All roles

Manager-Security Incident Response & Operations; Remote

Remote · USA Full-time New today

Position: Manager-Security Incident Response & Operations (Remote) Description American Specialty Health Incorporated (ASH) is seeking a Manager-Security Incident Response & Operations to join our Information Security department. The primary purpose of this position is to be responsible for providing cyber incident response subject matter expertise while collaborating on numerous security projects and operational improvement initiatives. This position will support the operational activities of junior-level cyber analysts while helping to develop the team's investigative skillset, process, and playbooks. In this role you will champion incident response services enrollment requirements to ensure progressive operational effectiveness and alert fidelity. In addition, you will be responsible for continuously identifying gaps and managing the improvements in security response process, technologies, and monitoring. Working closely with internal architecture, engineering, and project management teams, you will ensure cyber-defense requirements are identified and communicated early in the project life cycle. Salary Range American Specialty Health complies with state and federal wage and hour laws and compensation depends upon candidate's qualifications, education, skill set, years of experience, and internal equity. $112,500 to $175,000 Full-Time Annual Salary Range. Remote Worker Guidelines

  • Remote Worker Guidelines:

This position will be trained remotely and must be able to work from home (WFH) in a designated work area with company-provided technology equipment. This WFH position requires you have a stable connection to your Internet Service Provider with the ability to participate by video in online meetings over a reliable and consistent network. The internet connection must have a consistent 50 down/10 up Mbps minimum internet speed. 100 down/20 up is recommended to support higher quality video meetings.

Responsibilities

  • Providing cyber incident response subject matter expertise while collaborating on numerous security projects and operational improvement initiatives.
  • Manage SIEM operations.
  • Support cyber incident response actions to ensure proper assessment, containment, mitigation, and documentation.
  • Hunting to identify anomalous and malicious behavior, enhance SIEM rules to automate continuous identification.
  • Interact and assist other investigative teams within American Specialty Health on time sensitive, critical investigations.
  • Manage third-party MSSP (SOC) to ensure appropriate levels of incident response time, enrichment of SIEM content, and identify gaps in logging and monitoring coverage.
  • Drive continuous improvement of incident response processes, playbooks, and detection capabilities.
  • Participate as part of a close team of technical specialists on coordinated responses and subsequent remediation of security investigations.
  • Train matrixed team members on hunting, investigative, and forensic tools and processes
  • Help create, support, and participate in purple team exercises.
  • Manage the security monitoring enrollment process to ensure adequate coverage and effectiveness of all new and existing cloud and premise-based applications, services, and platforms.
  • Maintain detailed tracking plan of all internal/external enrollment outcomes/recommendations, and provide support through to implementation.
  • Act as a liaison between security operations, engineering, security architecture, network & system operations, and functional project teams to ensure effective project implementation that meets incident response requirements.
  • Work with colleagues in other technology departments as well as the business and product offices to establish effective, productive business relationships.
  • Define baseline security monitoring requirements for all new projects, services, and applications joining the American Specialty Health network.
  • Facilitate the development and tuning of SIEM rules to support enrollments and ensure high fidelity alerting.
  • Review and analyze cyber threats and provide SME support and training to junior level security analysts.
  • Performs other duties as assigned.
  • Complies with all policies and standards.

Qualifications

  • Bachelor's Degree in Computer Science, Information Security, Computer Engineering, related area of study, or equivalent experience required. If related experience, high school diploma required.
  • 10+ years of combined relevant experience using hunting and using IR technologies and/or industry-standard tools required.
  • 5 years in SIEM management required including:
  • Content management (e.g. parsing and correlation rules)
  • Case management ensuring sufficient due diligence steps are completed
  • Security Orchestration, Automation, and Response (SOAR) technology
  • Threat intel feeds
  • Use case mapping
  • 2 years of management experience required.
  • Experience writing thorough investigative reports detailing incident findings required.
  • Experience with Threat Intel providers and distribution of relevant information required.
  • Demonstrated experience in an enterprise-level incident response team or security operations…

Apply tot his job Apply To this Job

Related roles

Cybersecurity Manager Remote / Telecommute Jobs

Remote · USA Full-time

Staff Security Researcher

Remote · USA Full-time

Cyber Security Analyst job at Canandaigua National Bank in Pittsford, NY

Remote · USA Full-time

Sr. Security Researcher; Remote

Remote · USA Full-time

Senior Threat Researcher, Unit 42 (Clearance Required)

Remote · USA Full-time

IT & Security Audit Analyst III

Remote · USA Full-time

Senior Manager, Data Engineering

Remote · USA Full-time

Work-at-Home Data Analysis Associate

Remote · USA Full-time

Remote Data Entry, No Experience

Remote · USA Full-time

Data Pipeline AgTech Engineer

Remote · USA Full-time

Experienced Data Entry Specialist – Live Chat Support for arenaflex

Remote · USA Full-time

Territory Manager (GI) (Lexington KY) (Lexington, KY, US)

Remote · USA Full-time

Vehicle Detailer (Day Shift)

Remote · USA Full-time

Experienced Public Policy Intern – Policy Central Team Member for Summer Intern Program at Airbnb, Focusing on Strategic Policy Development, Research, and Storytelling

Remote · USA Full-time

Data Scientist (English Speaking)

Remote · USA Full-time

Experienced Remote Chat Support Agent – Flexible Global Opportunities for Customer Service Professionals to Work from Anywhere and Earn $25-$35/hr

Remote · USA Full-time

Experienced Data Entry Clerk (Typist) – Remote Work Opportunity with arenaflex

Remote · USA Full-time

Remote Accountant (Fund Accounting)

Remote · USA Full-time

Experienced Customer Service Representative – Remote Opportunity at arenaflex

Remote · USA Full-time

Experienced Data Entry Specialist (Remote) – Join arenaflex's Dynamic Team

Remote · USA Full-time