Lead Security Analyst
GLOBAL SEARCH PARTNERS PTE. LTD.
A lead technical role in the Security Operations Center (SOC) responsible for providing operation support on monitoring the MSS platform and incident response. Primary responsibility will be to follow procedures to triage and investigate security alerts, monitoring and responding to security threats, investigating cases, and taking immediate action or recommending a course of action to mitigate the threat. Facilitates the ingress, implementation and egress of complex client trouble / change requests for managed premise, cloud, NextGen UTM firewall, MDDoS, Threat Intelligence and Secure Log Management products. Provides mentoring, training and escalation support to Security Analysts and be involved with maturing incident response procedures and evaluating new security technologies. Represents security operations as technical lead and point of escalation with clients, vendors and internal corporate organizations. Takes ownership and leads on projects.
Responsibilities:
• Serve as a Team Lead / Tier 3 level for complex technical and procedural escalations
• Provide technical lead support to clients, vendors and coworkers as required;
• Responsible for development and execution of incident response plans for escalated response processes;
• Proactively identify indicators of compromise and generate and execute Incident Response Plan upon detection;
• Provide Incident remediation and prevention documentation;
• Handle User and Entity Behavior Analytics (UEBA) use cases of potential security incidents and security events in accordance with SOC processes and procedures;
• Identification and resolution of complex issues in customer environments. Develop resolution and implementation plans;
• Work in collaboration with other security and company departments (operations, legal, sales) to help identify / resolve chronic issues and assist with the creation and implementation of corrective / preventative action plans;
• Research, analyze and identify potential vulnerabilities and security deficiencies;
• Initiate escalation procedure to counteract potential threats/vulnerabilities;
• Research and implement customer generated change requests for MSS products;
• Responsible for operation, maintenance, and monitoring of network hardware and related control software providing a variety of customer services. Observe and control the status and performance of all security components of company products and services;
• Perform tasks associated with the installation, turn up and maintenance of security infrastructure and escalation of same;
• Conduct security training, new hire training and network impact reviews;
• Coordinate repair and maintenance of security system with security integrators. Liaise directly with third party vendors / suppliers;
• Participate in company sponsored job related activities plus training to further develop your management and technical skills.
Requirements:
• 5 - 10 years' of professional work experience in Information Security with at least a couple of years of SOC based experience;
• Experience using commercial and open source software and malware reverse engineering tools;
• Experience identifying vulnerabilities and modifications to hardware;
• Demonstrated proficiency exercising a detailed depth and breadth of technical subject knowledge to SME levels;
• Possible security technology certifications (e.g. CISSP, SANS (GCIA, GCIH, GSEC));
• BS/BA degree in Computer Science, Information Technology, or related discipline or equivalent experience;
• Strong analytical skills to define risk, identify potential threats, document and develop action/mitigation plan;
• A passion for information security and data security;
• Knowledge/experience with Operating Systems (e.g. Windows Server, CentOS Linux);
• Knowledge/experience of networking and firewalls (e.g. Cisco ASA, Palo Alto, Checkpoint, Juniper, Fortinet, Arbor, Radware);
• Working knowledge of Elastic Stack (Elasticsearch, Kibana) and Log Management/SIEM (e.g. Splunk, QRadar, ArcSight);
• Good to have programming and scripting skills (e.g. C++, Bash, Python, Perl, Powershell);
• Foundational Knowledge of Enterprise Anti-Virus, IDS, Full Packet Capture and Host/Network Threat Analysis;
• Knowledge of Threat Monitoring Procedures;
• Experience with securing various environments preferred;
• Experience working a SOC and doing incident response is preferred.
(EA Licence No. 14C7000)
(EA Personnel Registration No : R1110355)
Responsibilities:
• Serve as a Team Lead / Tier 3 level for complex technical and procedural escalations
• Provide technical lead support to clients, vendors and coworkers as required;
• Responsible for development and execution of incident response plans for escalated response processes;
• Proactively identify indicators of compromise and generate and execute Incident Response Plan upon detection;
• Provide Incident remediation and prevention documentation;
• Handle User and Entity Behavior Analytics (UEBA) use cases of potential security incidents and security events in accordance with SOC processes and procedures;
• Identification and resolution of complex issues in customer environments. Develop resolution and implementation plans;
• Work in collaboration with other security and company departments (operations, legal, sales) to help identify / resolve chronic issues and assist with the creation and implementation of corrective / preventative action plans;
• Research, analyze and identify potential vulnerabilities and security deficiencies;
• Initiate escalation procedure to counteract potential threats/vulnerabilities;
• Research and implement customer generated change requests for MSS products;
• Responsible for operation, maintenance, and monitoring of network hardware and related control software providing a variety of customer services. Observe and control the status and performance of all security components of company products and services;
• Perform tasks associated with the installation, turn up and maintenance of security infrastructure and escalation of same;
• Conduct security training, new hire training and network impact reviews;
• Coordinate repair and maintenance of security system with security integrators. Liaise directly with third party vendors / suppliers;
• Participate in company sponsored job related activities plus training to further develop your management and technical skills.
Requirements:
• 5 - 10 years' of professional work experience in Information Security with at least a couple of years of SOC based experience;
• Experience using commercial and open source software and malware reverse engineering tools;
• Experience identifying vulnerabilities and modifications to hardware;
• Demonstrated proficiency exercising a detailed depth and breadth of technical subject knowledge to SME levels;
• Possible security technology certifications (e.g. CISSP, SANS (GCIA, GCIH, GSEC));
• BS/BA degree in Computer Science, Information Technology, or related discipline or equivalent experience;
• Strong analytical skills to define risk, identify potential threats, document and develop action/mitigation plan;
• A passion for information security and data security;
• Knowledge/experience with Operating Systems (e.g. Windows Server, CentOS Linux);
• Knowledge/experience of networking and firewalls (e.g. Cisco ASA, Palo Alto, Checkpoint, Juniper, Fortinet, Arbor, Radware);
• Working knowledge of Elastic Stack (Elasticsearch, Kibana) and Log Management/SIEM (e.g. Splunk, QRadar, ArcSight);
• Good to have programming and scripting skills (e.g. C++, Bash, Python, Perl, Powershell);
• Foundational Knowledge of Enterprise Anti-Virus, IDS, Full Packet Capture and Host/Network Threat Analysis;
• Knowledge of Threat Monitoring Procedures;
• Experience with securing various environments preferred;
• Experience working a SOC and doing incident response is preferred.
(EA Licence No. 14C7000)
(EA Personnel Registration No : R1110355)
JOB SUMMARY
Lead Security Analyst
GLOBAL SEARCH PARTNERS PTE. LTD.
Singapore
6 days ago
N/A
Full-time
Lead Security Analyst