Senior Cyber Event Analyst
NBCUniversal’s Cyber Defense Operations team is responsible for providing cyber threat intelligence, event analysis, incident response and threat hunting for all areas of NBCUniversal in a highly collaborative, fast paced, and agile fashion. As a member of the Cyber Response team, a candidate can expect to utilize their technical expertise to assess, contain, and remediate cyber threats. The Senior Cyber Event Analyst is responsible for analysis, escalation and initial response actions of security events and alerts to incidents. The ideal candidate would have a working knowledge of current and relevant security technologies and how to apply them to cyber event analysis and response actions. A clear investigative methodology with a focus on preserving evidence and analyzing data to form conclusions that will steer response directions. Experience analyzing and responding to security events and incidents with practical and working knowledge of response analysis methodologies and enhancing security response processes. In addition, the candidate must be willing and available to work any shift including overnight shifts, weekends, and holidays to meet the needs of a 24x7/365 operation, with possibility of schedule changes based on business needs and priorities. The role involves regular interaction with various groups and leadership within the organization in order to accomplish job responsibilities. Working under the direction of the Manager, Cyber Response, the successful candidate will be responsible for participating in the following activities: Triage, scope, and disposition all security alerts or operational requests across multiple technology platforms (Cloud, Hosts, Networks, Applications, Email) to identify threats needing to be escalated to Incident Response and the Business Day-to-day operational tasks related to the ongoing support of Cyber Operations. Responsible for documenting evidence throughout the incident life cycle, conducting shift handovers, escalating security events to incident response, and providing support during cyber security incidents. Responsible for the ticket queue triage: prioritization, assignment and disposition of security incident tickets/events. Responsible for analyzing threat data from multiple sources and building evidence backed dispositions. Responsible for front line triage and response including some containment and remediation actions such as network isolation of hosts and blocking indicators of compromise within security perimeter tools. Analyst must keep detailed reports on all analysis activity, documented in the case management tool to validate process adherence. Responsible for contributing to the creation and updating of new and existing SOAR playbooks and runbooks and general response documentation. Identify operational gaps in security processes, provide ideas for solutions and take ownership for implementation. Peer review of tickets for fellow Cyber Event Analysts that request one. Managing the Cyber hotline during their shift. Act as a mentor to any Cyber Event Analysts and Intern’s that may be part of our team. Act as a SME for our team for our documented policies, processes and procedures. Identifying areas of educational/knowledge improvements including taking ownership of appropriate documentation and communication to the team.