Jobs and Careers
WY

Sr. Cyber Analyst - Security Intelligence

Wynn Resorts
Las Vegas, United Statesfull_timeVerifiedPosted 14 Aug 2023

About the role

Job Description

The Senior Cyber Security Intelligence Analyst will support the Information Security Department with the identification and investigation of network computer intrusions and other assignments relating to advancing the cyber investigation and response practice. Responsible for supporting the development of Incident Response (IR) tools, development of IR and cyber security protocols, development of advanced network intrusion detection protocols, information and intelligence sharing with the Wynn business teams.

Key Responsibilities:

  • Investigate network intrusions and other cyber security breaches to determine the cause and extent of the breach.
  • Research, develop, and recommend hardware and software needed for Incident Response and develop policies and procedures to analyze malware.
  • Participate in technical meetings and working groups to address issues related to malware security, vulnerabilities, and issues of cyber security and preparedness.
  • Collaborate with the Director of Cyber Security and INFOSEC to facilitate an effective IR program.
  • Prepare, write, and present reports and briefings.
  • Thoroughly investigate instances of malicious code to determine attack vector and payload.
  • Develop high performance, false positive free, signature-based network level, and malware detection schemes.
  • Participate in special forensic investigations as required, including collection, preservation of electronic evidence.
  • Preserve and analyze data from electronic data sources, including laptop and desktop computers, servers, and mobile devices.
  • Preserve, harvest, and process electronic data according to the department’s policies and practices on an as necessary basis.
  • Triage and track potential threats and alerts from multiple sources, and spot trends
  • Create filters, reports, dashboards, and alerts to surface potentially unwanted activity
  • Create and update existing playbooks and runbooks, working with multi-functional team members to maintain high-quality work products
  • Conduct and document the incident life cycle, managing and coordinating security incidents, escalating, and providing other support
  • Create or propose automated tooling or streamlined processes to quickly tackle incidents and issues as they arise
  • Participate in enterprise-wide operations to hunt for adaptable and previously unknown threats
  • Develop creative new approaches to accelerate threat detection, responses, and remediation of security incidents in a global organization
  • Participate in each pillar of security through mentorship, training, and project opportunities
  • Detect, respond to, investigate and remediate security events in an enterprise environment
  • Develop, implement and automate strategies, applying best practices and threat intelligence to tune tools and rules for detecting and remediating malicious activity
  • Participate in enterprise-wide operations to hunt for adaptable and previously unknown threats
  • Strategically define and implement additional detective capabilities or data sources to improve telemetry
  • Create and investigate alerts from detective telemetry and tune rules to increase fidelity, leveraging frameworks such as the ATT&CK matrix
  • Perform retrospective analysis using network, host, memory, and other artifacts from multiple operating systems and applications
  • Analyst SME for security tools deployed across the organization.
  • Provide in-depth analysis of security alerts and make recommendations to improve security posture.
  • Monitor external data sources (e.g. cyber defense vendor sites, CERT) to remain current with threat conditions and determine which security issues may have an impact on the enterprise.
  • Provide cybersecurity recommendations to leadership based on significant threats and vulnerabilities.
  • Support the construction of signatures which can be implemented on cyber defense tools in response to new or observed threats
  • Partner with security teams to provide guidance and support in implementing new projects.
  • Participate in global security or IT projects ensuring security operations goals are met.
  • Periodically review the incident response process and propose improvements.
  • Identify and monitor relevant operational metrics.

Qualifications

  • A minimum of five (5) years in an enterprise security or threat analyst role
  • Experience tuning, improving and devising new ways to collect signal, reduce noise, and identify suspicious events in corporate and SAAS environments; experience using Splunk a plus
  • Experience with log or data analysis, extracting salient data points to determine an event’s impact and root cause
  • Experience applying threat intelligence to operational capabilities for impr

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Wynn Resorts

View company profile →