Jobs and Careers
FR

Information Security Analyst (Remote)

Freenome
South San Francisco, United StatesRemotefull_timeVerifiedPosted 6 Jan 2023
💰 $150,000/yr($110,500/yr$150,000/yr)

About the role

Why join Freenome?

Freenome is a high-growth biotech company on a mission since 2014 to create tools that empower everyone to prevent, detect, and treat their disease. 

To achieve this mission, Freenome is developing next-generation blood tests to detect cancer in its earliest, most treatable stages using our multiomics platform and machine learning techniques. Our first blood test will detect early-stage colorectal cancer and advanced adenomas.

To fight the war on cancer, Freenome has raised more than $1.1B from leading investors including a16z, GV (formerly Google Ventures), T. Rowe Price, BainCapital, Perceptive Advisors, RA Capital Management, Roche, Kaiser Permanente Ventures, and the American Cancer Society’s BrightEdge Ventures. 

Are you ready for the fight? A ‘Freenomer’ is a mission-driven employee who is fueled by the opportunity to make a positive impact on patients' lives, who thrive in a culture of respect and cross collaboration, and whose work makes a significant impact on the company and their career. Freenomers are determined, patient-centric, and outcomes-driven. We build teams around divergent expertise, allowing us to solve problems and ascertain opportunities in unique ways. We are dedicated to advancing healthcare, one breakthrough at a time.

About this opportunity:

As an Information Security Analyst, you will help identify and reduce security risks in our office network and GCP cloud environment by implementing, maintaining and monitoring security related events and incidents. You will provide your expertise regarding collecting evidence and do forensic analysis. You will act as an Information Security representative with your peers across all lines of business and central teams.

What you’ll do:

  • Engineer, implement, and administer the SIEM platform, open-source or commercial.
  • Analyze, design, build, tune, and support SIEM use cases across various business functions and security operational needs.
  • Create, modify, and tune the SIEM rules to adjust the specifications of alerts and incidents.
  • Develop log ingestion, aggregation, and retention strategies to meet policy, related standards, and operational requirements.
  • Assist with onboarding new data sources into our SIEM, analyze the data for anomalies and trends, and build dashboards highlighting the key trends of the data.
  • Analyze and investigate security events from various sources.
  • Triage and validate security alerts and escalate incidents, as required. Ensure that incidents are correctly reported and documented in accordance with operational policies and procedures.
  • Manage security events as part of security operations, responding to urgent alerts, which may include off-hours investigation activities.
  • Troubleshoot system misconfigurations and recommend best practices for remediation.
  • Provide high quality written and verbal status reports, briefings, recommendations, and findings as required.
  • Maintain and support the operational integrity of SIEM/SOC toolsets.
  • Helping to develop the SOC (Security Operation Center) roadmap by delivering SOC capabilities to the business and championing new ideas and initiatives to help improve new and existing capabilities.
  • Ensure all relevant technical standards and policy documentation is reviewed and maintained throughout SOC technical capabilities.
  • Maintain situational awareness of emerging cyber trends by reviewing open-source reports for recent vulnerabilities and other threats that have the potential to impact the services and incorporate this understanding into day-to-day security monitoring.
  • Excellent knowledge of Endpoint protection.
  • Good understanding of vulnerability assessment and management.
  • Update SIEM/SOC documentation, processes and procedures and ensure currency, as required.
  • Provide ideas and feedback to improve the overall SOC capabilities and maturity.
  • Perform all other Information Security related duties as assigned and contribute to the success of the Information Security Team.

Must haves: 

  • Bachelor's degree in Information Security, computer science, business, or a related field, or equivalent in experience and expertise.
  • Excellent Google Cloud Platform knowledge.
  • At least 3 years' hands-on experience in SIEM tools implementing, operating and incident management in mission critical environments. 
  • Industry Certifications such as CISSP, CCSP, CCAK, CCSK, CISM, GCIH, GCIA, GSEC (Cloud security certification preferred).

Nice to haves: 

  • Proven experience with CASB and Cloud based logging and SIEM solutions.
  • Understand threat analysis models like MITRE ATT&CK Framework.
  • Knowle

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Freenome

View company profile →