Security Operations Centre Analyst
il y a 7 jours
**Location**:
Brussels, Belgium
**Security Clearance**:
EU Secret
**Introduction**:
One of our clients is currently looking for a Splunk Expert to provide professional service acting as the 1st line of response regarding the potential occurrence of a cyber-attack or security incident.
**Skills, knowledge, experience required**:
- Minimum 3 years’ experience with Splunk;
- At least 1 certification among the following:
- GPEN (GIAC Certified Penetration Tester);
- GCED (GIAC Certified Enterprise Defender);
- GPPA (GIAC Certified Perimeter Protection Analyst);
- GCFE (GIAC Certified Forensic Examiner);
- GCFA (GIAC Certified Forensic Analyst);
- GNFA (GIAC Certified Network Forensic Analyst);
- CFCE (IACIS Certified Forensic Computer Examiner);
- CCFP (Certified Cyber Forensics Professional);
- SCMO (SABSA Certified Security Operations and Service Management Specialist);
- Minimum 3 years’ experience in networking (TCP/IP, SNMP, DNS, Syslog-ng, etc.);
- Minimum 2 years’ experience in using, configuring and tuning a security information and event management (SIEM) tool;
- Knowledge on and minimum 2 years’ experience with the following network security solutions and technologies:
- Firewalls;
- Network intrusion detection systems (IDS) and intrusion prevention systems (IPS);
- Switches and routers;
- Advanced persistent threat (APT) detection solutions such as FireEye;
- DNS, DHCP, VPN;
- Network forensics (full packet capture);
- Traffic baselining analysis;
- Knowledge on and minimum 2 years’ experience with the following host-based security solutions:
- Host-based intrusion prevention systems (HIPS);
- Malware end-point protection;
- Operating system logs;
- Strong knowledge on and minimum 3 years’ experience in:
- MS Windows security events analysis;
- Security analysis of firewall, proxy, and IDS logs;
- Security analysis of applicable or middleware logs (Oracle HTTP Server, Apache HTTP Server, Oracle WebLogic Server);
- Minimum 1 year of experience in writing and optimizing:
- IDS signatures (preferably Snort and/or Suricata);
- YARA rules;
- Minimum 3 years’ experience with SIEM tools such as:
- HP ArcSight Enterprise Security Manager (ESM) 6.x;
- IBM QRadar SIEM;
- Minimum 2 years’ experience with:
- Snort or Cisco Sourcefire Next-Generation IPS (NGIPS);
- Cisco FireSIGHT;
- Check Point and Juniper firewalls;
- Blue Coat proxies.
**Desirable**:
- Minimum 2 years’ experience with STIX (Structured Threat Information Expression) with a particular focus on the following related standards:
- CybOX (cyber observables);
- CAPEC (attack patterns);
- MAEC (malware);
- TAXII (threat information exchange);
- Minimum 1 year of experience with:
- Suricata or Stamus Networks;
- ELK stack (Elasticsearch, Logstash and Kibana);
- FireEye (EX, NX, AX, FX, HX, IX).
**Duties/role**:
- Supervising and reporting on the SOC implementation based on configuration of Splunk as a SIEM;
- Providing real-time monitoring of cyber defence and intrusion detection systems;
- Performing automatic-based processing (centralisation, filtering, and correlation) of security events;
- Conducting human-based analysis of automatically correlated events;
- Processing incoming warnings, alerts, and reports;
- Performing triage based on verification, level of exposure and impact assessment;
- Categorizing events, incidents, and vulnerabilities based on relevance, exposure, and impact;
- Opening tickets and ensuring case management;
- Activating initial response plan based on standard playbook entries;
- Maintaining incident response address book;
- Advising affected users on appropriate course of action;
- Monitoring open tickets for incidents and vulnerabilities from start to resolution;
- Escalating unresolved problems to higher levels of support, including the Incident Response and Vulnerability Mitigation teams;
- Configuring the SIEM components for an optimal performance;
- Improving correlation rules to ensure that the monitoring policy allows an efficient detection of potential incidents;
- Analysing risks and security policy requirements, and translating them into technical events targeting the system components;
- Identifying the required logs, files or artefacts to collect from the monitored system and, if necessary, possible complementary devices to deploy;
- Elaborating the relevant detection and correlation rules, and implementing them in the SIEM infrastructure;
- Configuring and tuning cyber-defense solutions;
- Reviewing and improving the monitoring policy on a regular basis;
- Integrating cyber-defence solutions for efficient detection;
- Defining dashboards and reports for reporting on KPIs;
- Producing qualified reports (including recommendations) or alerts to SOC customers and following up on actions;
- Contributing to the design of the overall monitoring architecture, in close relationship with the customers and system owners on one hand, and the Security Operations Engineering team on the other hand, by performin
-
Security Operations Analyst
il y a 1 semaine
Brussels, Belgique Luminus Temps pleinPublicatiedatum: 22 augustus 2024 - Brussels - Contract open-end In today's landscape of escalating digital complexity and cybersecurity threats, a Security Operations Analyst plays a crucial role in safeguarding Luminus assets. The Security Operations Analyst is responsible for cyber incident response and the operations, monitoring and administration of a...
-
Security Operations Center Analyst
il y a 4 semaines
Brussels, Belgique Enzo Tech Group Temps pleinJob Opportunity: SOC Tier 2 Analyst (Temporary – Night Shift)Schedule: Night shifts, 12 hours (19:00–07:00)Location: 2 days a week on siteWe are urgently looking for an entry-level SOC Tier 2 Analyst to join our Cyber Defense team on a temporary basis. This role is critical to supporting our 24/7 security operations and ensuring continuous monitoring...
-
Security Operations Center Analyst
il y a 6 jours
Brussels, Belgique Enzo Tech Group Temps pleinJob Opportunity: SOC Tier 2 Analyst (Temporary – Night Shift)Schedule: Night shifts, 12 hours (19:00–07:00)Location: 2 days a week on siteWe are urgently looking for an entry-level SOC Tier 2 Analyst to join our Cyber Defense team on a temporary basis. This role is critical to supporting our 24/7 security operations and ensuring continuous monitoring...
-
Security Analyst
il y a 1 semaine
Brussels, Belgique Vector Synergy Temps plein**Location**: Brussels, Belgium **Introduction**: One of our clients is currently looking for a Security Analyst in information system security. The client’s infrastructure is supported by Corporate ITIC services. However, some local specific needs requires to design, setup, and administer an ad-hoc solution at client level. The main focus of the...
-
Process Analyst – Contact Centre
il y a 4 semaines
Brussels, Belgique Innova Solutions Temps pleinProcess Analyst – Servicing Transformation ProjectA major Servicing Transformation Program is underway to enhance efficiency for employees and customers, increase customer self-service, and build future-proof operations. The program impacts Operations and Contact Centres and spans multiple Business and IT initiatives.We are looking for an experienced...
-
Application Security Analyst
il y a 2 semaines
Brussels, Belgique InterEx Group Temps pleinUnique Security Analyst/ Belgium / CybersecurityWe are working exclusively with a top partner in cyber security who is currently expanding their security presence in Belgium, due to their rapid growth. They are looking to build a strong team of security application analysts to revolutionize their security team.Unique Security Analyst/ Belgium /...
-
IT Security and Resilience Officer
il y a 7 jours
Brussels, Belgique Ageas Temps pleinOur organisation **Ageas** is a listed international insurance Group with a heritage spanning of 200 years, offering Retail and Business customers Life and Non-Life insurance, and is also engaged in reinsurance activities. - As an international insurance company, Ageas concentrates its activities in Europe and Asia through a combination of wholly owned...
-
IT Security Analyst
il y a 4 jours
Brussels, Belgique Bandwidth Temps plein**Who We Are**: At Bandwidth, your music matters when you are part of the BAND. We celebrate differences and encourage BANDmates to be their authentic selves. #jointheband **What We Are Looking For**: The Information Security Engineer will provide daily support for the information security systems, tools and services for the local security operations of the...
-
Security Analyst
il y a 7 jours
Brussels, Belgique Proximus Group Temps pleinA job at Proximus? You’ll find that everything revolves around the idea ‘Think Possible’. This means: we always assume that something is possible, even if it seems impossible. Well, especially so, actually. Call it a way of thinking that involves being open to a world of digital solutions that make our lives easier. And our way of working...
-
Transformation Office Analyst
il y a 4 semaines
Brussels, Belgique Innova Temps pleinProcess Analyst - Servicing Transformation ProjectA major Servicing Transformation Program is underway to enhance efficiency for employees and customers, increase customer self-service, and build future-proof operations. The program impacts Operations and Contact Centres and spans multiple Business and IT initiatives.We are looking for an experienced Process...