CFA Institute
CFA Institute
CFA Institute yra pasaulinė pelno nesiekianti organizacija, aptarnaujanti investavimo srities specialistus finansų švietimo, profesinių kvalifikacijų, tyrimų ir politikos formavimo veiklos srityse. Jos paslaugos apima CFA programą ir kitus sertifikatus, pritaikytus skirtingiems karjeros etapams bei įvairioms finansų sektoriaus specializacijos kryptims. Organizacija taip pat skatina etikos ir profesinius standartus, padeda megzti ryšius ir teikia narystės paslaugas finansų specialistams visame pasaulyje.

Security Operations Analyst II (Remote, United States)

Investigate security alerts, incidents, and threats for CFA Institute across endpoints, identities, email, cloud services, and networks. Use Microsoft Defender, Sentinel, and KQL to support investigations, threat hunting, and incident response.

Aprašymas

  • Investigate security alerts and events across endpoint, identity, email, cloud, and network environments
  • Use Microsoft Defender XDR, Microsoft Sentinel, and KQL to correlate telemetry, investigate suspicious activity, and identify indicators of compromise
  • Lead routine and moderately complex investigations by assessing scope, severity, and business impact
  • Review escalated security cases with the managed security service provider and senior analysts
  • Support incident response activities from identification through investigation, containment, and recovery
  • Gather and analyse evidence to build accurate investigative timelines
  • Investigate phishing, suspicious email activity, credential compromise, and cloud or identity security events
  • Help develop and strengthen proactive threat-hunting capabilities
  • Suggest improvements to detection coverage, hunting queries, playbooks, and investigation procedures
  • Present technical findings clearly to technical and non-technical stakeholders and help prepare executive security briefings
  • Take part in a rotating on-call schedule for significant or time-sensitive security incidents

Reikalavimai

  • Professional hands-on experience in a Security Operations Center, cybersecurity operations, or a closely related technical security setting
  • Practical experience with Microsoft Defender and/or Microsoft Sentinel
  • Hands-on experience using KQL to query security data, investigate suspicious activity, or support threat hunting
  • Strong understanding of SIEM and EDR/XDR technologies and their investigation telemetry
  • Demonstrable experience investigating security alerts and incidents across endpoints, identity, email, and cloud environments
  • Experience investigating phishing, suspicious email activity, and potential credential compromise
  • Ability to work independently through complex or ambiguous situations and identify when escalation is needed
  • Understanding of incident response processes, security investigation methods, and attacker tactics and techniques, including familiarity with MITRE ATT&CK
  • Strong communication skills for explaining technical findings to varied audiences
  • Curiosity, commitment to continuous learning, and interest in emerging cybersecurity threats, technologies, and investigative methods

Privalumai

  • Eligibility for an annual incentive bonus
  • 12% employer contribution to a 401(k) or pension plan
  • Comprehensive medical benefits package
  • Health coverage
  • Generous time off
  • Competitive retirement plans
  • Flexible work options
  • Wellbeing and development programs

Susiję darbai