Cyber Defense - Cyber Triage and Forensic Analyst

EY

7+ yrs Thiruvananthapuram Full Time Hybrid (office + remote)
EY logo
Posted : 1 week ago
Actively hiring

Job description

Join EY as a Senior Security Analyst in Cyber Defense, playing a critical role in bolstering our security posture. This position involves vigilant monitoring, effective incident assessment, and management. You'll collaborate with a dedicated team and leadership to ensure robust security oversight and contribute to joint security monitoring and incident response efforts.

Your responsibilities will encompass incident triage, in-depth investigations, clear communication, and comprehensive reporting. These activities are vital for maintaining the integrity and resilience of EY's cybersecurity defenses and protecting critical information assets.

This is an opportunity to be part of a global team that thrives on collaboration and innovation, working to protect EY and its clients in an increasingly data-driven world. We offer a supportive culture, inclusive environment, and the tools to build a career as unique as you are.

Responsibilities

Detect and respond to information security incidents, adhering to established procedures for security event alerting and participating in thorough investigations. Proactively hunt for threats and conduct expert security assessments, leveraging EDR, SIEM, and other advanced tools to understand and counteract the evolving cybercrime landscape. Communicate effectively with IT stakeholders during incident response, ensuring efficient containment, remediation, and precise identification of compromise indicators. Generate reports on incident metrics, analyze findings, and develop comprehensive documentation for clear understanding and resolution of security events. Serve as an escalation point for incident response, potentially acting as a shift lead and mentoring junior team members to enhance overall team capabilities. Analyze security events, provide critical feedback on existing security controls, and drive process improvements to fortify the organization's security defenses. Maintain and refine security incident processes, protocols, and standard operating procedures to align with current best practices in security incident response.

Qualifications

A foundational Undergraduate or Postgraduate Degree in Computer Science, Engineering, or a related discipline (e.g., MCA, MTech, BTech, BCA, BSc CS, BSc IT). A minimum of 7 years of comprehensive experience, with at least 5 years specifically focused on incident response, computer forensics, and Security Operations. Proven experience operating within a Security Monitoring/Security Operations Center (SOC) environment, including hands-on involvement with CSIRT and CERT operations. Demonstrated expertise in investigating security events, identifying threats, and analyzing vulnerabilities. A strong grasp of electronic investigation and forensic methodologies, encompassing log correlation, electronic data handling, investigative processes, and malware analysis. In-depth knowledge of both Windows and Unix/Linux operating systems, alongside practical experience with EDR solutions for effective threat detection and response. Proficiency in cyber investigations, including evidence management aligned with best practices and the utilization of advanced tools for threat detection and incident management, featuring advanced querying with KQL. Expertise in analyzing diverse datasets, identifying malware, and conducting thorough security event analysis from network and host-based attributes to uncover security incidents and latent threats. Capability to conduct detailed forensic investigations across various operating systems, adept at identifying obfuscation techniques and clearly communicating findings.

Essential Skills

Incident ResponseComputer ForensicsSecurity Operations Center (SOC)Cyber Threat HuntingEDRSIEMKQLMalware AnalysisActive Directory SecurityWindows Operating SystemsUnix/Linux Operating SystemsThreat DetectionNetwork Traffic AnalysisHost-based AnalysisData Analysis

Good to Have

SSCPCEHGCIHGCFAGCIAGSECGIACSecurity+Cloud Security (Azure)Electronic DiscoveryShell ScriptingPowerShell ScriptingPython ScriptingC# ScriptingC++ ScriptingC ScriptingNetwork Architecture SecurityServer Configuration Security

Highlights

  • Actively hiring

More Details

RoleCyber Defense - Cyber Triage and Forensic Analyst
IndustryCybersecurity, Management Consulting
DepartmentInformation Security Analyst, Cyber Threat Intelligence, Forensic Analyst
Employment TypeFull Time, Hybrid (office + remote)

About the Company

EY Global Delivery Services ( EY GDS) logo

EY Global Delivery Services ( EY GDS)

Cybersecurity

Cyber Defense - Cyber Triage and Forensic Analyst at EY | SkillMX | SkillMX