Overview
Duration: 1 year + extension Aquent is proud to partner with a leading organization at the forefront of delivering essential services, where safeguarding critical infrastructure and data is paramount. This organization is committed to operational excellence and relies on robust cybersecurity measures to ensure continuous, reliable service for its customers. Join their vital cybersecurity team and play a crucial role in protecting their digital landscape, directly contributing to the security and resilience of their operations. Unleash Your Impact Are you ready to be a frontline defender in the ever-evolving world of cyber threats? We are seeking dynamic individuals to step into a critical role within a 24/7 Security Operations Center (SOC). As a key member of the team, you will be instrumental in the initial detection, analysis, and response to security incidents, making a tangible impact on the organization's security posture. This is an exciting opportunity for a curious, analytical, and highly motivated professional to contribute to a fast-paced environment, leveraging cutting-edge tools to protect vital assets and ensure operational continuity for countless customers. What You'll Be Doing
- Monitor and analyze security events and alerts generated from SIEM platforms, including Splunk, and other critical security tools.
- Perform initial triage and in-depth investigation of alerts to accurately determine their severity, scope, and potential impact on systems and data.
- Analyze logs, network activity, endpoint data, and email security alerts (e.g., Proofpoint) to proactively identify and mitigate malicious activity.
- Enrich security alerts with vital contextual data, including threat intelligence, asset information, and user behavior analytics, to facilitate informed decision-making.
- Follow defined escalation paths to more senior analysts (Tier 2/3) based on the severity, confidence, and impact of detected incidents.
- Document all incidents, findings, and actions taken thoroughly within case management systems, ensuring comprehensive records.
- Execute basic response actions and automated playbooks using SOAR platforms, such as Splunk SOAR, to streamline incident resolution.
- Assist in containment actions for active threats under the expert guidance of senior team members.
- Contribute to 24/7 SOC operations, including participating in shift work (nights, weekends, holidays), ensuring continuous monitoring and robust response capabilities.
- Actively participate in shift handoffs, providing comprehensive updates to maintain seamless situational awareness across the team.
- Stay current on emerging threats, vulnerabilities, and attack techniques to continuously enhance detection and response capabilities.
- Provide valuable feedback for the tuning of detection rules to improve alert fidelity and significantly reduce false positives.
What You'll Bring to the Team
- Minimum 2 years of experience in a 24/7 Security Operations Center (SOC) environment is highly preferred.
- An Associate degree in Cybersecurity, Information Technology, or a related field, OR equivalent practical experience in a SOC setting.
- **Active CompTIA Security+ Certification is required.**
- Demonstrated experience with security tools such as Splunk, Splunk SOAR, and Proofpoint.
- Proven experience in triaging security alerts and diligently following established escalation processes.
- Foundational knowledge of networking fundamentals and log analysis techniques.
- Familiarity with Microsoft and Azure security platforms and services.
- Strong analytical thinking and problem-solving skills to dissect complex security incidents effectively.
- Exceptional attention to detail in monitoring, investigation, and documentation.
- Excellent communication skills, both written and verbal, for effective collaboration and incident reporting.
- Adaptability and resilience to thrive in a fast-paced, dynamic cybersecurity environment.
- A high degree of curiosity and initiative to continuously learn and improve your skills.
- A collaborative spirit, working effectively within a team to achieve common security goals.
Stand Out With These
- CompTIA CySA+ certification.
- Splunk Core Certified User certification.
- Microsoft Security certifications (e.g., SC-200, AZ-500).
Important Considerations This role operates within a 24/7 Security Operations Center environment, which includes working nights, weekends, and holidays. You may also be required to be on-call or work extended hours during critical incidents to ensure continuous protection. Must be authorized to work in the US. W2 employment only (no visa sponsorship available; no C2C/subcontracting).
|