noris network AG logo
noris network AG

Mehr Leistung als Standard

Senior IT Security Analyst

Security AnalystSecurity AnalystFull TimeRemoteSeniorTeam 501-1,000Since 1993H1B No SponsorCompany SiteLinkedIn

Location

Germany

Posted

45 days ago

Salary

0

Seniority

Senior

Bachelor DegreeGermanEnglishLinux

Job Description

Senior IT Security Analyst

noris network AG

• Formulating hypotheses about potential threats • Manual and partially automated analysis of IT systems and validation of hypotheses using SIEM • Proactive and iterative threat hunting through networks to detect and isolate advanced threats • Improving the automated components of the detection system • Investigating potential risks and tracking suspicious network activity • Preparing IT security assessments for security-related incidents • (Partial) participation in IT projects, particularly in implementing security-related solutions • Planning and executing standard changes in accordance with ITIL • Participation in on-call duty

Job Requirements

  • Degree in Computer Science or equivalent qualification with an IT focus
  • Strong knowledge of security (IPS/IDS, threat intelligence, threat analysis and vulnerabilities)
  • Strong knowledge of IT security and networking environments, as well as system hardening
  • Strong knowledge in penetration testing and vulnerability management
  • Good knowledge of Linux and/or Windows
  • Practical experience in security process management
  • Programming experience with e.g. Python
  • Experience with Elastic is desirable and initial exposure to ServiceNow is an advantage
  • Structured, independent and solution-oriented way of working
  • Willingness to engage with and learn new technologies
  • Good written and spoken German and English

Benefits

  • Permanent contract and flexible working hours
  • Compensatory time-off credited to your time bank
  • Work at various locations possible (e.g. Nuremberg, Aschheim, Berlin) or 100% remote
  • High-quality equipment: laptop and company smartphone also for private use
  • Individual support and development through in-house training and external courses
  • Childcare allowance (per month/per child) and corporate benefits
  • Attractive company events (including travel expense coverage), a collegial and appreciative work environment, and a first-name culture from day one
  • Generous subsidy for the Deutschlandticket
  • Health management (e.g. free on-site massages), JobRad leasing and company pension with employer contributions
  • Welcome day, direct point of contact and a structured onboarding phase
  • Free beverages (including soft drinks) and fresh fruit at the offices

Related Job Pages

More Security Analyst Jobs

Prime System Solutions logo

SOC Analyst

Prime System Solutions

"Empowering Excellence, Ensuring Continuity, Uninterrupted Success"

Security Analyst45 days ago
Full TimeRemoteTeam 51-200Since 2023H1B No Sponsor

Description:  The Security Analyst I role is a critical position within the organization. The primary function of the role will be to provide monitoring of deployed customer environments for security events. This includes establishing the extent of a threat, the business impact, and advising the most suitable course of action to contain and remedy the event. A Cybersecurity Technician will serve as an escalation point to the subject matter expert for in-depth cybersecurity events and must be able to communicate effectively to all stakeholders during the event management process.  Responsibilities:  ·        Manage the security event monitoring and incident response ticket queues and triage as appropriate to meet the established service level agreements ·        Promptly transfer cybersecurity tickets to the client or internal point of contact ·        Clearly convey indicators of compromise, isolation, and remediation steps ·        Analyze and interpret system, security, and application logs in order to diagnose faults, spot abnormal behavior, and rule out false positives ·        Effectively utilize End Detection and Response tools to investigate alerts, anomalies, and build accurate timelines related to possible compromise ·        Follow established procedures to investigate, escalate, contain, or eradicate malicious activity ·        Develop and deliver written and oral reports to clients, teammates, and management to aggregate and communicate security information and metrics ·        Provide input and recommendations to improve internal processes and procedures related to SOC duties and responsibilities ·        Participate in threat-hunting activities and other special projects as required ·        Understand and follow, our set of standards and processes that produce a predictable result for the client. You must be aware of and maintain our standards. Additional Responsibilities:  ·        Maintain accurate and real-time timesheets, record complete and accurate notes of troubleshooting and communication with clients ·        Receive mentoring and feedback from peers and others ·        Where appropriate, escalate complicated issues to a more senior resource or other appropriate teams ·        Review Tickets with Manager ·        Actively Participate in Team Huddles, L10 Meetings, One on One Meetings, and any other Team Meetings ·        Create and update documentation when changes occur, or when discoveries are made ·        Attend monthly training & team meetings as required ·        Additional duties as required

South Africa
Zensar logo

DIGITAL SECURITY - SOC Services

Zensar

At Zensar, we’re “experience-led everything”. We are committed to conceptualizing, designing, engineering, marketing, and managing digital solutions and experiences for over 130 leading enterprises. We are a company driven by a bold purpose: Together, we shape experiences for better futures. Whether for our clients, our people, or the world around us, this belief powers everything we do. At the heart of our culture is ONE with Client - a set of four core values that reflect who we are and how we work: One Zensar, Nurturing, Empowering, and Client Focus. Part of the $4.8 billion RPG Group, we’re a community of 10,000+ innovators across 30+ global locations, including Milpitas, Seattle, Princeton, Cape Town, London, Zurich, Singapore, and Mexico City. We believe the best work happens when individuality is celebrated, growth is encouraged, and well-being is prioritized. We are an equal employment opportunity (EEO) and affirmative action employer, committed to creating an inclusive workplace. All qualified applicants will be considered without regard to race, creed, color, ancestry, religion, sex, national origin, citizenship, age, sexual orientation, gender identity, disability, marital status, family medical leave status, or protected veteran status.

Security Analyst45 days ago
Full TimeRemoteTeam 10,001

Vulnerability Management Specialist - Qualys ( Cyber security -Tool) As an vulnerability management specialist, you will support the SOC team in their daily activity and administrating Operational Security Processes. You will be asked to identify improvements in current processes and formalize it through clear documentation. Among the ongoing administration of Processes, your main responsibilities will be to manage the vulnerability scan process. The process is based on Qualys Tools. • Perform global infra vulnerability scanning along with change management process • Help system administrators to deploy and troubleshoot Qualys agent on different operating systems (Windows, Linux, AIX, etc) • Analyze scan results and deploy Qualys appliances(virtual and physical) to enhance scan coverage • Responsible for understanding, reviewing, and interpreting assessment and scanning results, reducing false positive findings, and acting as a trusted security advisor to the client. • Identify and prioritize all vulnerabilities in client environments and provide timely vulnerability assessment reports to key stakeholders • Develop and report enterprise-level metrics for vulnerabilities and remediation progress • User requests administration: manage users request on the platforms. Add Hosts, Assets Groups, create scan, report or Dashboard (using the standard and process delivered by SOC SG). Including Emergency stop of scan. • Manage Vulnerability Scan for GTS: Manage the Change management process to request a scan on GTS infrastructure. Manage the change creation, the achievement of the change process following by the job creation on Qualys platform. • Present Vulnerability Assessment Scanning and guidance, False Positive Validation, Compliance Scanning and, scan profile and policy creation. • Analysis of vulnerability: based on group standards, manage the alerting on critical vulnerability found by a vulnerability scan and follow the mitigation with remediation teams • Ability to identify false positives • Knowledge of vulnerability management frameworks and concepts such as CVE, and CVSS scoring systems and attacking vectors • Dashboard: generate monthly and quarterly reports and dashboards. • Understanding of Qualys tags • Manage Internal Qualys infrastructure: survey the status of Qualys appliances and manage the RMA process and deployment of new appliances. • Implement automated, proactive security measures • Hands on Qualys modules Vulnerability Management, Security Configuration Assessment(SCA)/Policy Compliance, Container Security, Cloud Agent, Container Security, Cloud security • Knowledge and experience on Terraform, python and any scripting is required Required Profile required • End to end understanding of Vulnerability management (scanning, remediation follow-up, false positive verification) • Conduct Network and System Vulnerability assessments and documentation of corrective/remediation actions • Drive the end-to-end vulnerability lifecycle from discovery to closure • Identify internal and external threats that could result in unauthorized disclosure, misuse, alteration, or destruction of customer's information assets • Identify and prioritize all vulnerabilities in client environments and provide timely vulnerability assessment reports to key stakeholders Ensure timely follow up with patch management and vulnerability remediation in coordination with Countermeasures personnel He/She has good knowledge in the Qualys Vulnerability assessment tool & Management . He/she has to complete certification in Qualys Guard: - Qualys VMDR - Qualys Cloud Agent - Qualys Policy Compliance - Qualys CSAM - EC-Council CEH At Zensar, we’re “experience-led everything”. We are committed to conceptualizing, designing, engineering, marketing, and managing digital solutions and experiences for over 130 leading enterprises. We are a company driven by a bold purpose: Together, we shape experiences for better futures. Whether for our clients, our people, or the world around us, this belief powers everything we do. At the heart of our culture is ONE with Client - a set of four core values that reflect who we are and how we work: One Zensar, Nurturing, Empowering, and Client Focus. Part of the $4.8 billion RPG Group, we’re a community of 10,000+ innovators across 30+ global locations, including Milpitas, Seattle, Princeton, Cape Town, London, Zurich, Singapore, and Mexico City. Explore Life at Zensar and join us to Grow. Own. Achieve. Learn. to be the best version of yourself. We believe the best work happens when individuality is celebrated, growth is encouraged, and well-being is prioritized. We are an equal employment opportunity (EEO) and affirmative action employer, committed to creating an inclusive workplace. All qualified applicants will be considered without regard to race, creed, color, ancestry, religion, sex, national origin, citizenship, age, sexual orientation, gender identity, disability, marital status, family medical leave status, or protected veteran status.

India

Security Analyst I

Ntiva

Ntiva, established in 2004, is a leading provider of IT consulting, managed IT services, cybersecurity solutions, and cloud-based technologies. The company is c

Security Analyst45 days ago

• Monitor & Investigate: Actively monitor security dashboards, queues, and alerts from various sources (automated tools, escalated tickets) to detect potential threats. • Incident Triage & Response: Conduct initial investigations into security alerts, perform rapid response actions like securing user accounts, and collect necessary log data for analysis. • Escalate Effectively: Analyze findings to determine the scope and severity of incidents, resolving straightforward issues and escalating complex cases to Level 2 Analysts with clear, concise information. • Security Tool Management: Review and implement authorized, routine changes to security tools, such as processing client exemption requests in the EDR or temporarily adjusting settings for testing. • Collaborate with the Security Team: Work closely with fellow analysts and security engineers, sharing information, participating in team discussions, and contributing to a collaborative security environment. • Engage with Users/Clients: Communicate professionally and clearly with end-users or clients to gather details about potential security issues, explain security procedures, and provide guidance during incident resolution. • Liaise Across Departments: Interact effectively with other teams (e.g., Reactive Support, Client Strategy, NOC) to coordinate security responses and share necessary information. • Document Actions: Maintain accurate and detailed records of investigations, actions taken, communications, and resolutions within ConnectWise. • Provide Support: Offer timely and helpful support related to security inquiries, upholding a professional and customer-service-oriented approach in all interactions.

Virginia
$55K - $68K / year
Job Closed
Full TimeRemoteTeam 11-50

cFocus Software seeks a Tier 1 SOC Analyst to join our program supporting the Congressional Budget Office (CBO). This position is remote. This position requires a Public Trust clearance. Qualifications: - Active Public Trust clearance - B.S. Computer Science, Information Technology, or a related field - Foundational knowledge of cybersecurity principles and SOC operations - Familiarity with SIEM tools, preferably Microsoft Sentinel - Understanding of common attack vectors and MITRE ATT&CK framework - Basic knowledge of networking, operating systems (Windows/macOS), and cloud environments - Strong analytical and problem-solving skills - Ability to follow procedures and work in a shift-based environment - Relevant certifications (e.g., Security+, CySA+, or equivalent) - Experience with Microsoft Defender tools (Endpoint, Identity) - Exposure to log analysis and incident response processes - Preferred certifications include but are not limited to - GCIA, GCIH, CISSP, CEH, or equivalent cybersecurity certifications - Microsoft Sentinel or Microsoft security platform certifications - Relevant cloud security certifications (e.g., AWS security) - Privacy certifications (e.g., CIPP/US, CIPM) where applicable Duties: - Monitor security alerts and events using SIEM tools (e.g., Microsoft Sentinel) - Perform initial triage and validation of alerts to determine legitimacy - Escalate confirmed or suspicious incidents to Tier II analysts per defined procedures - Document incidents, actions taken, and findings in ticketing systems - Follow established playbooks and standard operating procedure - Assist with log review across identity, endpoint, network, and cloud environments - Support reporting requirements by contributing to weekly and monthly SOC reports - Maintain situational awareness of emerging threats and indicators of compromise

United States