Analyst, SOC (Endpoint Protection Experience Required) Job at RKON, Chicago, IL

cEZiQUw1eWdDTUlzUVFPcmZDRXpQQ0JmSGc9PQ==
  • RKON
  • Chicago, IL

Job Description

About us: RKON is an ISO27001 and AICPA SOC 2 Type II certified company that specializes in providing IT migration and transformation services for the Mergers and Acquisitions market.  RKON was recently recognized as one of the 100 best places to work in IT, highlighting our competitive advantage of empowering thought leaders and providing cutting-edge solutions for the fast-paced industry of Private RKON is looking for ambitious professionals to join our award-winning team. We have a proven track record for finding and developing top talent with people that believe they can achieve something greater. We also pride ourselves on fostering an environment where initiative, creative thinking, and collaboration are encouraged and rewarded—a key reason for the extraordinary level of service we deliver to our customers.

RKON does not accept unsolicited resumes from staffing agencies, search firms or any third parties.

About the position: RKON is seeking a Cyber Security Analyst to work on the client-facing Security Operations Center (SOC) – Assurance and Response Team. This position requires a motivated fast learner, who is able to work within key vulnerability and security information event management functions to identify, analyze, and remediate potential threats to the environment. The candidate will require security industry knowledge that evolves with current and emerging vulnerabilities and threats, as well as an ongoing understanding of key business and technological processes. This position will report to the SOC Lead Security Analyst.

In this role you will perform key client-facing managed security services activities including identification of assets, scanning for infrastructure and application vulnerabilities, and security monitoring.  In addition, you will perform investigations and conduct analyses of events in order to thwart internal and external threats to the environment.  You will collaborate on an ongoing basis with clients’ key contacts and stakeholders to support detection, triage, incident analysis, containment, remediation, and reporting of vulnerabilities, events, and escalated incidents while coordinating business priorities, emerging and actual threats, and best practices to ensure confidentiality, integrity, and availability of the client’s information assets.

Responsibilities Include:
  • Assist in establishing a mature and optimized Security Operations Center discipline to support managed security services focused on client-facing vulnerability and security information event management engagements.
  • Identify and remediate infrastructure and application vulnerabilities identified in continuous scanning exercises and assist with risk prioritization.
  • Analyze and respond to security threats from Firewall (FW), Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS), Antivirus (AV), Endpoint Detection and Response (EDR), Network Detection and Response (NDR), Email Security, Cloud Security, and other security threat data sources.
  • Respond to clients in a timely manner (within documented SLA) with thorough and concise analysis and recommended actions.
  • Document actions in cases to effectively communicate information to internal and external stakeholders as well as for historical retrieval.
  • Adhere to RKON company and client policies, procedures, and security practices.
  • Resolve problems independently and understand escalation procedures.
  • Conduct scanning and monitoring activities to provide in depth visibility into potential known and unknown vulnerabilities and threats that may pose risk to the RKON and client environments.
  • Participate in security incidents and act as the technical Subject Matter Expert during significant security incidents.
  • Utilize analytics to identify potential vulnerabilities and threats to the environment.
  • Detect, respond, mitigate, and report on cyber threats/incidents that may impact the environment.
  • Collaborate with RKON and client technical leads and Subject Matter Experts including Engineering, Operations, Service Desk, Applications, and client key stakeholders on matters related to security scanning and monitoring across a global footprint.
  • Collaborate and serve as liaison to key security vendor solution partners.
  • Conduct operations surrounding cyber security incident response technologies including network logging and forensics, security information and event management tools, security analytics platforms, log search technologies, and host-based forensics as applicable.
  • Act as an internal information security consultant to the business and technology units, advising on risks, threats, and control practices related to SOC - Assurance and Response.
  • Assist in development and knowledge sharing within the team.
  • Assist in security console tuning.
  • Perform threat hunts that target known vulnerabilities, threats, and other attack vectors.
Required Technical and Professional Expertise
  • Desire to work in SOC, Vulnerability Management, Security Information Event Management, Threat Hunt, or Threat Intel team on a long-term basis
  • 1+ years’ experience in IT Operations (e.g. Service Desk, System Administration, Security, etc.)
  • Critical thinking and problem-solving skills
  • Passion for information security
  • Strong business acumen including written and verbal communication skills
  • Strong interpersonal and organizational skills
Preferred Technical and Professional Expertise
  • Experience with Vulnerability Management technologies
  • Experience with Security Information Event Management technologies
  • Practical experience with TCP/IP networking
  • Working knowledge of Routing and Access Control Devices
  • Experience with Linux, Windows, iOS, and Network Operating Systems
  • Experience with Endpoint and Network Detection Response technologies
  • Experience with Cloud Security configuration best practices
  • Experience with Windows Defender for Endpoint and other Defender Suites, CrowdStrike, SentinelOne, or other industry-leading Endpoint Protection Platforms
  • Industry related certifications: Security+, C|EH, GSEC, etc.

Job Tags

Full time,

Similar Jobs

Maryland Rural Development Corporation

Teacher Assistant - Head Start - Aberdeen Job at Maryland Rural Development Corporation

 ...MRDC Teacher Assistants assist Lead Teachers in providing developmentally appropriate classroom activities and instruction to Head Start students and supporting Head Start families in compliance with the Head Start Performance Standards and MRDC policies and procedures... 

Bricktown Brewery Restaurants

Host/Hostess Job at Bricktown Brewery Restaurants

 ...At Bricktown Brewery, we take pride in creating safe and respectful workplaces where our team members thrive. Were all about local beer, great food, and truly friendly serviceif that sounds like your vibe, wed love to hear from you! Position: Host/Hostess As a... 

All Care Therapies

Speech Language Pathologist (SLP) Job at All Care Therapies

 ...Therapies is a leading provider of Physical, Occupational, and Speech therapy services. We place an emphasis on attracting...  ...All Care Therapies is currently seeking a Speech Language Pathologist (SLP) to join our dynamic Outpatient clinics! This is an exciting... 

super-color

Part-time / Full-time - Data Entry Clerk (No Experience) Job at super-color

 ...seeking a Basic Data Entry Clerk for a work-from-home position with a requirement of 25 words...  ...data entry or administrative assistant experience is not mandatory, it can be an added advantage...  ..., etc. If you are seeking a part-time remote work-from-home job, this is an excellent... 

European Wax Center

Licensed Esthetician Job at European Wax Center

 ...skin care and waxing technique, well give our guests a reason to walk in and strut out.European Wax Center is in search of licensed estheticians & cosmetologists to join our nationwide centers! All of our centers are located in busy shopping centers sure to drive...