IT Cyber securité Specialist
Job Summary
Activities:
- Security incident management (analysis escalation resolution) including incident documentation;
- Coordination of different teams with a view to resolving the security incident or to improving the level of security;
- Analysis of network flows and correlation with alerts;
- Contribution to securing network architectures relevance of configurations exception management (impact and risk analysis);
- Participate in tuning protection and detection rules particularly on network security tools (WAF IDS/IPS NDR Proxy etc.);
- Implement exception management (impact and risk analysis);
- Cross-functional support on security tools;
- Post-mortem analysis of incidents: technical retrospective recommendations and follow-up of action plans with the ITSM team;
- Processing of alerts (SIEM WAF etc.) originating from the SOC and/or security tools;
- Security monitoring and threat intelligence: monitoring of CVEs IOCs MITRE ATT&CK tactics;
- Participation in the development or continuous improvement of SecOps processes procedures and guides;
- Support for IT projects related to operational security: security review delivery of technical and functional opinions active participation in the project team;
- Use of ITSM tools (Jira Service Management etc.);
- Any other activity related to operational security as required by the needs and priorities of the service;
Intervention methods:
- The mission is carried out within the security division of clients under the supervision of the operational security manager.
- The profile ensures regular full-time service of 40 hours/week.
- In addition to regular services it provides a rotation system to guarantee 24/7 on-call availability with a guaranteed response time. Certain alerts must be addressed within a maximum of 30 minutes.
- The SOC and the client will be able to call the on-call person to take charge of analyzing priority 1 or 2 incidents implement response actions and coordinate teams until the incident is resolved. Integration into existing processes (incident management change management SOC etc.)
Expected deliverables:
- Activity and incident reports progress report on post-incident recommendations
- NIS2: Initial notification preliminary report and final report
- Change log of rules (who what why)
- Optimized security tool configurations
- Technical documentation process and procedure
- Feedback and recommendations for improvement
- Cyber dashboard operational tactical and strategic reporting
- Security KPI Monitoring
Expected behavioral skills:
- Communication claire
- Rigorous change management
- Emergency management
- Incident Prioritization
- Adaptability and learning
- Technical curiosity
- autonomy
- team collaboration
- Assertiveness and the ability to challenge
Required Skills:
incident managerFirewallDNSproxiesSIEMXDRWAFCybernetwork security
About Company
30 employees
Welcome to Sansaone, a dynamic force in the realm of ICT talent acquisition. Born out of a passion for excellence and a vision for connecting outstanding professionals with forward-thinking organizations, we stand as a beacon for strategic recruitment solutions in the Information and ... View more