Responsible for investigating computer related incidents and events using incident and forensic tools. Responsible for protecting the organization's most sensitive information including information requiring regulatory protection.
Experience with security monitoring and reporting tools and conducting security investigations of incidents and events.
Certifications: EC-Council Certified Incident Handler, Certified Incident Handler (GCIH), CERT-Certified Computer Security Incident Handler (CSIH), or compatible.
Experience managing/using IDS/IPS
Bachelor’s Degree plus 2 years of experience managing and implementing SIEM, A/V, Internet content filtering/reporting, malware prevention, Firewalls, IDS & IPS, Web security, anti-spam technologies required OR 12 total years of experience managing and implementing SIEM, A/V, Internet content filtering/reporting, malware prevention, Firewalls, IDS & IPS, Web security, anti-spam technologies required
High degree of skill and knowledge in managing incident response, Intrusion Prevention Systems, Intrusion Detection Systems, SEIM, A/V, Firewalls, web security, anti-spam technologies, and network security
Strong knowledge of advanced attack capabilities, characteristics and defining signatures for detecting malicious code.
Strong knowledge of national security standards, business continuity, disaster recovery, auditing, risk management, vulnerability assessments, and regulatory compliance.
Extensive technical knowledge of security industry practices and procedures.