Network/Security Engineer [28580]
Individual with ability to deploy and manage the following: ISE, ESA, WSA, Stealthwatch (Cloud and Enterprise), Meraki gear with some SIEM experience.Key ResponsibilitiesManage the security event monitoring and incident response ticket queues and triage as appropriate to meet the established service level agreementsPromptly transfer cybersecurity tickets to the client or internal point of contactClearly convey indicators of compromise, isolation, and remediation stepsAnalyze and interpret system, security, and application logs in order to diagnose faults, spot abnormal behavior, and rule out false positivesEffectively utilize End Detection and Response tools to investigate alerts, anomalies and build accurate timelines related to possible compromiseFollow established procedures to investigate, escalate, contain, or eradicate malicious activityDevelop and deliver written and oral reports to clients, teammates, and management to aggregate and communicate security information and metricsProvide input and recommendations to improve internal processes and procedures related to SOC duties and responsibilitiesParticipate in threat hunting activities and other special projects as requiredUnderstand and follow “The VC3 Way”. This is our set of standards and processes that produce a predictable result for the client. You must be aware of and maintain our standardsSkills, Knowledge and ExpertiseTwo years’ work experience in the Information Security or related fieldsTwo or more current security-related industry certificationsExperience with SIEM platforms, firewall management, and endpoint detection and response platformsOne year or more of experience with EDR solutions, ESGs, vulnerability management and content filteringGood problem solving and decision-making skills; ability to understand and analyze complex issuesSelf-motivated, detail orientated, highly organized and able to handle a variety of tasks and responsibilities in an efficient manner with a high level of qualityOne of the following certifications preferred: CompTIA Security+, CompTIA CySA+, CCNA, C|EH, SSCP, or equivalent