Tier-1 Security Analysts

Tier-1 Security Analysts

Location: Remote - Preferred EST Time Zone

Duration: 12 months (possible extension)

Shifts (choose one)

Mid Shift (4PM-12AM EST)

Night Shift (12AM-8AM EST)

Job Duties:

Information Security Analysts are the backbone of the Security Operations Center (SOC), providing crucial support to enterprise-level customers. Tier-1 Security Analysts with at least one year of experience in security or technical troubleshooting roles, such as help desk, handle various tasks across various platforms. They play a pivotal role in the Security Incident and Event Management (SIEM) workflow, serving as the 24x7 "eyes on glass" who monitor alerts and escalate incidents as necessary.

Responsibilities:

  • Conduct near real-time security monitoring in a 24x7 environment, utilizing proprietary SIEM and cybersecurity tools to identify Indicators of Compromise (IOCs).
  • Monitor alert health in near real-time and escalate critical alerts according to service level agreements.
  • Detects and analyzes security incidents, particularly complex or escalated events, to assess threats effectively.
  • Address customer Requests For Information, leveraging soft and technical skills to query raw logs for IOCs, provide insights into SOC infrastructure, and offer guidance on SIEM features and best practices.
  • Perform level 1 assessment of incoming alerts, prioritizing and correlating details to determine severity within the customer environment and coordinating with tier II/III for critical incidents as needed.
  • Execute basic incident response activities using customer SIEM and cybersecurity toolkits.
  • Contribute to the SOC Knowledge Base and provide input for revisions.
  • Draft clear and concise escalation tickets.

Must-Have Skills:

  • Associate degree in Computer Science, Information Security, or a related field.
  • 1 to 3 years of experience in a security-related role.
  • Fundamental knowledge of Cyber Security technologies.
  • Understanding of the threat landscape and indicators of compromise.
  • Strong problem-solving skills.
  • Proactively engage with customers, client executives, and management teams.
  • Excellent documentation and communication abilities in written and oral English.

Desired Skills:

  • Bachelor's degree or higher in Computer Science, Information Security, or a related field.
  • One or more years of experience in an Information Security Analyst position.
  • Familiarity with basic cyber threat hunting techniques.
  • Experience in incident response using different SIEMs and adhering to industry best practices.
  • Proficiency in investigating security incidents, developing/tuning use cases, and understanding incident response protocols.
  • Ability to create new content, searches, and scripts for tools like Splunk, QRadar, Sentinel, etc.
  • Understanding of device logging, network troubleshooting, and device troubleshooting.
  • Experience with incident response techniques such as network forensic analysis.
  • Familiarity with Intrusion Prevention Systems (IPS) and analyzing alerts generated by inspection.
  • Scripting knowledge in languages like Python, Powershell, Bash Shell, Java, Ansible, etc.
  • Relevant security certifications such as SANS GIAC, GCIH, CompTIA Security+, CCNP-Security, CySA+, GCED, CEH, or similar credentials.
Back to blog

Other Jobs To Apply

No other job posts for this day.

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...