A leading cybersecurity firm is seeking a Security/Soc Analyst III for a 6-month contract opportunity in Houston, TX. The ideal candidate will have over five years of experience in the security domain, including incident response and threat monitoring. Responsibilities include performing security monitoring, incident response, and determining detection requirements for SIEM onboarding. Hands-on experience with various security technologies is essential for this role.
Qualifications
5+ years of experience in the security domain.
Hands-on experience in incident response and threat monitoring.
Ability to interpret code to support detection case development.
Responsibilities
Perform security monitoring and incident response of cybersecurity events.
Triage offenses for false positives.
Determine detection requirements for data sources onboarded to SIEM.
Define detection requirements for data sources onboarded to SIEM and identify gaps in the detection scheme.
Leverage security tech data to refine detections across multiple sources.
Interpret code to support detection case development.
Skills
Incident Response
Threat Monitoring
Triage Offenses
Detection Scheme Development
Cybersecurity Event Analysis
Tools
SIEM
Endpoint Detection and Response
Firewall/IPS/IDS
Proxy
Data Loss Prevention
Authentication
Job description
Exciting Security / Soc Analyst III, 6 months contract opportunity in Houston, TX.
5 plus years experience in the security domain, Incident Response, threat monitoring, and handling incidents (incident triage and response)
Determine detection requirements for data sources being on-boarded to the SIEM, and assessing the value of in place SIEM detection cases, in order to determine gaps and overlap in the overall detection scheme.
Perform security monitoring and incident response of cyber security events for proper determination of being considered a cybersecurity event.
Triage offenses for false positives
Hands‑on experience defining detection or protection schemes based on industry standards and frameworks.
SIEM, Endpoint Detection and Response, Firewall/IPS/IDS, Proxy, Data Loss Prevention, Authentication
Experience leveraging data from security technologies and referential data sources to define security detection requirements, including detections which correlate data across multiple data sources.
Ability to interpret code in the support of detection case development.