CenturyLink Lead Security Analyst (SOC) - Tier 3 in Singapore, Singapore
CenturyLink (NYSE: CTL) is the second largest U.S. communications provider to global enterprise customers. With customers in more than 60 countries and an intense focus on the customer experience, CenturyLink strives to be the world’s best networking company by solving customers’ increased demand for reliable and secure connections. The company also serves as its customer’s trusted partner, helping them manage increased network and IT complexity and providing managed network and cyber security solutions that help protect their business.
Reports to: Security Operations Manager – Asia Pacific
Support Hour: Shift Work
Position Objective/ Summary:
A lead technical role in the CyberSecurity Security Operations Center (CSOC) responsible for providing operation support on monitoring the MSS platform and incident response. Primary responsibility will be to follow procedures to triage and investigate security alerts, monitoring and responding to security threats, investigating cases, and taking immediate action or recommending a course of action to mitigate the threat. Facilitates the ingress, implementation and egress of complex client trouble / change requests for managed premise, cloud, NextGen UTM firewall, MDDoS, Threat Intelligence and Secure Log Management products. Provides mentoring, training and escalation support to junior Security Analysts and be involved with maturing incident response procedures and evaluating new security technologies. Represents security operations as technical lead and point of escalation with clients, vendors and internal corporate organizations. Takes ownership and leads on projects.
Serve as Tier 3 level for complex technical and procedural escalations;
Provide technical lead support to clients, vendors and coworkers as required;
Responsible for development and execution of incident response plans for escalated response processes;
Proactively identify indicators of compromise and generate and execute Incident Response Plan upon detection;
Provide Incident remediation and prevention documentation;
Handle User and Entity Behavior Analytics (UEBA) use cases of potential security incidents and security events in accordance with SOC processes and procedures;
Identification and resolution of complex issues in customer environments. Develop resolution and implementation plans;
Work in collaboration with other security and company departments (operations, legal, sales) to help identify / resolve chronic issues and assist with the creation and implementation of corrective / preventative action plans;
Research, analyze and identify potential vulnerabilities and security deficiencies;
Initiate escalation procedure to counteract potential threats/vulnerabilities;
Research and implement customer generated change requests for MSS products;
Responsible for operation, maintenance, and monitoring of network hardware and related control software providing a variety of customer services. Observe and control the status and performance of all security components of company products and services;
Perform tasks associated with the installation, turn up and maintenance of CenturyLink security infrastructure and escalation of same;
Conduct security training, new hire training and network impact reviews;
Coordinate repair and maintenance of security system with security integrators. Liaise directly with third party vendors / suppliers;
Participate in company sponsored job related activities plus training to further develop your management and technical skills;
He/she will be part of a rotating SOC shift and will need to manage their schedule accordingly so to ensure there is coverage during SOC shifts.
5 - 10 years’ of professional work experience in Information Security with at least a couple of years of SOC based experience;
Demonstrated proficiency exercising a detailed depth and breadth of technical subject knowledge to SME levels;
Possible security technology certifications (e.g. CISSP, SANS (GCIA, GCIH, GSEC));
BS/BA degree in Computer Science, Information Technology, or related discipline or equivalent experience;
Strong analytical skills to define risk, identify potential threats, document and develop action/mitigation plan;
A passion for information security and data security;
Knowledge/experience with Operating Systems (e.g. Windows Server, CentOS Linux);
Knowledge/experience of networking and firewalls (e.g. Cisco ASA, Palo Alto, Checkpoint, Juniper, Fortinet, Arbor, Radware);
Working knowledge of Elastic Stack (Elasticsearch, Kibana) and Log Management/SIEM (e.g. Splunk, QRadar, ArcSight);
Good to have programming and scripting skills (e.g. C++, Bash, Python, Perl, Powershell);
Foundational Knowledge of Enterprise Anti-Virus, IDS, Full Packet Capture and Host/Network Threat Analysis;
Knowledge of Threat Monitoring Procedures;
Experience with securing various environments preferred;
Experience working a SOC and doing incident response is preferred;
Strong leader and delegator;
Exceptional customer service skills;
Detail oriented individuals that work well in a team environment and have a hunger to learn;
Strong verbal/written communication and interpersonal skills are required to document and communicate findings, escalate critical incidents, and interact with customers, managers and vendors;
Must be able to satisfy local government / national background screening.
Bachelors or Equivalent in Information Systems or Computer Science
Requisition #: 205653
No Discrimination. We are committed to providing equal employment opportunities to all persons regardless of race, color, ancestry, citizenship, national origin, religion, veteran status, disability, genetic characteristic or information, age, gender, sexual orientation, marital status, family status, pregnancy, or other legally protected status (collectively, “protected statuses”). We do not tolerate unlawful discrimination in any employment decisions, including recruiting, hiring, compensation, promotion, benefits, discipline, termination, job assignments or training. Any offer of employment is contingent upon the results of a pre-employment drug test and background check.
The above job definition information has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job. Job duties and responsibilities are subject to change based on changing business needs and conditions.