Senior Detection & Response Analyst
Toyota Tsusho Systems US, Inc.
Plano, TX · పూర్తి సమయం
దరఖాస్తు చేసుకునే వారిలో మొదటి వ్యక్తిగా ఉండండి
- అనుభవం
- 4+ సంవత్సరాలు
- జీతం
- —
- ఖాళీలు
- 1
- పోస్ట్ చేయబడింది
- 11 గంటల క్రితం
- పని విధానం
- కార్యాలయంలో
- విద్య
- బ్యాచిలర్ డిగ్రీ
- పునఃప్రారంభం
- దరఖాస్తు చేసుకోవాలి
మీరు ఎక్కడ పని చేస్తారు
ఉద్యోగ వివరణ
About Toyota Tsusho Systems US, Inc.
Established in 2011, Toyota Tsusho Systems US, Inc. (TTS-US) operates as part of the Toyota group, delivering IT solutions globally to facilitate business operations. Evolving into a technology and mobility-oriented organization, TTS-US alongside its eight affiliates worldwide works towards securing a resilient Toyota global value chain. Their innovative capacity fosters limitless business opportunities.
Position Overview
The Senior Detection and Response Analyst plays a pivotal role in supporting the Regional Security Operations Center (RSOC) by providing continuous 24/7 monitoring and threat detection services to both internal and external clients. This role also involves leadership responsibilities during shifts, incident analysis, and enhancement of security monitoring measures.
Key Responsibilities
- Serve as the primary escalation point for security incidents, offering expert input on monitoring and suggesting enhancements.
- Step in as shift lead when required by directing and mentoring Incident Detection team members, prioritizing tasks, and addressing threats proactively.
- Ensure quality and timely completion of ID Analysts' tasks aligned with team lead expectations.
- Conduct comprehensive incident triage and analysis using cyber threat intelligence and security systems like intrusion detection tools and firewalls.
- Maintain up-to-date knowledge of the global threat landscape including cyber attacks, malware, phishing, DDoS, and physical security risks.
- Participate in 24/7 coverage and on-call rotations supporting RSOC operations.
- Collaborate with engineering teams by providing expert feedback and feature requests to improve automated SOC capabilities.
- Train and support team members within the Incident Detection Team to develop their skills.
- Enhance operational efficiency of daily security monitoring activities.
- Handle service requests from clients and internal staff related to security incidents.
- Assist in threat containment and remediation during incidents, documenting investigations via internal ticketing systems.
- Support Incident Response teams with advice and coordination to facilitate remediation efforts.
- Lead proactive threat hunting based on gathered intelligence.
- Generate daily and monthly security reports documenting findings and activities.
- Contribute to process standardization by creating documentation and playbooks to refine incident response procedures.
- Analyze investigation outcomes to identify security weaknesses and recommend posture improvements.
- Deliver timely security knowledge and training to support teams to strengthen incident detection efforts.
Essential Skills and Competencies
- Strong critical thinking and problem-solving abilities with a quick adaptability to evolving environments.
- Attention to detail combined with analytical proficiency.
- Effective verbal and written communication skills.
Qualifications and Requirements
- Minimum of 4 years' experience in security operations monitoring.
- Bachelor's degree preferred in Cybersecurity, IT, Computer Science, or related areas.
- Proficient with security operations frameworks, processes, and tools.
- Hands-on experience with cybersecurity tools such as Sentinel, Splunk, ATP, Symantec Endpoint, TrendMicro Antivirus, McAfee Web Gateway, Checkpoint Firewalls, Bluecoat, Sourcefire, and Active Directory.
- Advanced understanding of network monitoring and exploitation techniques.
- Technical expertise in security, networking, infrastructure, cloud platforms, and applications.
- Knowledge of risk assessment technologies and methodologies.
- Understanding of typical attack vectors including advanced threats from nation-state and financially motivated actors.
- Familiarity with web application attacks like SQL injection, XSS, invalid inputs, and forceful browsing.
- Insight into networking protocols like DNS, HTTP, and SMB at a technical level.
- Certifications such as GCIA, GCFA, GCIH, or CASP are advantageous.
- Experience with automation tools such as Tines is highly regarded.
- Competency in Microsoft Office suite and related documentation skills.