Cybersecurity Analyst III
The Cybersecurity Analyst III – role reports to the Sr. Director of Cybersecurity and is responsible for maintaining the daily security posture of the Collectibles business. They will aid in managing various aspects of the production, office, and network security environment, focusing on the company's SIEM and SOAR, as well as the vulnerability management platform. The Cybersecurity Analyst III will also work to ensure the Collectibles business' security posture aligns with the corporate minimum standards and actively assists in safeguarding corporate assets from unauthorized access.
Duties may include:
- Staying abreast of current security threats within the company region and vertical.
- Daily monitoring and protection of corporate assets.
- Assisting in the on boarding, management, and tuning of Sumo Logic for effective security information and event management.
- Helping with the configuration, management, and tuning of Qualys for effective vulnerability management.
- Analyzing and responding to security alerts from multiple security tools, operating systems, and cloud platforms.
- Supporting the business's vulnerability management program.
- Assisting in the production of meaningful KPI’s and executive level reporting.
Qualifications:
- Bachelor’s degree or equivalent experience required.
- 3 years' experience administering SIEM and SOAR tools, hands-on experience with Sumo Logic preferred.
- 3 years' experience working with vulnerability management tools, Qualys preferred.
- 3 years’ experience administering Endpoint Protection products, CrowdStrike preferred.
- Familiarity with cloud security alerts originating from AWS and Azure, leveraging the security tools and features available on these platforms to understand the scope and impact of the detected issues.
- A solid understanding of the MITRE ATT&CK framework, and utilizing it as a basis to identify, categorize, and respond to potential threats and security incidents.
- Understanding the key differences and applications of various threat indicators, including Indicators of Misconfiguration, Indicators of Attack, and Indicators of Compromise.
- A keen interest in cybersecurity investigations and familiarity with Incident Response procedures.
- Understanding of vulnerability management processes and tools.
- Basic scripting knowledge is a plus.
- General understanding of compliance regulations like SOX, GDPR, and CCPA.
- Excellent verbal and written communication skills.
- Security+ or CySA+ required, SSCP or CISSP a plus.
$95,000 - $120,000 a year
The salary range for this position is $95,000- $120,000 which represents base pay only and does not include short-term or long-term incentive compensation. When determining base pay, as part of a final compensation package, we consider several factors such as location, experience, qualifications, and training.