Job Summary Cyber Security Analyst
- Work as part of the First Line of Defense (1LoD) team to proactively identify and analyze cyber threats.
- Collaborate closely with a senior cybersecurity specialist in a knowledge-sharing environment.
- Conduct proactive threat hunting across endpoints, networks, and cloud environments.
- Analyze security data from SIEM, EDR, and other telemetry sources to detect anomalies and threats.
- Investigate and interpret network traffic, endpoint telemetry, and log data for indicators of compromise (IOCs) and adversary tactics.
- Develop and fine-tune detection rules, alerts, and dashboards for improved threat detection and response.
- Perform deep-dive investigations of suspicious activity and produce detailed analysis and reports.
- Work with threat intelligence teams to correlate internal findings with external threat data.
- Participate in developing threat hunting playbooks and enhance detection methodologies.
- Assist in preparing reports and presentations for both technical and non-technical stakeholders.
- Support vulnerability management by identifying and tracking remediation of security gaps.
- Stay updated on emerging threats, attack techniques, and cybersecurity best practices.
- Utilize knowledge of MITRE ATT&CK, kill chain models, and adversary emulation.
- Operate and analyze data using SIEM (CrowdStrike, Sentinel, QRadar) and EDR tools (CrowdStrike, Defender).
- Leverage email protection systems (Mimecast, Defender, Purview) in security operations.
- Apply basic scripting (Python, PowerShell) for automation and data parsing tasks.
- Maintain strong analytical, investigative, and communication skills.
- Preferred certifications: CompTIA Security+, CySA+, GSEC, CSA, Microsoft SC-200.