First Line Security Event Analyst (FLSEA) 6

First Line Security Event Analyst (FLSEA) voor NATO Cyber Security Centre in Mons, Belgium – eerste lijn analyse van logs en netwerkverkeer.

Bekijk en reageer bij jobs.ncim.nl (externe link)

Eisen

  • SIEM-producten (ArcSight, Splunk)
  • Goede schriftelijke en mondelinge communicatievaardigheden
  • Breed begrip van netwerkbeveiligingsdreigingen en mitigatietechnieken
  • Uitgebreide kennis van computer- en communicatiebeveiliging, TCP/IP, Windows en Linux
  • Analyse van NIDS events (SourceFire, Palo Alto)
  • Zelfstandig en in teamverband kunnen werken
  • Netwerkverkeeranalyse met Wireshark
  • Lack of degree gecompenseerd door minimaal 3 jaar relevante ervaring in cyber security analyse
  • Gebrek aan ervaring gecompenseerd door hoge kennis van cybersecurity
  • Logische benadering van analyse en gestructureerde security-onderzoeken met grote datasets
  • University degree in IT plus minimum 1 jaar ervaring in cyber security analyse
  • Loganalyse van diverse bronnen (firewalls, proxies, routers, DNS, security appliances)

Wensen

  • Militaire communicatiesystemen en netwerken
  • Vaardigheid in Intrusion/Incident Detection and Handling
  • Computer forensische tools (stand alone, online, netwerk)
  • Industrieel toonaangevende certificering (GCIA, GNFA, GCIH)
  • Ervaring met CIRT/CERT
  • Host Based Intrusion Detection Systems (HIDS)
  • Full Packet Capture systemen (Niksun, RSA/NetWitness)
  • Computer security tools (VA, anti-virus, protocolanalyse, anti-spyware)
Volledige omschrijving

NCIM is looking for a First Line Security Event Analyst (FLSEA) to work within the NATO Cyber Security Centre (NCSC) team in Mons, Belgium. The analyst will perform initial analysis of logs and network traffic, determine alert severity and escalate when required. They will collate information and present findings in a clear, structured format, providing remediation recommendations and first line response where applicable. Duties include conducting research and assessments of security events, providing analysis of firewall, IDS, anti-virus and other network sensor produced events, leveraging the comprehensive extended toolset (e.g.

Log Collection, Intrusion Detection, Packet Capture, VA, Network Devices) for enhancing investigations, supporting the end-to-end Incident Handling process, and proposing optimisations and enhancements to maintain and improve NATO's Cyber Security posture.

Requirements: a university degree in a technical subject with a focus on Information Technology (IT) plus a minimum of 1 year experience in cyber security analysis; lack of degree may be compensated by at least 3 years relevant experience, or by demonstrating a high level of knowledge in cybersecurity.

Also required: comprehensive knowledge of computer and communications security including TCP/IP networking, Windows and Linux; broad understanding of common network security threats and mitigation techniques; experience with SIEM products (e.g. ArcSight, Splunk); analysis of NIDS events (e.g. SourceFire, Palo Alto); log analysis from various sources (Firewalls, Proxies, Routers, DNS, security appliances); network traffic capture analysis using Wireshark; logical approach to analysis and ability to perform structured security investigations using large, complex data sets; good written and spoken communication skills; ability to work independently and as part of a team.

Preferences include industry leading certifications (GCIA, GNFA, GCIH), CIRT/CERT experience, proficiency in Intrusion/Incident Detection and Handling, Full Packet Capture systems (Niksun, RSA/NetWitness), Host Based Intrusion Detection Systems, computer security tools (Vulnerability Assessment, Anti-virus, Protocol Analysis, Anti-Spyware), computer forensics tools, and military communication systems and networks.

Je CV en reacties

Gegevens automatisch overgenomen uit de oorspronkelijke publicatie; controleer de details bij de bron. Wij zijn geen partij bij de aanvraag. Hoe wij werken.