IBM is a global technology and consulting company that helps organizations advance their hybrid cloud and AI journeys. The Technical Operations Analyst will safeguard an organization's digital infrastructure by identifying, analyzing, and mitigating cyber threats, investigating security incidents, managing incident reports, analyzing network and endpoint events, and supporting vulnerability management and cyber threat intelligence activities.
**Conduct Event Investigations:** Investigate security incidents using SIEM, SOAR, EDR, and XDR platforms, and apply industry frameworks like MITRE ATT&CK and the Cyber Kill Chain to understand and counter adversary tactics effectively
**Manage Incident Reports:** Prioritize and manage incident reports, providing actionable recommendations and responses to strengthen the client's security posture
**Analyze Network and Endpoint Events:** Interpret security tools and logs from Windows, MAC, and Linux systems to identify potential threats
**Engage in Vulnerability Management:** Participate in vulnerability management and cyber threat intelligence activities to identify and anticipate potential threats
**Provide Actionable Recommendations:** Deliver recommendations and responses to clients to enhance their security posture
Qualification
Required
High School Diploma/GED
Familiarity with a variety of cybersecurity tools, including SIEM, SOAR, EDR, and XDR platforms, to monitor, prioritize, investigate, and respond to security incidents
Knowledge of industry frameworks like MITRE ATT&CK and the Cyber Kill Chain to understand and counter adversary tactics effectively
Ability to interpret security tools and logs from Windows, MAC, and Linux systems to identify potential threats
Participation in vulnerability management and cyber threat intelligence activities to identify and anticipate potential threats
Familiarity with security technologies and certifications related to threat detection, response, and intelligence
Active TS/SCI is required
Active DoD 8570/8140 IAT Level II certification required (e.g., Security+ CE, CCNA Security, CySA+, GICSP, GSEC, or SSCP)
US Citizenship Required
Preferred
Bachelor's Degree
Exposure to scripting languages such as Python, PowerShell, or Bash is beneficial for automating tasks and interacting with various cybersecurity tools
Understanding cloud security principles and experience working with cloud-based security solutions can be advantageous in identifying and mitigating cyber threats
Familiarity with threat intelligence platforms and feeds can aid in staying up-to-date with emerging threats and improving incident response capabilities
Benefits
Healthcare benefits including medical & prescription drug coverage, dental, vision, and mental health & well being
401(k)
Cash balance pension plan
IBM Employee Stock Purchase Plan
Financial counseling
Life insurance
Short & long-term disability coverage
Opportunities for performance based salary incentive programs
Generous paid time off including 12 holidays, minimum 56 hours sick time, 120 hours vacation, 12 weeks parental bonding leave in accordance with IBM Policy, and other Paid Care Leave programs
Paid family leave benefits to eligible employees where required by applicable law
Training and educational resources on our personalized, AI-driven learning platform where IBMers can grow skills and obtain industry-recognized certifications to achieve their career goals
Diverse and inclusive employee resource groups
Giving & volunteer opportunities
Discounts on retail products, services & experiences
IBM provides technology and consulting, including software, infrastructure systems, and cloud-based solutions.
Glassdoor
3.9
Founded in 1911
Armonk, New York, USA
10001+ employees
http://www.ibm.com
IBM provides technology and consulting, including software, infrastructure systems, and cloud-based solutions.