All jobs

Cybersecurity Analyst SOC Levels 3-5

100% Remote Full-time Open now

About the position The purpose of this position is to provide critical technical expertise in the detection, analysis and response to cybersecurity events. Cybersecurity Analyst will be responsible for early and accurate detection, prevention response, containment, and guidance to remediation of threats directed against the MTA on a 24/7 basis. The analysis is conducted through technology risk assessments, data analytics tools, business processes reviews and collaborate with security engineers, architects, developers, vendors, business units to constantly improve the overall security of the MTA. The cybersecurity analyst will focus on specific domains and specialties within cybersecurity with a great degree of specialty to detect, protect and advise the organization proactively and reactively. The Cybersecurity Analyst will be a member of the Cyber Security Operation Center "CSOC". This role will conduct real-time 24/7 security monitoring and intrusion detection analysis using a Security Incident & Event Management system "SIEM" along with various technology and analytic tools, such as web and next generation firewalls, machine and human behavior learning tools, host-based security system, security event and incident monitoring systems, virtual, physical, and cloud platforms, user endpoint (laptop, desktop, mobile, and internet of things/IOT) systems, etc. The Analyst will research emerging threats and vulnerabilities to aid in the identification and analysis of network incidents, and supports the creation or improvement of security controls, policies, standards, and guidance to address them.

Responsibilities

  • Researching emerging threats and vulnerabilities to aid in the identification of network incidents, and supports the creation of new architecture, policies, standards, and guidance to address them
  • Provide incident response support, including mitigating actions to contain activity and facilitating forensics analysis when necessary
  • Conducts security monitoring and intrusion detection analysis using various technology and analytic tools, such as web and next generation firewalls, machine and human behavior learning tools, host-based security system, security event and incident monitoring systems, virtual, physical, and cloud platforms, user endpoint (laptop, desktop, mobile, and internet of things/IOT) systems, etc.
  • Correlates events and activities across systems to identify trends of unauthorized use
  • Reviews alerts and data from sensors and documents formal, technical incident reports
  • Tests new systems and manage cybersecurity risks and remediation through analysis
  • Responds to computer security incidents according to the computer security incident response policy and procedures
  • Provides technical guidance to first responders for handling information security incidents
  • Provides timely and relevant updates to appropriate stakeholders and decision makers
  • Communicates investigation findings to relevant business units to help improve the information security posture
  • Validates and maintains incident response plans and processes to address potential threats
  • Compiles and analyzes data for management reporting and metrics
  • Monitors relevant information sources to stay up to date on current attacks and trends
  • Analyzes potential impact of new threats and communicates risks back to detection engineering functions
  • Performs root-cause analysis to document findings, and participate in root-cause elimination activities as required
  • Works with data sets to identify patterns
  • Understands data automation and analysis techniques
  • Uses judgment to form conclusions that may challenge conventional wisdom
  • Hypothesizes new threats and indicators of compromise
  • Monitors threat intelligence feeds to identify a range of threats, including indicators of compromise and advanced persistent threats (APTs)
  • Identifies the tactics, techniques and procedures (TTPs) of potential threats through the MITRE ATT&CK or similar frameworks
  • Participate in the creation of enterprise security documents (policies, standards, baselines, guidelines, and procedures) under the direction of the IT Security Manager, where appropriate.
  • Perform Contract management and supply management functions appropriate to reduce security risks Requirements
  • Bachelor's Degree and minimum 1 year of relevant experience for Level 3
  • Bachelor's degree in Computer Science or related fields preferred
  • CISSP or other advanced security-related certification preferred but not required
  • Certifications in technology subdomains preferred but not required (ie. Cloud, Applications, Infrastructure, Security Technology, etc.)
  • Requires prior experience with installing, maintaining and troubleshooting technology systems
  • Proven ability to troubleshoot and support technical issues using standardized procedures
  • Proven ability to analyze a security risk assessment or conduct one with guidance
  • Understanding of Operating Systems and Hardware
  • Understanding of TCP/IP (OSI Layers 1- 4) and Internet and Intranet technologies required (OSI Layers 5-7) required
  • Scripting or programming skills (PERL, Python, PowerShell, etc.) preferred as needed
  • 1 year of experience in a specific (Cloud, Applications, Infrastructure, Security Technology, etc.) cybersecurity subdomain is preferred Nice-to-haves
  • 3+ years of relevant experience in a specific cybersecurity subdomain for Level 4
  • 5+ years of relevant experience in a specific cybersecurity subdomain for Level 5
  • Must possess at least one of the following professional certifications in subject domain including but not limited to: Certified Information Security Professional (CISSP), or Global Information Assurance Certification (GIAC), or Certified Information Security Manager (CISM), or Certified in Risk and Information Systems Control (CRISC), or Certified Information Systems Auditor (CISA), or other related certification(s)
  • Progressive cybersecurity related accomplishments
  • Requires broad technical knowledge of multiple technologies, or an in-depth knowledge of one technology including its impact on other technologies Apply tot his job

Apply tot his job Apply To this Job

You might also like

Cybersecurity System Engineer- Early Career with Security Clearance

100% Remote Full-time

Jr. Security Operations Analyst: Entry Level, Full Time (Remote)

100% Remote Full-time

Junior Medical Coder – Remote Role for Fresh Graduates

100% Remote Full-time

Senior Epidemiologist, Oncology, Breast Cancer, Real World Evidence - FSP (Sponsor Dedicated)

100% Remote Full-time

[Hiring] Case and Contact Investigator (Epidemiologist I) @CDC Foundation

100% Remote Full-time

[Remote] Associate Director, Operational Accounting

100% Remote Full-time

Associate Attorney, Northern Rockies

100% Remote Full-time

Conflicts Attorney I

100% Remote Full-time

Data Analyst (Epidemiologist II)

100% Remote Full-time

Senior Project Manager (EST Time Zone) (Higher Education/SaaS/ERP)

100% Remote Full-time

Werkstudent GTM / Marketing (m/w/d)

100% Remote Full-time

Insurance Billing Order Entry Specialist-Temp

100% Remote Full-time

Staff Data Scientist

100% Remote Full-time

Experienced Customer Support Specialist – Remote Customer Service Representative

100% Remote Full-time

Wintel Engineer

100% Remote Full-time

Regional Gene Therapy Liaison - East Coast

100% Remote Full-time

Experienced Remote Data Entry Specialist – Aviation Industry Administration

100% Remote Full-time

Analyst - Business Management, Global Corporate & Investment Banking

100% Remote Full-time

Experienced Senior Technology Consultant for Remote Inflight Connectivity and WiFi Platform Enhancement

100% Remote Full-time

Hobby Lobby Remote Job Entry Level Work From Home $30/Hour

100% Remote Full-time