Detection Analyst
Core
Analyze security events, research alerts using multiple data sources, and mitigate risks to critical information.
Role type
Security Incident Detection Analyst
Builds
Security monitoring and incident response capabilities for critical information systems
Domain
Cybersecurity / Information Security
Deliverable
client delivery
Required skills
Incident analysis, vulnerability assessment, data loss prevention (DLP) monitoring, insider threat detection, forensic knowledge, SIEM tool usage, real-time alert prioritization
Preferred skills
Experience with User and Entity Behavior Analytics (UBA), knowledge of hardware and operating systems, understanding of CERT principles
Technologies
Digital Guardian, Sureview, Securonix, EnCase, Magnet, RMS, SIEM tools
Responsibilities
Deliver documentation to capture, respond to, and mitigate security events; Research events by correlating various data sources; Review alerts and risk ratings for critical information and high-risk events; Provide feedback to Critical Information Owners via periodic reports; Partner with appropriate teams (e.g., Forensics) to respond to incidents
Seniority
Mid-level, hands-on IC