Information Security Analyst
ValonFull Time
Mid-level (3 to 4 years), Senior (5 to 8 years)
Candidates should possess a Bachelor’s degree in information security, information systems, or a similar field, along with relevant industry certifications in information security or management information systems security. A minimum of 3 years of experience in information security or a related technology role is required, demonstrating practical knowledge of information security, IT concepts, internet concepts, and business applications. Expertise in using infosec testing tools and scripts, with a history of leading their implementation, is essential. Specific experience with OpenSearch SIEM in a SOC environment, including configuration and customization for log collection, analysis, and real-time monitoring, is also required. Additionally, candidates must demonstrate in-depth knowledge and practical experience in managing Security Operations Center (SOC) activities, including intrusion detection systems, threat intelligence gathering, and response protocols.
The Information Security Manager will lead and manage a team in designing, developing, documenting, and analyzing configurations, rules, and alerts for systems, services, and networks. This includes overseeing the creation, management, and refinement of security alerts, and developing effective alerting protocols. The manager will conduct security, vulnerability, and risk assessments across services and applications, and guide the infosec analyst team in developing policies, procedures, and response playbooks. Responsibilities also include assisting in the creation of baseline security configuration standards, supervising the monitoring, investigation, and response to security incidents and alerts, and facilitating root cause analyses of vulnerabilities and incidents. The role involves driving the team's continuous learning, preparing reports for leadership on technology status and compliance issues with risk mitigation recommendations, and collaborating with business units to ensure adherence to security policies. The manager will also provide recommendations regarding the hiring, firing, promotion, and discipline of subordinate employees.
Security awareness training and phishing simulations
KnowBe4 provides security awareness training and simulated phishing exercises to help organizations combat social engineering threats. Their platform is designed to be easy to use and can be quickly implemented, allowing IT professionals to deploy training programs faster than many competitors. The service includes a variety of training modules and phishing simulations that are accessible through a subscription model. A dedicated Customer Success team supports clients during the onboarding process, ensuring a smooth transition without requiring extra consulting time. The main goal of KnowBe4 is to enhance the security posture of businesses by educating employees about potential cyber threats.