Cforce IT Solutions
Key Responsibilities Monitor and investigate security alerts and events from various security platforms. Perform initial investigation and analysis of potential security incidents. Analyze logs, alerts, IP addresses, domains, URLs, processes, and other Indicators of Compromise (IOCs). Investigate suspicious user activities, endpoint behavior, network traffic, and email threats. Perform basic threat hunting and security event correlation. Assist with incident response, containment, and remediation activities. Validate vulnerabilities and assist with vulnerability remediation and patch management. Document investigation findings, actions taken, and recommendations. Create and maintain incident reports and security documentation. Escalate confirmed or high-risk security incidents to the appropriate team. Required Skills Communication Skills Good written and verbal communication skills. Able to communicate technical security findings clearly to both technical and non-technical users. Comfortable communicating through email, chat, and incident/ticketing platforms. Able to properly document investigation findings and provide clear recommendations. Investigation & Analytical Skills Strong investigation and analytical skills. Ability to analyze security alerts and determine whether activity is benign, suspicious, or malicious. Ability to correlate information from multiple security tools and log sources. Strong attention to detail and ability to identify unusual patterns or behavior. Ability to troubleshoot and investigate security-related issues independently. Willingness to learn and continuously improve cybersecurity knowledge. Preferred Technical Experience Experience with, or working knowledge of, the following cybersecurity and IT platforms is highly preferred : IBM QRadar – SIEM monitoring, offense investigation, event/log analysis, and correlation. CrowdStrike Falcon – Endpoint detection and response, alert investigation, and threat analysis. Tenable – Vulnerability scanning, vulnerability validation, and remediation tracking. BeyondTrust – Privileged access management and privileged account monitoring. CSW – Security monitoring and investigation. Cisco ETD – Email threat detection and investigation. Mimecast – Email security, threat investigation, and message tracing. Palo Alto Panorama – Firewall monitoring, traffic investigation, and security log analysis. ServiceNow – Incident management, ticketing, documentation, and workflow management. Note: Candidates do not need to have experience with all of the tools listed above. Candidates with experience in similar cybersecurity platforms are also encouraged to apply. We are looking for someone who is: Analytical – able to investigate security events and connect information from different sources. Detail-oriented – understands that small details can be critical during security investigations. Proactive – willing to investigate beyond the initial alert and identify potential threats. Communicative – able to clearly explain findings and provide timely updates. Responsible – understands the importance of security operations and proper incident handling. Adaptable – willing to work on either day or night shifts depending on operational requirements. Curious and willing to learn – continuously develops technical and cybersecurity knowledge. Team-oriented – able to work effectively with SOC, IT Infrastructure, Network, and other teams.
Cforce IT Solutions