We are seeking a skilled and vigilant L1 qualified for handling EDR operations. The ideal candidate will play a key role in monitoring, analyzing, and responding to security incidents using Carbon Black EDR while ensuring SLAs are met.
Responsibility:
- Monitor Carbon Black EDR alerts and maintain SLAs.
- Research and analyze Carbon Black EDR for potential threats.
- Troubleshoot EDR agent-related issues and analyze endpoint data for Indicators of Compromise (IOCs).
- Conduct triage and assessment of security incidents, including determining scope and impact.
- Escalate confirmed security incidents to Level 2 analysts or the Incident Response team.
- Ensure EDR operations and tickets are handled and resolved within defined SLAs.
- Perform detailed threat analysis and log review using analytical skills and experience.
- Stay updated on the latest cybersecurity threats, vulnerabilities, and trends relevant to endpoints.
- Follow Runbooks, Playbooks,
and Standard Operating Procedures for security incident handling.
Requirements:
- 5-7 years of work experience as a security analyst with hands-on experience in EDRs.
- Good knowledge of Carbon Black EDR, alert detection, and response.
- Understanding of threats like lateral movement, phishing, ransomware, spyware, and emerging threats.
- Experience with TCP/IP network traffic, Internet protocols, and event log analysis.
- Knowledge of threat intelligence tools for detailed alert analysis.
- Ability to decode encrypted scripts and understand alert execution.
- Familiarity with Runbooks, Playbooks, and SOPs for EDR operations.
- Good understanding of banking business and IT practices in the banking sector.
- Cybersecurity certifications such as CEH or CompTIA+ are preferred.
- Must be comfortable working 24/7 shifts.