This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
This position sits within the Vulnerability and Threat Management program at Sysco where you’ll use defensive measures and information collected from a variety of sources to identify, analyze, and report cybersecurity events that occur or might occur within the Sysco network to protect information, resources, and networks from threats.
Job Responsibility:
Receive, characterize, and analyze endpoint and network alerts from various sources within the enterprise and determine possible causes of such alerts to identify anomalous activity and potential threats to network resources and users
Provide timely detection, identification, and alerting of possible attacks/intrusions, anomalous activities, and misuse activities and distinguish these incidents and events from benign activities
Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack
Serve as an escalation point to SOC Analysts providing support, guidance, as well as work and track security incidents through final resolution
Create and maintain incident response processes, procedures and blueprints. Documenting and maintaining knowledge base of incident methodologies and plans
Requirements:
Security Certification
Minimum 7 years in IT
5 years in Incident Response
5+ years of cybersecurity incident response experience with excellent background in networking and security to include intrusion detection/prevention
Excellent knowledge of security applications such as IDS, IPS, EDR, SIEM, next-gen AV and anomaly detection tools
Knowledge of cyber attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks.)
Excellent knowledge of the 6 phases in Cyber incident response plan
Wide knowledge of application and IT product diversity, interoperability, and extensive knowledge in IT security
Ability to configure and conduct vulnerability scans using VM tools such as Tenable.io and Tanium
Nice to have:
Security+, CEH, OSCP/OSCE, CISSP, CISA, or GIAC
10 years in IT, Minimum 7 years in Incident Response