Cyber Defense Analyst - Real Time

Perform the security monitoring process and escalate relevant issues to the Cyber Defense Team Lead – Real Time.   Identify potential security incidents and forward to the appropriate  team for further analysis. Uses data collected from a variety of cyber defense tools (e. g. , IDS alerts, firewalls, network traffic logs. ) to analyze events that occur within their environments for the purposes of mitigating threats. 

 

Perform cyber security monitoring of Industrial Control/SCADA systems with established monitoring tools including Industrial Defender and Splunk

Perform tracking of cyber events as required for NERC CIP Compliance. 
Interface with various business entities to determine nature of detected cyber events, perform detailed analysis on cyber events and advise entities on methods to improve security posture

Create detailed documentation on use of monitoring systems, topology and details of business entity ICS/SCADA systems, and performance of NERC CIP logging monitoring and alerting processes

Provide daily summary reports of network events and activity relevant to cyber defense practices. Use cyber defense tools for continual monitoring and analysis of system activity to identify malicious activity. 

Remain up-to-date on the latest security information in order to validate the security analysis & identification capabilities of the security operations technologies

Participate in efforts to analyze & define security filters & rules for a variety of security parameters