Description
At CDW, we make it happen, together. Trust, connection, and commitment are at the heart of how we work together to deliver for our customers. It’s why we’re coworkers, not just employees. Coworkers who genuinely believe in supporting our customers and one another. We collectively forge our path forward with a level of commitment that speaks to who we are and where we’re headed. We’re proud to share our story and Make Amazing Happen at CDW.
Job Description
The Analyst performs in depth investigation of security incidents, writes an incident report with details of the investigation findings, initiates response actions if applicable and provides applicable recommendations and next steps to the client based on the findings from the investigation. The Analyst applies trusted advisor techniques on all engagements with clients.
What You’ll Do:
Services Delivery (65%)
- Monitor, analyze, and triage cyber security alerts on the SIEM/EDR/XDR tool by applying industry accepted analytics techniques and cyber security frameworks such as Kill Chain and MITRE ATT&ACK.
- Take ownership of in-scope cyber incident investigations.
- Create, manage, and follow up on service tickets.
- Monitor and manage request and incident queues and provide response and resolution within Service Level Agreement and Service Level Objective.
- Follow defined processes for incident response.
- Correlate event details within the incident timeline to identify malicious activities leveraging SIEM/EDR/XDR tool.
- Carry out extended searches for leveraging the SIEM platform to provide in depth investigation and identify full attack path where applicable.
- Design, create, and update documentation as directed.
- Research and analyze threat intelligence and indicators of compromise (IOC) for applicability during incident investigation.
- Review alerts, decipher false positives, and follow through on incident investigations.
- Evaluate risk of security alerts and make appropriate recommendations to mitigate evaluated risks.
- Update service tickets and cases with investigation evidence.
- Apply Trusted Advisor techniques to build up client trust and influence loyalty.
- Carry out rapid IOC searches based on given IOC obtained from threat intelligence feeds across clients’ endpoint/extended detection and response platforms.
- Open technical support cases with respective vendors where applicable
- Escalate issues encountered during the shift to the Manager.
Professional Development (35%)
- Attend training sessions or shadowing activities and obtain industry-related certifications as determined by the Manager.
- Participate in all in-house CTFs and self-paced training.
Qualifications
What You Need to Succeed:
Must-Have:
- Bachelor's degree (B.A./B.S.) or 3-year diploma in Engineering, Computer Science, or Technology related field
- At least 1 year of work experience in supporting information technology/systems.
- At least one (1) technical certification in the technologies for which Sirius offers Managed Security Services. These may include, but are not limited to: QRadar, LogRhythm, Exabeam, Splunk or similar technology.
- Any of these security focused certifications: Comptia Security +, Comptia CYSA, SANS: GCIA, GCIH, CEH
Other Position Requirements:
- The candidate must be proactive and pay attention to details.
- works collaboratively with other teammates.
- Takes ownership and drives issues towards a resolution.
- A good understanding of IT infrastructure systems, Cybersecurity fundamentals, vulnerability management fundamentals, endpoint and server administrations, network routing and switching, network traffic analysis and administration.
- Ability to acquire technical skills and certifications required to effectively execute the role, develop familiarity with industry or specialty products/services, and apply the knowledge gained through training.
- Ability to investigate problems and use standard operating procedures and processes to resolve them.
- Good troubleshooting and problem-solving skills. Possess an innate curiosity and critical thinking mindset.
- Ability to establish positive working relationships and contribute to team objectives in a consulting environment.
- Good verbal, written communication skills and the confidence to engage the clients effectively.
- Proven time management and organizational skills
- Word, Excel, Visio, PowerPoint, and Outlook skills
Nice-to-have:
- Previous experience working in a Security Operations Centre (SOC) environment or similar environment.
Essential Functions:
The position is part of a 7 day per week, 24 hour per day managed services operations. To provide the required coverage, must be willing to work other shifts including weekends, holidays, and overtime.
The above primary duties, responsibilities, and position requirements are not all inclusive.
At CDW, we strive to offer market-competitive total rewards packages to attract and retain talent. As such, we are committed to pay transparency and ensuring fair compensation for all our coworkers. Each of our roles is assigned a salary range that is informed by multiple sources of market data. We determine individual pay within a given range based on a candidate's prior experience, knowledge, skills and abilities. This approach allows us to offer competitive and equitable salaries that reflect the value and responsibilities of each role at CDW.
Salary : $60,000
We make technology work so people can do great things.
CDW is a leading multi-brand provider of information technology solutions to business, government, education and healthcare customers in the United States, the United Kingdom and Canada. A Fortune 500 company and member of the S&P 500 Index, CDW helps its customers to navigate an increasingly complex IT market and maximize return on their technology investments. Together, we unite. Together, we win. Together, we thrive.
CDW is an equal opportunity employer. All qualified applicants will receive consideration for employment without regards to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status or any other basis prohibited by state and local law.
Read Full Description