create/update documentation related to information security systems, processes and procedures.
This position will work 3 days in the office and 2 days remote.
Key Responsibilities:
- Performs initial analysis, identification, and documentation of network intrusions and computer systems compromises.
- Serves as a member of the CSIRT team and will assist with incident response efforts including Detection, Verification & Triage, Scoping, Containment, Eradication, Recovery, Remediation
- Identifies and recommends potential solutions to improve the existing security posture and assist with testing/POC efforts as appropriate.
- Maintains and proactively monitors the Firm’s information security systems to include:
- Security Information and Event Management (SIEM) Platforms
- NGFW Appliances
- IDS/IPS Systems
- AV/EDR/XDR Platforms
- DLP/FRP Systems
- MFA/SSO Systems
- Identifies and recommends solutions to improve the Firm’s security posture and assist with testing/POC efforts as appropriate.
- Proactively research trending Tactics, Techniques, and Procedures (TTP) to aid in the identification of security events that may occur within the organization.
- Leads the firm’s patching/software update team efforts to ensure that the firm maintains the most up-to-date operating system and firmware revisions applicable to the systems.
- Monitors email filtering systems such as Anti-Spam, Anti-Malware.
- Maintains and increases professional and technical knowledge through participation in professional development activities including webinars, seminars, conferences and formal training classes.
- Assist with firm’s disaster recovery and business continuity planning and testing activities.
- Keep supervisor and peers informed of all changes and threats to the systems.
- Bachelor’s degree (four-year college or technical school) Preferred. Field of study: Information Technology, Information Security, Computer Science or related qualifications.
- Must have at least 2 years of experience in a general IT related role - experience in a system support role in an enterprise network and good workstation experience (ie. Windows 10 or greater), and a solid understanding of network connectivity (wired and wireless) and troubleshooting skills, and exposure to servers.
- Knowledge/experience with incident response, malware, and Azure security tools.
- Preferred certifications include: Comp TIA Security+, ISC2 SSCP, Microsoft Azure Certifications, SANS GSEC
- Familiarity with systems such as: Virtualization, Active Directory, Printing, DNS/DHCP, TCP/IP, Email Systems, LAN/WAN Networking.
- Familiarity with basic scripting e.g. PowerShell, Python.
- Must carry a Firm-managed mobile device and be available after normal working hours.
- Experience in an information security role or comparable experience
- Be available 24x7 in order to respond to security incidents.
- Will occasionally be required to work more than 37.5 hours a week.
- Must have proficient keyboard skills.
- Some travel to other Firm locations and/or remote training facilities may be necessary.
- Interpersonal skills necessary to communicate effectively in person, by email and telephone to provide information to clients, attorneys and staff with courtesy and tact.
- Passionate about information security and pursuing, certification/education in the field.