The purpose of this plan is to evidence the professional development of a new cyber security Incident Response Analyst from the SkillBridge program. Our program will include milestone objectives, immediate training plans, the timeline of those training blocks, the training objectives, model provided, and the instructor’s qualification.
Job description:
IT Incident Response AnalystStarr’s Information Security Team is seeking a candidate to join our Incident Response Team. Qualified candidates will possess a general understanding of the current cyber security threat types, attack methodologies, and the common controls and counter measures deployed to detect and defend against them. Candidates should be familiar with IR processes including documenting incident details, performing root cause, and lesson learned analysis.Specific Skills & Responsibilities:Responsible carrying out daily monitoring and response security proceduresMonitor IT Systems, Security alerting queues, and review daily reportsPerform initial incident assessment, evidence gathering, and triageEscalate incidents, and participate in remediation effortsProvide feedback and recommendations for improvement of security controls and response proceduresCommunicates with peer Security/Operations teams and management with expected interactions with business users and vendorsAssists with day to day security functions, respond to help tickets, requests for assistance with accessing Starr systems and softwareSplunk Log & Event Platform (basic query and report building)Related and Desired Skills and Work experience:Bachelors Degree in Information Technology, Engineering, or a related field preferred but not required.2 years working in the Information Technology or Computing Field preferred but years in other career paths considered. Basic understanding of security defenses (anti-virus, firewalls, access controls)Basic understanding of types of attacks, exploits and methods used to compromise or damage computing systems and networks.Basic understanding of networking and internet communicationsSecurity+ or similar security certification a plusExperience with any of the following technologies greatly preferred:Splunk Log & Event Platform (basic query and report building)Network Access ControlVulnerability ScanningAdvanced Detection and Response Endpoint AgentsNetwork Packet Capture and Event AnalysisThreat Intelligence PlatformsMicrosoft Patching and Device Management PlatformsExperience with Splunk SOAR a plusExperience with scripting, (batch, PowerShell, python, etc..) a plus