• Monitor level 1/2 analyst performance by investigating incoming events using SOC-available tools.
• Ensure level 1/2 event(s) are addressed in a timely manner using available reporting and metrics.
• Approve and, if necessary, further investigate level 1-escalated events.
• Mentor level 1/2 analysts to improve detection capability within the SOC.
• Conduct research, analysis, and correlation across a wide variety of all
source data sets (indications and warnings).
• Manage SOC event and information intake to include gathering intelligence
reports, monitoring ticket queues, investigating reported incidents, and
interacting with other security and network groups as necessary.
• Serve as detection authority for initial incident declaration.
• Determine the extent of threats and recommend courses of action or
countermeasures to mitigate risks.
• Function as shift subject-matter experts (SMEs) on incident detection and
analysis techniques, providing guidance to junior analysts and making
recommendations to organizational managers.
• Drive and monitor shift-related metrics processes ensuring applicable
reporting is gathered and disseminated per SOC requirements.
• Provide timely detection, identification, and alerting of possible
attacks/intrusions, anomalous activities, and misuse activities and
distinguish these incidents and events from benign activities.
• Use cyber defense tools for continual monitoring and analysis of system
activity to identify malicious activity.
• Analyze identified malicious activity to determine weaknesses exploited,
exploitation methods, effects on system and information.
• Conduct analysis of log files, evidence, and other information to
determine best methods for identifying the perpetrator(s) of a network
intrusion.
• Characterize and analyze network traffic to identify anomalous activity and
potential threats to network resources.
• Analyze computer-generated threats for counter intelligence or criminal
activity.
• Validate intrusion detection system ( IDS ) alerts against network traffic
using packet analysis tools.
• Gather and analyze data (e.g., measures of effectiveness) to determine
effectiveness, and provide reporting for follow-on activities.
• Conduct analysis of log files, evidence, and other information to determine
best methods for identifying the perpetrator(s) of a network intrusion.
• Provide daily summary reports of network events and activity relevant to cyber defense practices.
• Capture and analyze network traffic associated with malicious activities
using network monitoring tools.
• Serve as a backup analyst for any potential coverage gaps to ensure
business continuity.
• Monitor and evaluate integrated SOC operations to identify opportunities
to meet organization objectives.
• Monitor and report changes in threat dispositions, activities, tactics,
capabilities, objectives, etc. as related to designated cyber operations
warning problem sets.
• Monitor and report on validated threat activities.
• Monitor operational environment and report on adversarial activities which
fulfill leadership’s priority information requirements.
• Monitor target networks to provide indications and warning of target
communications changes or processing failures.
• Document lessons learned that convey the results of events and/or
exercises.
• Facilitate the sharing of “ best practices ” and “lessons learned”
throughout the cyber operations community.
• Communicate new developments, breakthroughs, challenges and
lessons learned to leadership, and internal and external customers.
• Participate in the development or modification of the computer environment
Cyber Security program plans and requirements.
- مجال الشركة:
- أمن المعلومات و الشبكات
- الدور الوظيفي:
-
تكنولوجيا المعلومات