Job Closed
This listing is no longer active.
Cybersecurity Operations Analyst, Principal
Location
United States
Posted
38 days ago
Salary
$127.5K - $155.9K / year
Seniority
Lead
Job Description
Cybersecurity Operations Analyst, Principal
Cummins Inc.
• Responsible for ensuring information and data on computer systems is protected • Lead execution of complex response to computer security incidents according to the Information Security Policies and Industry Best Practices • Lead efforts of and provide timely updates and recommendations to multiple business units during response • Contribute to a team of cybersecurity professionals while working with threat data, writing reports, briefing event details to leadership, and coordinating remediation with personnel • Lead analysis of potential impact of new threats and exploits and communicate risks to Cyber Security Engineering • Monitor information security related web sites including SANS Internet Storm Center and mailing lists – BugTraq • Ensure technology employed by the Incident Response team compliments operational processes • Investigate and analyze relevant response activities using Cybersecurity Incident Response plans to end malicious activity and restore business operations • Understand and apply concepts of computer forensics • Provide guidance to tier one and other first responders for proper handling of Information Security Incidents • Perform operations according to Cybersecurity Defense Operations plan to detect and mitigate potential or real-time internal and external threats • Participate in industry task forces and working groups to understand current and future threats • Develop requirements for technical capabilities for cyber incident management • Recommend configuration changes to improve the performance, usability, and value of cyber analysis tools • Assess internal and external cybersecurity attacks using cybersecurity standards and tools including Security Orchestration Automation & Response (SOAR) to identify specific vulnerabilities • Manage the information security data sources to maintain organizational situational awareness • Trouble-shoot very complex, cross-business issues within existing security and privacy protections • Perform root cause analysis and make recommendations on changes • Coach and mentor less senior Cyber Security employees • Identify and manage risks, recommending improvements to Incidents Response Processes and Procedures • Develop strong relationships to deliver business value using Business Relationship Management practices
Job Requirements
- Master’s degree in Computer Science, Information Technology, Mathematics or Cybersecurity, or related field and 3 years of experience as a Cybersecurity Operations or Investigations Analyst or related position
- Alternatively, the employer will accept a Bachelor’s degree in Computer Science, Information Technology, Mathematics or Cybersecurity, or related field and 5 years of experience as a Cybersecurity Operations or Investigations Analyst or related position
- Experience to include: Investigate cybersecurity applying concepts of computer forensics; Cybersecurity Threat Analysis; Cybersecurity Incident Response; Cybersecurity Defense Operations plans; Security Orchestration Automation & Response (SOAR); Root cause analysis; Business Relationship Management practices; Risk Management.
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
- Kovimmat muutokset tehdään pehmein arvoin - Sofita - 100 % kotimainen, perheomisteinen yritys. Laadukasta soten korkeakoulutettujen rekrytointia jo vuodesta 2018. Sofita tarjoaa ainutlaatuisia työmahdollisuuksia sosiaali- ja terveydenhuollon korkeakoulutetuille, jotka haluavat vaikuttaa työhönsä, työskennellä moniammatillisessa porukassa ja katse tiiviisti kohti tulevaa! 🌱 Työnohjaaja! 📣 Tule osaksi parhaiden asiantuntijoiden kasvavaa yhteisöä! 📌Tehtävä: Etsimme työnohjaajia tilaajakumppaniemme tarpeisiin valtakunnallisesti. Työnohjaukset painottuvat sosiaali- ja terveysalan työntekijöiden, esihenkilöiden sekä johdon työnohjauksiin. Työnohjaukset voivat olla sekä yksilö- että ryhmätyönohjauksia. Työnohjausten sisältöä määrittää tilaajakumppanien asettamat toiveet/tavoitteet, työnohjattavan/-ryhmän kanssa rakentamasi tavoitteet työnohjaukselle sekä oma työnohjauksen viitekehyksesi. Toteutat työnohjauksia omiin aikatauluihisi sovittaen. Meillä sinä päätät! Tarjoamme: 🔺Valmiiksi neuvotellut työkokonaisuuden, jotta sinä saat keskittyä olennaiseen - kohtaamiseen ja työnohjaamiseen 🔺Tarpeitasi vastaavan ammatillisen tuen, joka voi olla joko työnohjaajamentorin tai moniammatillisen tiimin konsultointia 🔺Tiiviin yhteydenpidon yhteyshenkilösi kanssa varmistaaksemme, että et jää yksin 🔺Mahdollisuuden työskennellä itsenäisessä ja antoisassa asiantuntijatyössä, jossa voit hyödyntää ja kehittää vahvuuksiasi 🔺Yksilölliset, tarpeesi mukaiset käytännönjärjestelyt työn vastaanottamiseksi ja toteuttamiseksi, kuten työvälineiden tarjoaminen ja työmatkakulkemisen tuki 🔺Yhdessä neuvotellun palkkion, joka määräytyy aiemman työkokemuksesi, mahdollisten lisäkoulutusten, työpaikan toimipisteen etäisyyden ja työn vaativuustason mukaisesti Odotamme sinulta: 🔺Soveltuvaa korkeakoulututkintoa 🔺Työnohjaajakoulutusta. - Noudatamme Suomen työnohjaajat ry (Story):n suositusta työnohjaajakoulutuksesta. Sen mukaisesti työnohjaajakoulutus on laajuudeltaan vähintään 60 op (tai 40 ov) ja muodoltaan prosessimainen. 🔺Aktiivista työotetta, itseohjautuvuutta ja hyvää organisointikykyä 🔺Hyviä vuorovaikutustaitoja ja asiakaslähtöisyyttä 🔺Lisäksi eduksesi katsotaan: - vähintään kahden lukukauden johtamis- tai esihenkilökoulutus (muu kuin coach-koulutus) - sertifioitu coachin koulutus - vähintään kahden lukukauden koulutus työyhteisöjen kehittämiseen tai johtamis-/esihenkilötyöhön - kriisipsykoterapeutin koulutus tai kriisityönohjaajan / debriefing-ohjaajan pätevyys - vähintään kahden lukukauden lisä- tai jatkokoulutus työnohjaukseen - opintoja kasvatus- ja koulutusalalta - työkokemusta kasvatus- ja koulutusalalta - kokemusta johtamis- tai esihenkilötyöstä 🫱🏾🫲🏼Tule mukaan rakentamaan parempaa ammattilaisarkea yhdessä Sofitan kanssa! 🌿 💌Ota yhteyttä ja kysy lisää: Rebecca Svahn Palvelujohtaja, Sosiaalityöntekijä (VTM) 040 048 0899 rebecca.svahn@sofita.fi TAHTOA, ROHKEUTTA, LUOTTAMUSTA Sofita sovittaa yhteen organisaatioiden ja työntekijöiden työelämätarpeet joustavasti, tehokkaasti ja luotettavasti. Tuotamme asiakkaillemme psykologien, lääkärien, työnohjaajien ja sosiaalityöntekijöiden kattavat asiantuntijapalvelut muun muassa täydentävän työvoiman ja suorarekrytoinnin avulla, tarjoten samalla asiantuntijoillemme heidän erityisosaamisensa arvoiset uramahdollisuudet.
cFocus Software seeks a Security Operations Analyst 3 to join our program supporting the National Indian Gaming Commission (NIGC). This position is remote. This position requires a Public Trust clearance. Qualifications: - Active Public Trust clearance - B.S. Computer Science, Information Technology, or a related field - 4+ years of experience in cybersecurity operations or SOC analysis (senior-level) - Strong knowledge of security monitoring, incident response, and threat detection - Experience with SIEM, SOAR, EDR, and NDR tools - Familiarity with NIST frameworks, FISMA, and federal cybersecurity standards - Experience analyzing logs across network, endpoint, and cloud environments - Knowledge of Microsoft 365, Azure, and identity management (Entra ID) - Experience supporting federal agencies and compliance frameworks - Experience with VMware, Linux administration, and disaster recovery planning - Relevant certifications such as CISSP, CySA+, GCIH, or GCIA - Experience with PowerShell scripting and automation tools Duties: - Perform all security analysis activities according to established standards. - Maintain threat awareness and monitor NIGC information systems for exploits and any suspicious activities; analyze aggregated logs and reports from security tools. - Develop a daily security analysis and reporting checklist and execute activities identified in the checklist. - Evaluate effectiveness of security analysis activities compared to best practices and recommend improvements. - Adhere to Continuous Monitoring practices to evaluate the effectiveness of implemented security controls and execute proactive threat hunting activities to ensure confidentiality, integrity, and availability of NIGC information systems. - Develop detection and response configuration policies to increase automation and alerting. - Develop Incident handling procedures. - Execute Incident Response activities to include all associated actions according to the NIGC incident response plan. - Validate that sufficient and relevant information is captured and retained from security tools to support actionable security awareness and incident investigations. - Collect security operations performance and NIGC security posture management metrics and prepare NIGC threat reports to inform risk management decisions.
cFocus Software seeks a Cybersecurity Operations Engineer to join our program supporting the National Indian Gaming Commission (NIGC). This position is remote. This position requires a Public Trust clearance. Qualifications: - Active Public Trust clearance - B.S. Computer Science, Information Technology, or a related field - 4+ years of experience in cybersecurity operations or engineering - Strong knowledge of NIST frameworks, FISMA, and federal cybersecurity directives - Experience with Microsoft Azure, M365, and cloud security tools (Defender suite) - Experience with Cisco networking, firewalls, and hybrid infrastructure environments - Proficiency with SIEM (e.g., Microsoft Sentinel), SOAR, EDR, and NDR tools - Experience with PowerShell scripting and log management (Syslog) - Strong understanding of identity management (Entra ID, MFA) - Experience in incident response, threat hunting, and continuous monitoring - Industry certifications such as CISSP, GCIA, GCIH, CEH, or Microsoft Security certifications - Experience supporting federal agencies and compliance frameworks - Experience with VMware, Linux administration, and disaster recovery planning Duties: - Apply knowledge and skills of information systems security principles, NIST guidelines, FISMA, CISA, and federal directives, to conduct ongoing security assessments of installed systems and networks with a view to recommend corrective actions. - Perform systems engineering and maintenance activities according to established standards. - Apply knowledge of Networking Technologies including LAN, MS Azure, and Wireless management in security solutions implementation and troubleshooting. - Develop NIGC security operations capabilities by evaluating current strategies and pursuing alignment with best practices. - Ensure the effective configuration and daily operations of tools that support the NIGC cybersecurity strategy. Such tools include SEIM integration, Syslog, Network Detection and Response (NDR), Endpoint Detection and Response (EDR), Firewalls, M365 Cloud security, Defender for Cloud, and Continuous Diagnostics & Mitigation (CDM) capabilities. - In collaboration with CISO and Privacy Officer develop plans, techniques, and measurable objectives to improve the development of cybersecurity and privacy measures that meet NIGC goals for protecting sensitive information. - Collaborate with other teams on the integration of NIGC Applications and IT services to consider security implications and ensure that NIGC security requirements are met. - Maintain threat awareness and monitor NIGC information systems for exploits and any suspicious activities. Analyze aggregated logs from security tools and perform regular threat hunting activities. - Develop Security Orchestration and Automation capabilities. - Adhere to Continuous Monitoring practices to evaluate the effectiveness of implemented security controls and execute proactive threat hunting activities to ensure confidentiality, integrity, and availability of NIGC information systems. - Develop detection and response configuration policies to increase automation. - Execute Incident Response activities to include all associated actions according to the NIGC incident response plan. - Develop Incident handling procedures. - Validate that sufficient and relevant information is captured and retained from security tools to support actionable security awareness and incident investigations. - Collect security operations performance and NIGC security posture management metrics and prepare NIGC threat reports to inform risk management decisions. - Develop and maintain accurate security operations documentation including the preparation of standard operating procedures for recurring tasks
Security Operations Specialist
LoopioSupercharge responses to RFPs, RFIs, and Security Questionnaires.
• Monitor and investigate security events across networks and cloud environments • Support security incident response through investigation and escalation • Review authentication activity and access controls for gaps • Maintain effectiveness of security operational controls and practices • Support logging and monitoring controls across infrastructure • Participate in BCP/DR testing and documentation activities • Collaborate with Engineering and Product for secure software development practices • Work cross-functionally to support security operations and customer trust initiatives



