Jobs and Careers
WE

Cybersecurity Incident Response Analyst I

Western & Southern Financial Group
Cincinnati, United Statesfull_timeVerifiedPosted 14 Feb 2025

About the role

Overview

Responsible for handling escalated incidents using proper investigation techniques, processes and procedures. Work in an agile manner to quickly respond to active threats. Works with managed security service provider (MSSP) to tune rules for detection of threats while minimizing false positives/false negatives. Maintains the central knowledge base for all processes, procedures and case documentation for accuracy and completeness. Assists in the mentoring of junior cyber associates to facilitate their development as incident analysts.

Responsibilities

What you will do:
  • Under broad supervision, investigates incidents that are escalated per procedure. Communicates with customers as appropriate, keeping Cybersecurity Operations Center (CSOC) management informed per incident severity requirements. Follows applicable processes and procedures while maintaining flexibility to “think outside the box” during the investigation in order to find all affected systems, including “patient zero”; performs root-cause analysis; determines attribution if appropriate; completes documentation; and participates in lessons learned post mortem. For high-severity level incidents, functions as a team member on the incident team, interfacing with outside incident response personnel as well as both senior and junior cyber associates. Serves as the SME for the incident response team for one area of incident response, including, but not limited to, endpoint detection and response, application security or network forensics.
  • Provides supervision and backup for monitoring capabilities. Works with Cybersecurity Threat Analysts on automation recommendations. Evaluates and makes recommendations to Senior Cybersecurity Analysts. Leads project team to implement improvements.
  • Ensures process, procedure and system documentation are complete and followed consistently. Assists senior cyber associates in creating, revising, and maintaining processes and procedures related to continuous monitoring, triage, incident analysis and incident response activities. Consults with other cyber associates to continuously improve those processes and procedures, and works with other associates to ensure that when new tools or external inputs change that the documentation is adjusted accordingly.
  • Assists in the mentoring and training of junior cyber associates to learn proper investigation techniques, documentation requirements and evidence handling. Serves as a technical consultant to those associates. Functions as a technical contact for managed security service provider (MSSP) analysts when technical questions arise, consulting with senior analysts and management for guidance as appropriate.
  • Assists more senior analysts and managed security service providers in documenting and implementing use case detections. Participates in periodic use case reviews and works with other analysts to adjust existing use cases under broad supervision.
  • Communicates with CSOC management, cyber and information security staff members, and customers in written and verbal communication regarding investigations and status updates. Maintains need-to-know discretion for all investigations.
  • Interfaces regularly with the Cybersecurity Engineer to test and improve custom tools, suggesting features and improvements in order to improve efficiency and productivity. During investigations, communicates with the engineer in order to quickly gather the information needed in the most efficient manner possible, giving constructive feedback on custom tools provided in that process.
  • Performs knowledge sharing with team members through meetings, presentations and written communications. Creates, revises and maintains documentation of incident response processes and procedures in the central knowledge base.
  • Participates in after incident lessons learned meetings to give input on recommendations for process or procedure improvements, and to provide mitigation recommendations to reduce future incidents or minimize their impact.
  • Tracks performance metrics and provides timely updates to CSOC management.
  • Performs other duties as assigned.
  • Complies with all policies and standards.

Qualifications

  • Bachelor's Degree In information assurance, information systems, computer science, IT, or commensurate selection criteria experience. (Required)
  • Proven experience in threat detection technologies, including intrusion detection and prevention systems (IDS/IPS), security incident and event management (SIEM) technology, and network packet analyzers. Experience with security data analytics, endpoint protection, malware analysis and forensics tools are highly desired. (Required) and
  • Demonstrated experience in incident analysis and response activities, including execution of response and analysis plans, processes and procedures, and perf

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Western & Southern Financial Group

View company profile →