• Conducts network monitoring and intrusion detection analysis using various Computer Network Defense (CND) tools, such as Intrusion Detection/Prevention Systems (IDS/IPS), Firewalls, NAC, Vulnerability Management tools, and Host Based Security System (HBSS), etc.
• Correlates activity across networks, applications, and systems to identify trends of unauthorized use or opportunity for misuse
• Reviews alerts and data from sensors and documents formal, technical incident reports
• Researches emerging threats and vulnerabilities to aid in the identification of incidents
• Analyzes data from threat and vulnerability feeds and analyzes data for applicability to the organization
• Identifies and resolves false positive findings in assessment results
• Performs compensating controls analysis and validates efficacy of existing controls
• Generates reports on assessment findings and summarizes to facilitate remediation tasks
• Develops and enforces computers, software, switch and routers security standards
• Supports the creation of business continuity/disaster recovery plans, to include conducting disaster recovery tests, publishing test results, and making changes necessary to address deficiencies
• Recommends improvements to the Information Security Program to the Information Security Director
• Plans, develops, and executes vulnerability scans of organization information systems
• Ensures compliance with all applicable configuration standards
• Manages enterprise vulnerability assessment and configuration assessment tools
• Recommends security controls and/or corrective actions for mitigating technical and business risk
• Produces vulnerability, configuration, and coverage metrics and reporting to demonstrate assessment coverage and remediation effectiveness
• Technical expertise in analyzing threat event data, evaluating malicious activity, documenting unusual files and data, and identifying tactics, techniques and procedures used by attackers
• Technical expertise in system security vulnerabilities and remediation techniques, network and web-related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, etc.)
• Technical expertise in security engineering, system and network security, authentication and security protocols, cryptography, and application security
• Strong decision-making, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one
• An understanding of business needs and commitment to delivering high-quality, prompt, and efficient service to the business
- مجال الشركة:
- خدمات تكنولوجيا المعلومات
- الدور الوظيفي:
-
تكنولوجيا المعلومات