US Jobs US Jobs     UK Jobs UK Jobs     EU Jobs EU Jobs


Incident Response Analyst - Overnight Shift

Company

Federal Reserve Bank of Richmond

When you join the Federal Reserve—the nation's central bank—you’ll play a key role, collaborating with leading tech professionals to strengthen and protect our economic, financial and payments systems.

We invest in contemporary and emerging technology each year to support the Federal Reserve and our economy, and we’re building a dynamic team for our future.

The Federal Reserve System (FRS) National Incident Response Team (NIRT) is seeking an Incident Response Analyst.

The NIRT, a national service provider for the FRS, delivers effective intrusion detection, incident response, forensics, security intelligence, threat assessment, and penetration testing services.

The role is for an incident triage and response professional.

You will be expected to be able to investigate and respond to security events within the FRS with minimal oversight.

The ideal candidate will have some more specialized skills such as Security Operations Center (SOC) support, disk and/or memory forensics, phone forensics, malware analysis, and/or threat hunting skills.

Key Activities


* Perform security event triage and analysis with knowledge in current security threats and techniques.


* Analyze a large volume of security event data from multiple sources to identify suspicious and malicious activity.


* Perform postmortem analysis of traffic flows.


* Conduct network forensics.


* Conduct follow up analysis throughout the incident life cycle.


* Complete projects and tasks associated with security monitoring, detection, and incident response.


* Analyze all relevant data sources for attack indicators and potential network and host compromises.


* Respond to different attack vectors such as data exfiltration, DDoS, malware, insider risk, and phishing.


* Develop scripts and tools to improve the efficiency of incident detection and response processes.


* Interface with NIRT customers and stakeholders.

Qualifications


* Bachelor's Degree or equivalent experience with 3+ years of relevant work experience.


* In-depth understanding of a variety of information technologies and information security topics.


* Specifically, this should include the following:
+ SIEM/SOAR utilization skills to analyze security events from multiple monitoring and logging sources to identify, investigate and confirm suspicious activity.
+ Knowledge of incident response and handling methodologies.
+ Knowledge of common adversary tactics, techniques, and procedures (TTPs).
+ Knowledge of cyber threats and vulnerabilities.
+ Knowledge of cyber-attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks).
+ Knowledge of which system files (e.g., log files, registry files, configuration files) contain relevant information and where to find those...




Share Job