Jobs and Careers
EX

CFC (Cyber Fusion Centre) Sr. Threat Detection Analyst I - US REMOTE ONLY

Experian
United StatesRemotefull_timeVerifiedPosted 28 Nov 2023

About the role

Company Description

About us, but we’ll be brief

We are very proud that FORTUNE named us one of The 100 Best Companies to Work For. In addition, for the last five years we’ve been named in the 100 “World’s Most Innovative Companies” by Forbes Magazine.

Job Description

Central Time Zone working shift hours range between 7:30am-8:30pm, 4 of 7 days a week. 

What you’ll be doing:

The Senior Threat Detection Analyst I is responsible for monitoring the alert stream, conducting the initial assessment and information gathering on security incidents, leveraging various analytical tools, and triage and escalation of security incidents to senior analysts if applicable. These individuals also work closely with a number of cybersecurity teams, technical SMEs, and business unit contacts. 

Below is the list of CFC (Cyber Fusion Centre) Senior Threat Detection Analyst I (L1) main tasks: 

  • Monitor alerts and investigate incidents using SIEM and UEBA technologies, packet captures, reports, data visualization, and pattern analysis. 
  • Analyze, escalate, and assist in remediation of critical information security incidents. 
  • Improve and challenge existing processes and procedures in a very agile and fast-moving information security environment. 
  • Security analysts should have expert knowledge of: 
  • Information security policies and goals 
  • Log analysis and event traffic patterns 
  • The current IT threat landscape and upcoming trends in security 

Responsibilities 

  • Able to work on a 10x7 shift rotating schedule. 
  • Be eye-on-the-screen to fulfill operational necessity. 
  • Monitor the alert stream, assess each alert for severity based on the defined criteria in playbooks, and respond within SLO requirements. Escalate potential incidents to the next level for further investigation and remediation. 
  • Identify and analyze anomalies in network traffic using metadata. 
  • Perform follow up monitoring from prior shift based on severity.
  • Update playbooks and brief teammates on updates, under the supervision of the lead analyst. 
  • Complete training requirements 
  • Ensure SLO standards are met for 90% of incidents worked. 
  • One presentation per quarter on security topic or contribution to the information security threat blog. 
  • Follow investigative process for incident escalation and shift turnover with cross team US/KL 
  • Develop specialization in one tool 
  • Attend and participate, unless there is a plausible justification, in the CFC Weekly Meetings. 
  • Contribute at least two (2) items to the CFC Weekly Meeting Lessons Learned per Month. 
  • Minimize (less than 5%) CIRT callbacks for cases not including all information and improve case quality 
  • Minimize (less than 5%) negative management feedback for internal analyzed cases 
  • Maximize effort and eliminate wasteful or duplicate efforts with CFC activities. 
  • Provide daily shift briefing and maintain activity shift log of interesting events. 
  • Perform analysis on Experian Systems assets, document results noting attacker profiles. 
  • Produce daily, weekly, and monthly reports on security activity and CFC workload metrics to include tickets opened, events per analyst hour, and open or pending items. Additionally, reporting will be conducted to demonstrate top firing IDS/IPS signatures, top talking sources and destination and various other pre-determined CFC metrics. 
  • Identify impact of incidents on systems, and using available tools determine if data was infiltrated. 
  • Document and maintain a knowledge base of alarms (false positives and false negatives, blacklists, whitelists) that IDS and IPS encounter. 
  • Serve as work area experts for security/information assurance policy recommendations. 

Qualifications

  • 2+ years’ experience in the following areas: 
  • Demonstrates practical understanding and hands-on knowledge at:  
    • TCP/UDP/IP networking, familiarity with packet analysis tools such as WireShark, and a general understanding of networking and security protocols 
    • Network operations or engineering components while assessing and troubleshooting issues 
    • System administration on Unix, Linux, or Windows 
    • Willingness to acquire in-depth knowledge of network- and host security technologies and products (such as firewalls, network IDS, scanners) and continuously improve these skills 
    • Security monitoring technologies, such as SIEM, IPS/IDS, UEBA, DLP, among others. 

Demonstrates behavioral skills, such as: 

  • Demonstrated ability to work in a te

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Experian

View company profile →