Security Analyst/Engineer
REDMOND, WA- HYBRID
NOTES: YOU WILL NEED TO MAKE SURE AND INCLUDE A SEPERATE ATTACHMENT WHEN YOU ATTACH THE RESUME WITH A WRITE UP FROM THE CANDIDATE
Describe your experience with IDS/IPS, including specific tools and how they fit into a larger security architecture.
Job Description, Role & Responsibilities :
• Ability to conduct T1 & T2 triage of security events (network events, email events, endpoint events, cloud events)
• Ability to drive security event investigations end to end
• Ideally be familiar with Splunk ES, Crowdstrike, Proofpoint, Wiz to shave on training time
• Escalate AD findings
• Escalate external attack surface findings
• Escalate network threat findings
• Suggest detection rules for event findings
• Tune FP detection rules
Operations Work
• Update security tools
• Update security certificates
• Review net new networks
• Assess vulnerability scanning zones and update scanning