You are viewing a preview of this job. Log in or register to view more details about this job.

Threat Intel Analyst


Job Description

Title:    Threat Intel & Cyber Defense Analyst

Location:  Atlanta, GA

 

 Threat Intel & Cyber Defense Analyst

This role is part of NCR’s Global Information Security team. This team is responsible for developing and implementing NCR’s corporate information security program. The primary goal of the program is to protect the confidentiality, integrity, and availability of information resources. Key information security functions and activities include architecture and design for NCR information security controls, developing and enforcing policies and standards, security awareness training, risk management, assessment, and testing, monitoring and metrics, incident management, and threat and vulnerability management.

 

The Cyber Defense Analyst shall be responsible for actively hunting for Cyber threats and building automation to improve our capabilities to detect such threats at scale. Working in a collaborative team environment, the Cyber Defense Analyst will investigate information security incidents and escalate when required. The Cyber Defense Analyst shall work in a collaborative manner with other incident responders, key incident management team members, management, and other stakeholders to ensure security incidents are contained, eradicated, remediated and after-action review is held according to corporate policy.  The Cyber Defense Analyst is expected to contribute to weekly status calls, work on the on-call rotation which includes working off hours/weekends and respond to ad-hoc requests as part of this position. The Cyber Defense Analyst will work with stakeholders and team members to assist with improving incident response processes that are aligned with the mission of the office of the CISO.  The Threat Intel analyst shall work in a collaborative manner with the incident response team, key incident management team members, management, and other stakeholders to ensure security incidents have pertinent information to drive investigations. The Threat Intel analyst will also be responsible for building detections based on industry and technology related threats. This position reports to the Incident Response Manager, Cyber Defense Center and is based in the Global Headquarters of NCR in Midtown Atlanta.

 

Key Responsibilities

Effectively apply corporate incident handling procedures by leading information security incident meetings and documenting related activities

Triage, respond to and escalate security incidents

Provide or facilitate the forensics analysis of security events

Coordinate incident response activities across multiple independently managed environments and security teams

Utilize multiple security/threat intelligence tools and resources to understand threats

Analyze and respond to minor and major incidents, reported SPAM and Phishing e-mails

Provide leadership in process improvement and automation of incident response activities

Support 24/7 operations

Finding new threats

Provide comprehensive threat intelligence

Patch and triage vulnerabilities

 

Skills and Qualifications

Strong knowledge of network, backend systems, operating systems, applications and web services in a manner that allows for the interaction of all as it relates to security and services. 

2+ Years as a cybersecurity incident responder

Ability to apply analytical expertise and critical thinking to security incidents

Ability to assimilate, understand and utilize various security technologies

Ability to collaborate within a geographically distributed team of Incident Response Analysts

Demonstrated team or functional leadership experience

Experience processing and analyzing intelligence in support of management decision making

Knowledge of relevant information security and incident response frameworks such as ISO 27001, NIST SP 800-61, NIST Cyber Security Framework, MITRE ATT&CK Framework.

Strong communication skills and ability to work in a collaborative atmosphere

Strong attention to detail

Ability to deal with ambiguity and translate high level objectives into detailed tasks

Proven decision-making and influencing skills

Ability to prioritize work with multiple, simultaneous work assignments

Ability and willingness to learn new tools and processes.

Bachelor's degree preferred

Experience documenting business processes or technical procedures preferred.

3+ years working in Information Security preferred

Experience with event escalation, reporting and investigation preferred

Industry certifications related to security and incident handling (ServiceNow Admin, Certified Incident Responder, Recorded Future certified analyst, Insight VM certified administrator Rapid7) preferred