In this role, you’ll work in our IBM Client Innovation Center (CIC), where we deliver deep technical and industry expertise to a wide range of public and private sector clients around the world. These centers offer our clients locally-based skills and technical expertise to drive innovation and adoption of new technology.
- Monitoring systems and processes security events and incidents using established processes
- Performing deep analysis of events and incidents escalated by Tier-1 security analysts.
- Delegating the investigation of detected events to Tier-1 Security analysts
- Determining whether critical systems and data are affected and initiates or recommends corrective actions.
- Maintaining and updates detection rulesets following established processes.
- Maintaining and updates an incident log and a lessons learned
- Categorizing and reports incidents following established procedures.
- Supporting the 24x7x365 SOC by providing a view of security events and network activity
- Mentoring and supporting Tier-1 security analysts
- Quality experience in working as a network security analyst in a security operations center
- Extensive experience with all phases of incident response
- Extensive experience in the inner-workings of Operating systems (Windows and Linux-based)
- Extensive knowledge of network communications and routing protocols
- Experience in programming and/or scripting languages
- Extensive experience using SIEM applications
- Experience managing and prioritizing large volume of alerts
- Experience managing , analyzing, editing and crafting Intrusion Detection rules
- Practical experience in Information Security concepts and technology
- English - excellent verbal and written communications skills
- GIAC GCIH Certification
- GIAC GCIA Certification
- Microsoft Certified Windows Server Administrator (or equivalent Windows Certification)
- Redhat Certified Systems Administrator (or equivalent Linux certification)
- CISSP / CISM or equivalent certification