Specialist Cybersecurity Ops Analyst
Job Summary
We are a team of over 500 talented individuals spanning more than 30 functions and areas of expertise and representing over 40 nationalities. Together we bring diverse perspectives and professional backgrounds to help shape the future of healthcare through innovation and technology.
This is your opportunity to explore a world of possibilities across areas such as Data & Analytics Digital Technology & Innovation Cybersecurity R&D Operations Global Distribution Finance Regulatory Affairs General & Administrative Human Resources and many more.
Located in the heart of Lisbon our AMGEN office fosters a culture of innovation excellence and purpose. Come thrive with us at AMGEN supporting our mission To Serve Patients.
What we do at AMGEN matters in peoples lives.
Incident Response Specialist Cybersecurity Ops Analyst
ABOUT THE ROLE Amgen is seeking an Incident Response Specialist Cybersecurity Ops Analyst who will report to the Senior Manager Information Systems and will be based in Portugal ACC. At Amgen our mission is simple: to serve patients.
Leading Amgens Cyber Security Organization the Incident Response Cybersecurity Ops Analyst engages with key business and operational partners in enhancing the detection response and remediation of cyber related attacks on Amgens global enterprise while contributing and delivering services and projects that support the mission priorities and objectives of the organization.
The Incident Response Cybersecurity Ops Analyst will be part of a global team and is responsible for building services around incident identification containment eradication recovery and lessons learned. You will be directly responsible for organizing training and equipping Amgen employees and contractors in a manner directly aligned with Amgens culture principles and core values.
In the capacity of Incident Response Cybersecurity Ops Analyst you will craft and oversee standard operating procedures field manuals and operating instructions. As part of the investigation or remedial processes you will have to engage with key business and operational partners in managing the detection response and remediation of cyber related attacks on Amgens global enterprise.
The Incident Response Cybersecurity Ops Analyst is within the Incident Response team and is expected to contribute to and deliver services and projects that support the mission priorities and objectives of the this vital role you will:
Key Activities of the Incident Response Specialist Cybersecurity Ops Analyst
- Execute all phases of the incident response lifecycle in accordance with the SANS PICERL framework including preparation identification containment eradication recovery and post-incident activities.
- Perform advanced investigations involving endpoint network cloud and identity-based security incidents across enterprise environments.
- Analyze security events and alerts from SIEM EDR/XDR NDR cloud security platforms and threat intelligence sources to determine the scope impact and severity of security incidents.
- Conduct enterprise-wide threat hunting using Indicators of Compromise (IOCs) Indicators of Attack (IOAs) behavioral analytics and the MITRE ATT&CK framework.
- Perform incident triage and validation to distinguish malicious activity from benign events and accurately scope security incidents.
- Correlate endpoint network cloud identity email and security control telemetry to reconstruct attack timelines and determine the extent of compromise.
- Perform root cause analysis to identify initial access vectors attacker techniques persistence mechanisms and opportunities to improve defensive controls.
- Develop and execute containment eradication and recovery strategies that minimize operational impact while preserving investigative evidence.
- Acquire preserve and analyze digital evidence in accordance with established forensic procedures and chain-of-custody requirements.
- Perform forensic analysis of endpoints and system artifacts including event logs registry data file system metadata browser artifacts and other operating system artifacts to support incident investigations.
- Assist with forensic collection and analysis of endpoint cloud email memory and disk artifacts to support incident scoping and investigative activities.
- Create and maintain detection content including SIEM correlation rules Sigma rules IOC feeds detection use cases and other analytics to improve detection and response capabilities.
- Develop automation and scripting using PowerShell Python Bash SQL or similar languages to improve investigation evidence collection and incident response efficiency.
- Collaborate with SOAR engineering teams to automate investigation enrichment containment and response workflows.
- Partner with Threat Intelligence Security Engineering Cloud Security Identity Network Security Endpoint Security and other cybersecurity teams to investigate and remediate complex security incidents.
- Produce detailed technical documentation forensic findings incident reports attack timelines and lessons learned to support remediation legal compliance and regulatory requirements.
- Maintain and enhance incident response playbooks forensic procedures investigation methodologies and standard operating procedures based on evolving threats and organizational requirements.
- Participate in tabletop exercises purple team engagements adversary emulation activities and incident simulations to validate and improve incident response capabilities.
- Research emerging threats attacker tradecraft vulnerabilities and defensive technologies to continuously improve the organizations detection response and forensic capabilities.
Basic Qualifications
We are all different yet we all use our unique contributions to serve patients. The incident response professional we seek is a great coordinator with 5 years of directly related experience
Preferred Qualifications
- Experience as an Incident Response analyst supporting a multinational organization
- Experience working with Agile principles and values
- Practical DFIR experience in Host Network Cloud (AWS GCP Azure) and Operations Technology (e.g. Purdue model layers 0-3.5)
- Excellent written and verbal communication skills to diverse target audiences
- Passionate collaborative and results oriented
- Comprehensive knowledge of the workings of security-related controls like firewalls intrusion detection systems anti-malware secure gateways security monitoring data encryption and other industry-standard techniques and practices.
- Extensive experience with security application tools and systems e.g. CrowdStrike QRadar Encase Office 365 Security Log and Endpoint analysis tools
- Demonstrated ability to coordinate/lead multiple projects/activities with competing priorities
- Excellent data-driven problem solving and analytical skills and proven experience within high-performance team.
- Skill in applying analytical ability; and communication techniques sufficient to present new or updated plans and procedures to Leadership for review and final approval with the expectation of little to no rework.
- Must be team-oriented placing priority on the successful completion of team goals.
- Must be highly motivated and able to work effectively under minimal supervision
- Experience with regulated systems (GxP SOX) in the pharmaceutical biotechnology healthcare industry
- Demonstrated knowledge of digital network telecom including TCP/IP and related network protocols Information Security standards and policies such as: ISO 27001/27002 NIST
- Preferred Certifications (Minimum one of the certificates is a plus):
- CISSP GNFA GCIH GCFE GCFA GRID CompTIA CySAAWS Security Specialist or equivalent certifications.
- CISSP GNFA GCIH GCFE GCFA GRID CompTIA CySAAWS Security Specialist or equivalent certifications.
APPLY NOW
Objects in your future are closer than they appear. Join us.
EQUAL OPPORTUNITY STATEMENT
Amgen is an Equal Opportunity employer and will consider you without regard to your racecolour religion sex sexual orientation gender identity national origin protected veteran status disability status or any other basis protected by applicable law.
We will ensure that individuals with disabilities are provided with reasonable accommodation toparticipatein the job application or interview process to perform essential job functions and to receive other benefits and privileges of employment.
.Salary Range
5232090EUR-7078710EURRequired Experience:
IC
About Company
Amgen, a biotechnology pioneer, discovers, develops and delivers innovative human therapeutics. Our medicines have helped millions of patients in the fight against cancer, kidney disease, rheumatoid arthritis and other serious illnesses. As an organization dedicated to improving the ... View more