Peckham, Inc.

Peckham, Inc. is a nonprofit organization dedicated to empowering individuals with disabilities and other barriers to employment through inclusive job training,

Information Security Operations Analyst

Location

Michigan

Posted

3 days ago

Salary

0

Seniority

Entry Level

Professional Certificate

Job Description

Information Security Operations Analyst

Peckham, Inc.

Title: Information Security Operations Analyst Location: Lansing, MI Job Description: SUMMARY The Information Security Operations Analyst supports the mission of the Information Security Team to protect the confidentiality of Peckham’s proprietary, customer, and employee information while defending technology systems against cyber threats to ensure the continuity of Peckham’s business operations. The Security Operations Analyst plays an important role in monitoring for and responding to cyber threats by reviewing security information and event monitoring tools during their daily shift and after-hours in responding to high-priority threats escalated to the Information Security Team by Peckham’s managed threat detection and response partners. The Security Operations Analyst role is a hybrid of work-from-home (about 75%) and work from the Peckham Headquarters in Lansing Michigan (about 25%). MAIN DUTIES AND RESPONSIBILITIES - On a constant, daily basis throughout their scheduled shift, review Microsoft Defender and Microsoft Sentinel tools for potential cyber threats like malware infections, phishing attempts, and unauthorized access. - Document suspected threats within incident handling logs, triage the threat, report the threat to the Senior Security Operations Analyst or the Director of Information Security, and investigate the threat as directed. - On nights and weekends, respond to high priority threats escalated to the Information Security Team by Peckham’s managed threat detection and response partner, Critical Start. These incidents average 1-2 per week. - As guided by the Director of Information Security, assist the Senior Security Operations Analyst with using Tenable and other tools to identify new software and hardware vulnerabilities affecting Peckham’s information systems, prioritize the vulnerabilities, and report them to the appropriate remediation team(s). - Track remediation progress and report status to the Director of Information Security. - As needed, assist the Senior Security Operations Analyst with open incident investigations and response actions. - In the absence of the Senior Security Operations Analyst, assume primary responsibility for cyber threat detection and response activities. - As requested by and under the guidance of the Director of Information Security, the Security Operations Analyst will perform various tasks associated with the implementation of information security-related projects. - Continuously gather threat intelligence via multiple sources like email lists and social media to stay aware of threats and risks to Peckham. - Utilizing training opportunities provided by Peckham, commit to continuous improvement of cybersecurity skills through training and certification. OTHER DUTIES AND RESPONSIBILITIES - Maintain a safe and clean work environment. - Promote Peckham’s vision values and services to all customers and stakeholders. - Assist in maintaining organizational wide quality standards. - Other duties as assigned. SUPERVISORY RESPONSIBILITIES - This position does not have direct supervisory responsibility. MINIMUM QUALIFICATIONS - 1-2 years of experience working in a security operations center or similar environment triaging cybersecurity incidents. - Microsoft Certified: Security Operations Analyst Associate certification, the CompTIA CySA+, the GIAC SOC, or an equivalent certification or experience. - Ability to understand and practice the CIA Triad of Confidentiality, Integrity, and Availability in all aspects of their job duties. - Ability to install software and maintain and secure their own computing devices and tools. - familiar with the Microsoft Windows family of operating systems and at least one Linux or Unix distribution (Ubuntu, Kali, macOS, etc.). - Experience with capturing and analyzing network packets. - Strong understanding of modern networking and the Open Systems Interconnect model and 5-tuple. - Must possess strong documentation skills for the purposes of forensic analysis. - Ability to work under pressure and quickly handle multiple security incidents simultaneously. - Must be detail oriented and thorough. - Ability to compartmentalize sensitive information and employ the philosophy of need-to-know in all communications and disclosures. - Ability to work independently and with minimal supervision within their assigned job duties without affecting quality, thoroughness, or timeliness. - Must be flexible and adapt to changing conditions and multiple priorities on a regular basis. PREFERRED QUALIFICATIONS - Experience with Microsoft security solutions like Defender XDR, Sentinel, and Intune are preferred. - Experience with Tenable One Exposure Management Platform or Nessus Vulnerability Scanner is a plus. - Experience with securing cloud environments like Microsoft 365, Microsoft Azure, and Amazon Web Services is a plus. PHYSICAL DEMANDS The physical demands of this position may be reasonably accommodated for individuals with disabilities on a case-by-case basis. PECKHAM IS AN EQUAL OPPORTUNITY EMPLOYER EEO/AA Employer/Vet/Disabled. Peckham provides equal opportunities and does not unlawfully discriminate on the basis of race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, age, disability, genetic information, height, weight, marital status, veteran status, or any other protected characteristic protected by applicable federal, state, or local law.

Related Categories

Related Job Pages

More Security Operations Jobs

Full TimeRemoteTeam 1,001-5,000Since 2012H1B Sponsor

• Drive the generation services and technologies business to meet or exceed quarterly and annual quota objectives in partnership with the account and domain teams. • Follows the Optiv Standardize Sales Operating Processes (SOPs) to achieve consistent success. • Maintain advanced knowledge of the client’s security environment, business operations, security needs, and risk appetite. • Identify their security concerns and how they correlate to Optiv’s strategic solutions across the assigned domain and holistic cyber security programs. • Identify cross-sell and upsell opportunities across clients and Optiv's partner relationships. • Qualify lead and partner with internal colleagues to determine scope, proposal management, and follow through to closure. • Participate in sales opportunities across Optiv's entire portfolio. • Clearly articulate how the necessary elements of the Optiv technology and services portfolio meet the specific needs of the client stakeholders at a senior leadership level. • Stay abreast of industry trends, news, and maintain a broad understanding of the security landscape to facilitate thought leadership, support, analysis, and guidance to clients and internal Optiv groups. • Collaborate with service delivery to ensure the team has necessary supporting domain specialty materials that presents a consistent and comprehensive approach. • Effectively work with multiple client personas across the security leadership team, as well as other relevant personas to develop security strategy and define roadmaps to execute on security strategy aligned business goals, budgetary spend, and metrics based on return of investment. • Maintain advisory relationships with key stakeholders at clients by facilitating thought leadership, support, information, and guidance in conjunction with sales partners. • Maintain strong working relationships with relevant Optiv technology partners, based on client spend, and Optiv focus. • Identify and drive complete security programs to meet client objectives across technology and services including: driving new discussions by leveraging peer and industry network contacts performing requirements gathering analysis, and technology selection criteria coordinating demonstrations and security technology evaluations drive cross organizational solutions leveraging Optiv's portfolio. • Interface and partner with the internal Optiv teams, particularly service delivery liaisons, to align client expectations with the entire Optiv solution portfolio to ensure service delivery excellence and client satisfaction. • Identify new and emerging technologies for internal enablement and exposure to clients. • Promotes Optiv’s portfolio and security awareness at speaking events, partner events, and leveraging social media. • Builds a reputation as trusted advisor with clients, partners, peers and cyber community resulting in an influential network of contacts. • Listen for client feedback and continually share with internal teams to evaluate and cultivate continuous improvement. • Participate in account planning, forecasting, and pipeline management activities. • Participate in managing and prioritizing the proposal process to create business proposals, contracts, and respond to RFI/RFP’s. • Actively pursue personal development by maintaining and obtaining technical capabilities, soft skills, and security specific knowledge through formal education, certification, and other avenues. Advanced sales techniques: makes connections, facilitates meetings, reads the room, asks probing questions, overcomes objections, gains trust, maintains composure under pressure, positions solutions, and assist in finalization of sale.

New Jersey + 2 moreAll locations: New Jersey | Michigan | Pennsylvania
$200K - $250K / year
Apollo Information Systems logo

SOC Analyst I

Apollo Information Systems

Intelligence-led, precision-fit cybersecurity.

Full TimeRemoteTeam 51-200Since 2002H1B No Sponsor

• Monitor security events and alerts using SIEM tools and other security technologies. • Analyze and triage security alerts to determine severity and potential impact. • Perform initial incident response activities and escalate issues when necessary. • Document and track security incidents and their resolutions. • Assist in creating and maintaining security documentation and procedures. • Contribute to the development and improvement of security metrics and reporting. • Collaborate with other team members and departments to address security concerns. • Partner with SOC Analyst II to develop and refine SIEM correlation rules. • Stay informed about emerging threats and security trends.

United States
$50K - $80K / year
Job Closed
Cribl logo

Staff Security Operations Engineer

Cribl

Cribl, the Data Engine for IT and Security, empowers organizations to transform their data strategy.

Full TimeRemoteTeam 501-1,000Since 2017H1B Sponsor

• strengthen security posture through robust security operations and advanced threat detection • lead security incident management, triage, and investigations • develop innovative solutions to remediate current threats and proactively prevent future attacks • design, implement, and optimize detection logic to identify sophisticated threats • partner closely with Product Security, IT, and Legal teams • report to the Sr. Director, Security Engineering and Operations under the CISO

California
$128K - $200K / year
Conduent logo

Cyber Operations Engineer, Senior

Conduent

At Conduent, we want you to be yourself. We recognize that everyone is different and that how people want to work and deliver at their best is different for everyone too. When you join Conduent, you are engaged in creating the future - both our company’s and your own. With more than 60,000 associates across 24 countries, we will provide you the opportunity to grow with a team of people who will challenge and inspire you to be the best!

Full TimeRemoteTeam 10,001+Since 2017H1B Sponsor

• Manage multi-step breach and investigative analysis of advanced threats • Serve as an escalation resource and mentor for other analysts • Work directly with cyber threat intelligence to convert intelligence into useful detection • Work with security partners developing and refining monitoring use cases • Work on complex tasks assigned by leadership, which may involve coordination of effort among Level 1/2/3 analysts • Coordinate evidence/data gathering and documentation and review Security Incident reports • Identify root cause incident and take proactive mitigation • Define required security controls and processes and enforces through the execution of policy documentation, standards, education and awareness, and conducting risk assessments. • Monitor external regulatory requirements and supports compliance and certification activities. • Enforce a defense-in-depth methodology in support of the overall enterprise cyber security risk posture. • Create and develop CSIRT processes and procedures working with Level 2 and Level 1 Analysts

Utah
$91.4K - $118.8K / year