Security Operations Centre Analyst

il y a 4 jours


Luxembourg Vector Synergy Temps plein

**Location**:
Brussels, Belgium

**Security Clearance**:
EU Confidential

**Introduction**:
**Skills, knowledge, experience required**:

- At least 1 certification among the following:

- GPEN (GIAC Certified Penetration Tester);
- GCED (GIAC Certified Enterprise Defender);
- GPPA (GIAC Certified Perimeter Protection Analyst);
- GCFE (GIAC Certified Forensic Examiner);
- GCFA (GIAC Certified Forensic Analyst);
- GNFA (GIAC Certified Network Forensic Analyst);
- CFCE (IACIS Certified Forensic Computer Examiner);
- CCFP (Certified Cyber Forensics Professional);
- SCMO (SABSA Certified Security Operations and Service Management Specialist);
- Minimum 3 years’ experience in networking (TCP/IP, SNMP, DNS, Syslog-ng, etc.);
- Minimum 2 years’ experience in using, configuring and tuning a security information and event management (SIEM) tool;
- Knowledge on and minimum 2 years’ experience with the following network security solutions and technologies:

- Firewalls;
- Network intrusion detection systems (IDS) and intrusion prevention systems (IPS);
- Switches and routers;
- Advanced persistent threat (APT) detection solutions such as FireEye;
- DNS, DHCP, VPN;
- Network forensics (full packet capture);
- Traffic baselining analysis;
- Knowledge on and minimum 2 years’ experience with the following host-based security solutions:

- Host-based intrusion prevention systems (HIPS);
- Malware end-point protection;
- Operating system logs;
- Strong knowledge on and minimum 3 years’ experience in:

- MS Windows security events analysis;
- Security analysis of firewall, proxy, and IDS logs;
- Security analysis of applicable or middleware logs (Oracle HTTP Server, Apache HTTP Server, Oracle WebLogic Server);
- Minimum 1 year of experience in writing and optimizing:

- IDS signatures (preferably Snort and/or Suricata);
- YARA rules;
- Minimum 3 years’ experience with:

- SIEM tools such as:

- HP ArcSight Enterprise Security Manager (ESM) 6.x;
- IBM QRadar SIEM;
- At least one of the following log management solutions:

- HP ArcSight Logger;
- IBM QRadar Log Manager;
- Splunk;
- Minimum 2 years’ experience with:

- Snort or Cisco Sourcefire Next-Generation IPS (NGIPS);
- Cisco FireSIGHT;
- Check Point and Juniper firewalls;
- Blue Coat proxies.

**Desirable**:

- Minimum 2 years’ experience with STIX (Structured Threat Information Expression) with a particular focus on the following related standards:

- CybOX (cyber observables);
- CAPEC (attack patterns);
- MAEC (malware);
- TAXII (threat information exchange);
- Minimum 1 year of experience with:

- Suricata or Stamus Networks;
- ELK stack (Elasticsearch, Logstash and Kibana);
- FireEye (EX, NX, AX, FX, HX, IX).

**Duties/role**:

- Providing real-time monitoring of cyber defence and intrusion detection systems;
- Performing automatic-based processing (centralisation, filtering, and correlation) of security events;
- Conducting human-based analysis of automatically correlated events;
- Processing incoming warnings, alerts, and reports;
- Performing triage based on verification, level of exposure and impact assessment;
- Categorizing events, incidents, and vulnerabilities based on relevance, exposure, and impact;
- Opening tickets and ensuring case management;
- Activating initial response plan based on standard playbook entries;
- Maintaining incident response address book;
- Advising affected users on appropriate course of action;
- Monitoring open tickets for incidents and vulnerabilities from start to resolution;
- Escalating unresolved problems to higher levels of support, including the Incident Response and Vulnerability Mitigation teams;
- Configuring the SIEM components for an optimal performance;
- Improving correlation rules to ensure that the monitoring policy allows an efficient detection of potential incidents;
- Analysing risks and security policy requirements, and translating them into technical events targeting the system components;
- Identifying the required logs, files or artefacts to collect from the monitored system and, if necessary, possible complementary devices to deploy;
- Elaborating the relevant detection and correlation rules, and implementing them in the SIEM infrastructure;
- Configuring and tuning cyber-defense solutions;
- Reviewing and improving the monitoring policy on a regular basis;
- Integrating cyber-defence solutions for efficient detection;
- Defining dashboards and reports for reporting on KPIs;
- Producing qualified reports (including recommendations) or alerts to SOC customers and following up on actions;
- Contributing to the design of the overall monitoring architecture, in close relationship with the customers and system owners on one hand, and the Security Operations Engineering team on the other hand, by performing the following tasks:

- Assessing security events detection solutions and developing new solutions;
- Integrating the solutions within the security monitoring scheme (log collection architecture,



  • Luxembourg Vector Synergy Temps plein

    **Location**: Luxembourg, Luxembourg **Security Clearance**: EU Confidential **Introduction**: **Skills, knowledge, experience required**: - At least 1 certification among the following: - GPEN (GIAC Certified Penetration Tester); - GCED (GIAC Certified Enterprise Defender); - GPPA (GIAC Certified Perimeter Protection Analyst); - GCFE (GIAC Certified...

  • Security Analyst

    il y a 4 jours


    Luxembourg Vector Synergy Temps plein

    **Location**: Brussels, Belgium **Security Clearance**: EU Secret **Introduction**: The Security Analyst aims at identifying areas where information system changes are needed to support business plans and to monitor the impact in terms of change management. This service contributes to the general functional requirements of the business organization in the...


  • Luxembourg POST Group Temps plein

    **DEEP - System Analyst - Security**: **Date**:27 nov. 2024 **Lieu**: Luxembourg, Luxembourg **Entreprise**:POST Luxembourg Afin de renforcer les équipes de DEEP au sein de la Business Line Customer Support and Operations, nous recherchons actuellement un(e) **System Analyst - Security **(M/F/n) **à temps plein. **Vos missions**: - Prendre en charge le...


  • Luxembourg EBRC Temps plein

    Afin de renforcer les équipes de DEEP au sein de la Business Line Customer Support and Operations, nous recherchons actuellement un(e) **System Analyst - Security **(M/F/n) **à temps plein. **Vos missions**: - Prendre en charge le déploiement ainsi que la gestion quotidienne des architectures de sécurité de nos clients, notamment: - Firewall, IPS/IDS...

  • SOC Analyst

    il y a 1 jour


    Luxembourg LMGC Temps plein

    LMGC is an IT services company which specialized in SAP when it was founded in 2006. For over 10 years, LMGC has been providing IT expertise to its Luxembourgish and European customers. Well-known and recognized for its SAP know-how in Europe, LMGC is also a major player in the Greater Region, supporting its customers in the modernization and digitization of...


  • Luxembourg ELTRONA SECURITY SYSTEMS S.A. Temps plein

    La société Eltrona Security Systems travaille dans les métiers d’alarme intrusion, vidéo surveillance et télésurveillance (TeleAlarm ®). Elle développe et commercialise des systèmes de sécurité et de transmission afin d’apporter une solution globale à nos clients. Pour développer nos activités**,** nous recherchons, pour notre centre de...

  • Information Security Officer

    il y a 2 semaines


    Luxembourg Centre Hospitalier du Nord Temps plein

    Le Centre Hospitalier du Nord, issu de la fusion de l’Hôpital St Louis d’Ettelbruck et de la Clinique St Joseph de Wiltz, avec sa capacité d’accueil de 359 lits et plus de 1160 collaborateurs, et de 170 médecins agréés, est l’un des employeurs les plus importants du Nord du Pays. Nous offrons un cadre de travail agréable, un excellent...

  • Junior Operations Analyst

    il y a 1 semaine


    Luxembourg Satispay Temps plein

    **About Satispay** At Satispay, we're not just reimagining payments; we're pioneering a movement toward simplicity and accessibility. Picture yourself at the forefront of innovation, leading the way in revolutionizing payments - and beyond! - across Europe, alongside a vibrant community of like-minded individuals driven by a shared vision: simplifying...

  • Finance Operations Analyst

    il y a 2 semaines


    Luxembourg Schroders Temps plein

    **Finance Operations Analyst - Asset Management** **Who we’re looking for** We are looking for a motivated individual who will report to the Finance Operations Team Leader within the Finance department. The Finance Operations Analyst assists in calculating, accounting and reporting rebates due to intermediaries investing in pooled funds domiciled in...

  • Network Security

    il y a 2 semaines


    Luxembourg Sword Technologies S.A. Temps plein

    The main area to be covered is Network Security. The proposed resources will work specifically in the following area: **Network Architecture** Technical domains: Data Networks (LAN, WAN, MPLS, WIFI, Cloud Networking...) IP and MPLS protocols and technologies Routing and switching hardware and software solutions Network traffic segregation (VLAN, VRF,...