Security Incident Response Incident Coordinator
hace 7 días
The Security Incident Response Control Center (SIRCC) Incident Coordinator position will serve as the in-region coordinator for all DXC cyber security incidents. Each follow-the-sun region will have a coordinator who will function in the incident coordination role in cooperation with the other coordinators in the other regions. Security incidents will be handed off between coordinators as regions go off and come online for their normal working hours to ensure continuity of the incident response process. Coordinator tasks consist of reviewing the work and consulting with the SIRCC analysts to ensure that a given security incident is being handled in an appropriate and expeditious manner according to its severity and risk.
**Job specifics/responsibilities**:
- Ensuring that security incidents are prioritized correctly and handled in a manner reflecting their priority.
- Ensuring tasks necessary to the verification, mitigation, remediation and reporting of security incidents are assigned to SIRCC analysts and progressing in a satisfactory manner.
- Ensuring higher priority incidents are continuing to progress as regions go offline and come on line in the follow-the-sun model in coordination with other regional incident coordinators.
- Ensuring the handoff of incident response activity from the regional shift before and after the region of responsibility.
- Ensuring the appropriate incident escalations and reporting are taking place in accordance with established policy and process guidance.
- On-call duties for escalation of Security Incidents
- Responsible for peer review, final approval, and delivery of significant incident reports (e.g. Root Cause Analyses), management briefings, and incident updates
- Take the lead in management and technical update meetings during significant incidents, delegate tasks to the SIRCC analyst team members, to other security teams, and to other business units.
- Define the meeting timeframes and scheduling for all update briefings.
- Document action items carried out by the Incident Coordination team
- If required, task the SIRCC Incident Analyst team members to complete additional incident related actions outside of meetings
- Liaise with SIRCC Analysts to ensure that SIRCC action items are being actioned correctly, and provide guidance where necessary to facilitate the completion of such tasks
- Peer review and release of management alerts notifications.
- Use intelligence sources to proactively investigate the environment for threats and real or potential security breaches
- During incidents, lead reactive intelligence analysis, and once a basic methodology is established, hand over ongoing tasks to the SIRCC Analysts for continued analysis.
- Peer review results of the SIRCC Analysts analysis of intelligence (e.g. correlation of logs from multiple tools)
- Liaise with other Incident Coordinators to allocate daily and longer term tasks between different coordinators
- Own security tools used by SIRCC and contribute to their strategic development
- Ongoing mentoring of SIRCC staff
- Implementation and management of minor SIRCC projects, and development and documentation of initial draft of project-related processes
- Liaise with SIRCC Manager to completely develop and implement new processes as required
- Work with the SIRCC Manager to develop acceptance criteria, SLA’s, processes, and procedures as required for new tasks and processes being assigned to the SIRCC team by management
**Technical skills**
- Experience with gathering Open Source Intelligence (OSINT)
- Understanding of the requirements for security audit processes/frameworks, such as SOX, SAS70, or ISO27001
- Experience with programming languages such as Python, Perl, Java or C++
- The ability to perform an in-depth analysis of log files from multiple devices and environments and identify indicators of security threats.
- Solid knowledge of common types of Information Security threats.
- In-depth understanding of TCP, IP, and other lower-level network protocols, as well as common higher-level protocols such as HTTP, HTTPS, SMTP, FTP, and others. The ability to conduct an in-depth analysis of network traffic and packet captures.
- Strong familiarity with network security devices, including firewalls, Intrusion Detection/Prevention Systems, proxies, switches, routers, and others. Understanding of modern network operating systems.
- Understanding of, and experience using, Unix-style operating systems, such as Solaris, Linux, or BSD.
- Current or recent experience working with enterprise level anti-malware or advanced endpoint protection packages.
- Experience with Operating System security, administration, and logging in an enterprise environment.
- Previous experience with process and procedure development.
- Experience dealing with cybercrime and working in an environment that requires an investigative response when dealing with computer-based electronic evidence.
- Fluent in written and verbal English
-
Security Incident Response Specialist
hace 15 horas
San Francisco, Heredia, Costa Rica Tebra A tiempo completoAbout the RoleWe are seeking a highly skilled Senior Security Incident Responder to join our team at Tebra. As a key member of our security team, you will play a critical role in identifying and responding to cybersecurity threats.In this position, you will be responsible for investigating security incidents using log data, networking tools, and big data...
-
Security Incident Response Professional
hace 1 día
San José, San José, Costa Rica Smartsheet A tiempo completoThe Role of Cyber Security AnalystIn this critical position, you will be responsible for SecOps capabilities that detect and respond to various security incidents globally. As a security analyst, you will perform hands-on tasks and have the opportunity to enhance the overall security incident response experience of the organization. Your expertise will...
-
Incident Response Team Director
hace 15 horas
San Francisco, Heredia, Costa Rica Experian A tiempo completoWe are seeking an experienced cybersecurity professional to join our Global Security Office as a Incident Response Team Director. In this role, you will be responsible for leading a team of analysts who respond to and contain security incidents that may impact our information assets.Responsibilities:Lead a team of incident response analystsDevelop and...
-
Cyber Incident Response Lead
hace 7 días
San Francisco, Heredia, Costa Rica Experian A tiempo completoFull-timeEmployee Status: RegularRole Type: HomeDepartment: Legal & ComplianceSchedule: Full TimeShift: Day Shift**Company Description**:Experian is the world's leading global information services company.During life's big moments - from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers - we empower...
-
Security Incident Response Analyst Tier 1
hace 7 días
San José, Costa Rica DXC Technology A tiempo completo**Job specifics/responsibilities**: - Receive input from various event sources, investigate it for unusual and potentially malicious behavior that may indicate security incidents, and escalate any suspicious activity or anomalies to the Tier 2 SIRCC Analyst team; - During security incidents, liaise with the Tier 2 SIRCC Analyst and Tier 3 Incident...
-
Cyber Incident Response Team Lead
hace 22 horas
San Francisco, Heredia, Costa Rica Experian A tiempo completoCompany DescriptionExperian is the world's leading global information services company.During life's big moments - from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers - we empower consumers and our clients to manage their data with confidence.We help individuals to take financial control and...
-
Incident Response Specialist
hace 4 días
San José, San José, Costa Rica Damovo A tiempo completoWe are looking for a highly skilled Incident Response Specialist to join our dynamic and growing global ICT organization based in Costa Rica. As an Incident Response Specialist, you will play an integral role owning all incidents and service requests throughout the lifecycle.Your key responsibilities will include assigning incidents/service requests within...
-
Incident Response Specialist Role
hace 4 días
San Francisco, Heredia, Costa Rica Moody'S A tiempo completoWe are seeking an experienced Incident Response Specialist to join our team at Moody's. In this role, you will lead the response to complex cybersecurity incidents, leveraging your technical expertise and problem-solving skills to resolve issues efficiently.Key responsibilities include:Leading incident response efforts, including containment, eradication,...
-
Cyber Incident Response Delegate
hace 4 semanas
San Francisco, Heredia, Costa Rica Ibm A tiempo completo**Introduction****Your Role and Responsibilities**- Act as a delegate to the IBM Cloud CISO by overseeing cyber incidents in collaboration with IBM CSIRT, Legal, and other various security teams within IBM.- Provide final approvals for the Root Cause Analysis performed post-incident and ensure preventative actions are in place with the responsible parties.-...
-
Incident Response Specialist
hace 7 días
San José, San José, Costa Rica Crg Solutions A tiempo completoCrg Solutions is seeking a Cybersecurity Threat Hunter to join its team. This role is responsible for identifying and mitigating cyber threats through digital forensics investigations and threat hunting.The ideal candidate will have extensive experience in conducting digital forensics investigations, including identifying attack vectors, understanding attack...
-
Incident Response Analyst
hace 4 días
San José, Costa Rica Splunk A tiempo completoJoin us as we pursue our vision to make machine data accessible, usable and valuable to everyone. We are a company filled with people who are passionate about our product and seek to deliver the best experience for our customers. At Splunk, we’re committed to our work, customers, having fun, and most importantly to each other’s success. Learn more about...
-
Global Incident Management Lead
hace 5 días
San José, San José, Costa Rica Smartsheet A tiempo completoAbout UsSmartsheet was founded on the idea that teams and millions of people worldwide deserve a better way to deliver their very best work. We deliver a leading cloud-based platform for work execution, empowering organizations to plan, capture, track, automate, and report on work at scale.Job SummaryThis Global Incident Management Lead role plays a crucial...
-
Security Operations and Response Expert
hace 5 días
San José, San José, Costa Rica Smartsheet A tiempo completoJoin Our TeamWe are seeking a talented Security Operations and Response Expert to join our security team. In this critical role, you will be responsible for providing technical deep understanding of managing and coordinating security incidents, conducting lessons learned (PIR), mitigating cyber risks and improving security controls. You will also be...
-
Incidentes de Ti
hace 1 semana
San José, Costa Rica Grupo CMA A tiempo completoACERCA DE LA VACANTE Funciones del Puesto Cumplir el proceso de administración de incidentes (ciclo de vida del incidente) Menores y Mayores. Velar por el cumplimiento de los acuerdos de níveles de servicio para la atención de incidentes. Cumplir con el escalamiento definido del incidente para mitigar el impacto del incidente. Dar seguimiento al...
-
Incidentes de Ti
hace 1 semana
San José, Costa Rica Grupo CMA A tiempo completo**Acerca de la vacante**: **Funciones del Puesto**: Cumplir el proceso de administración de incidentes (ciclo de vida del incidente) Menores y Mayores. Velar por el cumplimiento de los acuerdos de níveles de servicio para la atención de incidentes. Cumplir con el escalamiento definido del incidente para mitigar el impacto del incidente. Dar seguimiento al...
-
Cyber Security Threat Response Manager
hace 7 días
San Francisco, Heredia, Costa Rica Experian A tiempo completoAbout ExperianExperian is a global information services company, empowering consumers and clients to manage their data with confidence. We help individuals take financial control, businesses make informed decisions, lenders lend responsibly, and organizations prevent identity fraud and crime.Cyber Security Threat Response Manager RoleThe Cyber Security...
-
Information Security Incident Responder
hace 4 días
San Francisco, Heredia, Costa Rica Equifax A tiempo completo**Key Responsibilities**We are looking for an Information Security Incident Responder to support our Security Operations Center. This includes performing threat hunting to identify potential security threats, developing and modifying SOC processes and procedures per internal standards, and providing support for incident management lifecycle activities.To be...
-
Senior Security Incident Responder
hace 22 horas
San Francisco, Heredia, Costa Rica Tebra A tiempo completo**About the Role**:A security engineer to join our team to focus on threat detection and response protection.In this position, you will investigate security issues using log data, networking tools and big data search engines to stop threats impacting our internal and external customers.You will be part of Tebra's security team as a trusted resource to help...
-
Lead Incident Management Engineer
hace 1 semana
San José, San José, Costa Rica Syniverse A tiempo completoSyniverse is the world's most connected company.Whether we're developing the technology that enables intelligent cars to safely react to traffic changes or freeing travelers to explore by keeping their devices online wherever they go, we believe in leading the world forward.Which is why we work with some of the world's most recognized brands.Eight of the top...
-
Cyber Security Threat Response Specialist
hace 5 días
San José, San José, Costa Rica Smartsheet A tiempo completoCompany OverviewSkyrocket your career with Smartsheet, a leading cloud-based platform for work execution. Our mission is to empower organizations to plan, capture, track, automate, and report on work at scale.Job DescriptionWe are seeking an exceptional Cyber Security Threat Response Specialist to join our security team. In this critical role, you will be...