysis of firewall, proxy, and IDS logs;
- Minimum 3 years of experience in the security analysis of Applicable or Middleware logs (Oracle, Apache, Weblogic );
- Minimum 3 years of experience in networking (TCP/IP, SNMP, DNS, Syslog-ng, etc.);
- Minimum 3 years’ experience with:
- SIEM (Arcsight ESM 6.x, Q-RADAR, or equivalent - subject to acceptance by the contracting EU-I)
- Log management solution (Arcsight Loggers and/or QRADAR and/or Splunk or equivalent - subject to acceptance of the contracting EU-I))
- Minimum 2 years’ experience with:
- CheckPoint and Juniper Firewalls
- BlueCoat proxies
- SNORT or SourceFire NGIPS, FireSIGHT
- Minimum 1 year of experience in using, configuring and tuning a SIEM;
- Minimum 2 years of experience in Host based security solutions;
- HIPS
- Malware end-point protection
- OS logs
- Minimum 2 years of experience in network security solution/technologies:
- Firewalls;
- Network IDS and IPS;
- Switches and routers
- APT detection solutions such as FireEye
- DNS, DHCP, VPN
- Network forensics (full packet capture)
- Traffic baselining analysis
Minimum 3 years of experience in:
- Windows security events analysis
- Writing and optimizing IDS signatures (preferably SNORT and/or SURICATA)
- Writing and optimizing YARA rules
At least 1 certification among the following:
- GCIH (GIAC Certified Incident Handler)
- GCIA (GIAC Certified Intrusion Analyst)
- ECIH (EC-Council Certified Incident Handler)
- CSIH (SEI Certified Computer Security Incident Handler)
- SCPO (SABSA Certified Security Operations & Service Management Practitioner)
- or an equivalent certification recognized internationally (subject to acceptance as a valid credential by the Contracting EU-I)
Desirable
- Minimum 2 years of experience with STIX (Structured Threat Information Expression) with a particular focus on the following related standards:
-
CybOX (cyber observables);
- CAPEC (attack patterns);
- MAEC (malware);
- TAXII (threat information exchange).
- Minimum 1 year of experience with:
- Suricata/ StamusNetworks;
- ELK (ElasticSearch, Logstash & Kibana)
- FireEye Ex, Nx , Ax, Fx , Hx, Ix
VECTOR SYNERGY sp. z o.o., ul. Marcelińska 90, 60-324 Poznań, NIP PL7811857270, REGON 301575740, KRS: 0000369575
Rejestr Przedsiębiorców KRS prowadzony przez Sąd Rejonowy Poznań – Nowe Miasto i Wilda w Poznaniu, VIII Wydział Gospodarczy KRS, kapitał zakładowy wynosi: 7 1 65 0,00 złotych wpłacony w całości, TEL +48 616684500, FAX +48 616684501, www.vectorsynergy.com , info@vectorsynergy.com