06 Aug
|
HCA Healthcare - India
|
Hyderabad
06 Aug
HCA Healthcare - India
Hyderabad
**CDC GCN I
** Position Title
GCN 1
Department Name
Information Security
Department No.
853
Direct Reports
Reports directly to
Manager, Cyber Defense Center
Matrix report to
Job location
Corporate - SkyPark
Job Code/Grade/Level
JOB SUMMARY (Primary Purpose Of The Position.) The GCN 1 – serving as direct support to the HCA CDC corporate team – is a critical member of the 24/7 CDC team. They will use state of the art technologies to detect threats on our network and eradicate them as a member of our Cyber Defense Center (CDC). As a member of the CDC, they will operate along with a small team of like-minded individuals with a passion for cyber security.
This role will provide Tier 1 and Tier 2 analysis and response to cyber security threats.
Threat Response
Engineers will be expected to detect malicious activity and support the business through the Incident Response process for both routine and major events. Successful candidates will have a passion for cybersecurity and be naturally curious and self-motivated to investigate and discover root causes of events while working in a fast-paced and sometimes stressful environment. Good teamwork and communication skills are also vital. Our team operates as a close-knit group serving a noble purpose – to win the fight against evil every day.
GENERAL RESPONSIBILITIES ( The essential responsibilities and accountabilities of this position including interactions with other departments and outside vendors, if applicable, in PRIORITY order.)
Major Responsibilities:
- Monitor security alert queue – investigate and triage events based on criticality. Provide recommendations on how to mitigate the threats. Use analytic techniques and critical thinking to determine if and when to escalate threats to larger Cyber Security team.
- Provide guidance to field resources on how to properly remediate a threat.
- Work closely with other CDC team members to improve tools, techniques, and procedures for CDC operation.
- Continuously improve documentation of work products and processes.
- Participate in red/blue team exercises.
- Execute HCA’s Incident Response plan as part of an incident response team. Serve as Incident Commander, Task Lead, or Scribe during incidents.
- Routinely collaborate with individuals and teams from across the enterprise.
Desired Experience:
- Experience as a member of a Cyber Incident Response Team (CIRT) or comparable team.
- Experience executing an Incident Response plan, preferably based on recognized industry standards (e.g. – NIST, SANS, etc).
- Experience in Windows Artifact Analysis and Initial Forensic Analysis (e.g. – Program Execution, File/Folder opening, Account Usage, pulling memory, following proper evidence handling procedures, etc) using industry standard tools and available logs (e.g. – Endpoint Detection and Response (EDR) tools).
- Experience in Memory Analysis using tools such as Volatility
- Experience in network forensic analysis to determine validity of detected events using available network logs collected via SEIM.
- Experience in DFIR (Digital Forensics Incident Response).
- Experience with an event/information analysis framework such as Analysis of Competing Hypotheses (ACH).
- Experience in performing security analysis or reporting utilizing Security Incident and Event Management (SIEM) Technologies. Preferably Splunk and SPL experience.
- Experience with document management and sustaining Security Operations Center (SOC) policies and run book procedures for incident response.
- Experience with documenting root cause analysis and lessons learned.
- Experience consuming and generating cybersecurity threat intelligence.
- Experience across the technology stack. Familiarity with all OSI layers and expertise in some.
- Experiencing using the following types of security tools:
- SIEM
- Firewalls
- Web Proxy
- Anti-Virus (AV)
- Next Gen Anti-Virus (NGAV)
- Endpoint Detection and Response (EDR)
- Sandboxing
- Virtual Machines
- Netflow analysis
- Malware Repositories
- Threat Intelligence
- Deception Stack
- Intrusion Detection/Prevention System (IDS/IPS)
- Security Orchestration Automation Response (SOAR)
- Phishing Triage
- User Behavior Analytics (UBA)
- Email Hygiene and Filtering
- Experience interfacing with peer support teams (Security Engineering, Vulnerability and Patching Teams, Networking, Access Management, Legal, Risk/Governance, etc.)
- Experience working in a high-tempo, dynamic environment with a high-performance team.
- Experience with work ticketing systems (e.g. – ServiceNow, JIRA).
- Experience with Threat Modeling and Kill Chain analysis.
RELEVANT WORK (Minimum amount of specifically related experience which is required to perform the role at this level. Experience Note In Other Additional Specific Exp.)
Less than 1 year
1+ years
3+ years
5+ years
7+ years
10+ years
15+ years
Other Preferred/required Experience : MANAGEMENT ( Minimum amount of specifically related experience which is required to perform the role at this level.
Experience Note In Other Additional Specific Exp.)
Less than 1 year
1+ years
3+ years
5+ years
7+ years
10+ years
15+ years
Other Preferred/required Experience : EDUCATION (Minimum formal academic training which typically provides the knowledge and skills necessary for successful job performance.
Note In Other If Experience May Be Substituted.) High School Graduate/Equivalent
Associate’s Degree Required
Bachelor’s Degree Preferred Bachelor’s Degree Required
Master’s Degree Required
Doctorate Degree Required in _______________
Medical Doctorate (MD) Required
Doctor of Pharmacy (PharmD) Required
Technical Training
Other As Noted: OTHER/SPECIAL QUALIFICATIONS (Required licenses, certificates, specific skills, personal traits, e.g., RN, CPA, able to type 90 wpm, detail orientation.)
- The successful candidate will possess the following aptitudes and skillsets:
- Able to maintain a superior knowledge of the cyber security capabilities of operating systems, networking devices, control systems, and vendor offerings via self-directed learning and formal training.
- Excellent critical thinking skills to understand available data and use it to support or refute potential hypothesis that explain the data. Use available data to develop and communicate conclusions and recommendations.
- An ability to work and thrive in stressful situations. A demeanor that conveys calm professionalism in stressful situations.
- An ability to maintain confidentiality of sensitive data and to follow proper ethical practices for using tools and accessing data.
- A solid desire to determine root cause of events. A willingness to fully investigate all alternatives exhaustively until a conclusion can be supported.
- Ability to self-prioritize tasks based on criticality and threat level.
- Advanced written and oral communication skills.
- The following certifications and courses are helpful, but, not required:
- Certified Ethical Hacker (CEH)
- GIAC: GSEC, GCIH, GCIA, GCED, GMON, GCDA, GDAT, GCFE or comparable
- CompTIA Security+
PHYSICAL DEMANDS/WORKING CONDITIONS (Specific statements of physical effort required and description of work environment; e.g., prolonged sitting at CRT., required travel %)
- Extensive periods of sitting or standing at work station to include use of mouse, keyboard, and monitor(s).
📌 Deputy Manager - Business Information Security (Hyderabad)
🏢 HCA Healthcare - India
📍 Hyderabad