Security Operation Analyst - 100% Remote - 12+Yrs only Job at KTek Resourcing, Fort Worth, TX

RW5RVmsxMk15Vm9lMFZTcG9VMDBNbzVIVUE9PQ==
  • KTek Resourcing
  • Fort Worth, TX

Job Description

Hello ,

My name is Rajat , and I am a Technical Recruiter at K-Tek Resourcing . We are searching for professionals for the below business requirements for one of our clients.

Please send me your updated resume at - rajat.rathore@ktekresourcing.com

Role- Security Operations Analyst -L3

Work Location- Remote is fine but Work / Shift timing will be California time

Technical Requirements / JD:

Query & Investigations:

Extensive experience in SIEM query building, complex query writing (such as subqueries, conditions, etc.), data pivoting (via queries, excel, notepad++, etc.), data parsing and manipulation.

Cyber Investigation and Threat Hunting Skills:

understanding how to investigate different types of attack/compromise scenarios, isolate associated risks (and enumerate potential CoA’s & responses actions: such as network contain hosts, reimage assets, rotate accounts, revoke tokens, reset sessions, etc.). The response actions should be tailored to risk, dictated by indications of compromise identified, dictated by the specific attack scenario identified (e.g. advanced malware, info-stealers, phishing, malicious links in email, ransomware, hacking software such as mimikatz, cobalt, meterpreter, impacket, PS empire, AD enum tools etc.), which is alluded to by the monitoring content triggered (i.e. security event).

Threat Intelligence :

general understanding about threat actors (criminal orgs, advanced persistent actors (APT – other national sovereign states), ransomware groups, targets/victims, verticals, TLP ratings, intelligence integration into cyber operations and how to use that, etc.

CyberOps Toolset :

Should have advanced understanding of the following toolsets by category (not brand) and express that experience/depth of understanding, in the interview:

  • EDR – process trees, disk operations, network connections, commandlines run, load & run state of binaries and DLL’s, duration, actions applied, process IDs, etc. Also advanced experience running queries in EDR
  • SIEM – as stated above regarding advanced query building/writing and pivoting skills. In addition, should have advanced experience building content rules in SIEM (per patterns identified).
  • Sandbox – how to submit various artifacts/links etc. and how to interpret the reports which require understanding of WinAPI’s
  • Cloud – both AWS and Google GCP, general knowledge regarding compute (EC2, Compute Engine), storage (S3, Cloud Storage), and databases (RDS, Cloud SQL) as well as serverless computing (AWS Lambda, Cloud Functions) – should be familiar with CloudTrail and GuardDuty datasets and how to investigate and pivot those.
  • Email Proxy – experience regarding email based research and investigation – phishing, malicious emails, content, artifacts, downloads, campaigns

Special Knowledge Sets of Interest to Customer/Industry:

  • General understanding regarding AD – Domain Controllers, their role, their function, what they store, how authentication is achieved, how service requests are processed, etc.
  • AD Attacks – ntds.dit, golden ticket, pass the hash, pass the ticket, krbtgt account compromise, how to perform privilege escalation attacks (various techniques) etc.
  • Associated AD attack tools – bloodhound, sharphound, mimikatz, ntdsutile.exe, impacket suite, etc.

Job Tags

Shift work,

Similar Jobs

Covington & Burling LLP

Part-Time Security Officer Job at Covington & Burling LLP

 ...which this position will have access Qualifications Must be computer literate: MS Office. Must be dependable and flexible to work this schedule. Strong written and verbal communication skills. Must maintain qualifications as a Special Police Officer.... 

Jazz Forum

Front-of-House Manager Job at Jazz Forum

 ...staff. Close register and manage nightly cash tips distribution. Coordinate...  ...a 20-25 hour per week position with shifts on Fri, Sat and Sun. In the future, weekday...  ...before or at end of shift. Vacation time is pro-rated as a part-time position. WHO WE ARE The... 

Confidential Jobs

E-Commerce Customer Success Manager Job at Confidential Jobs

 ...The E-Commerce Customer Success Manager manages merchant service coordinators who are responsible for interaction with merchants on a day-to-day basis regarding...  ...role is traditionally based on-site, we are open to remote candidates who live within a reasonable commuting... 

The Medical Transcription Service

Work From Home as a Medical Transcriptionist Job at The Medical Transcription Service

We are looking for good pathology MTs who can work evenings. Must reside in the U.S. or Canada. Our MTs are independent contractors working from home. For more information regarding earning potential, equipment needed, and the reports we transcribe. Please email us for ...

WELDALL AND COMPANIES

Fitter-Welder Job at WELDALL AND COMPANIES

 ...Description: Founded in 1973, Weldall Manufacturing, Inc., began with one welder and a vision; to provide the best in class service and quality products. Today, Weldall has grown into the preferred manufacturer of choice for clients around the world. Still family owned...