|Preferred GIAC Certifications||GSOC, GMON, GCDA|
We’re passionate about unlocking the power of data in order to transform lives and create opportunities for consumers, businesses and society. For more than 125 years, we’ve helped businesses grow, consumers and small businesses gain access to financial services, and economies and communities flourish – and we’re not done.
Our 17k amazing employees in 40+ countries believe the possibilities for you, and the world, are growing. We’re investing in the future, through new technologies, talented people and innovation so we can help create a better tomorrow.
To do this we employ the greatest and brightest minds that share our purpose and want to make a difference. We embrace our diversity yet share similar values and growth mindsets.
What’s your next professional and personal goal? Let Experian help bring this to life
Successful candidate is required to work on 12 hours rotational shift
The Threat Detection Lead Analyst is an essential part of Experian’s Global Security Operation Center (GSOC) that perform in-depth analysis and further triage of security threats, proposes remediation actions, and takes part in the creation and steady improvement of correlation rules, processes and procedures and other department related documentation. The Threat Detection Lead Analyst is a leader within the organization, executing on strategic items that promote a strong information security posture. Below is the list of main tasks:
Investigate incidents using SIEM technology, packet captures, reports, data visualization, and pattern analysis.
Analyze, escalate, and assist in remediation of critical information security incidents.
Improve and challenge existing processes and procedures in a very agile and fast-moving information security environment.
Collaborate with external teams for incident resolution and escalations, ensuring questions and concerns from Experian users are answered in a timely manner.
Provide support and leadership to the tier one analysts, including feedback on quality of work, driving case quality.
Expert knowledge of:
Information security policies and goals
Log analysis and event traffic patterns
The current IT threat landscape and upcoming trends in security
Required Experience: 5+ years’ experience in the following areas:
Demonstrates advanced technical skills and hands-on knowledge, such as:
In-depth packet analysis skills, core forensic familiarity, incident response skills, public could security practices, and data fusion skills based on multiple security data sources
Security analysis and architecture of Azure and AWS cloud environment using security tools including Defender for Cloud, GuardDuty, CloudTrail, or CloudWatch.
System administration on Unix, Linux, or Windows
Network forensics, logging, and event management
Defensive network infrastructure (operations or engineering)
Vulnerability assessment and penetration testing concepts
Malware analysis concepts, techniques, and reverse engineering
In-depth knowledge of network and host security technologies and products (such as firewalls, network IDS, scanners) and continuously improve these skills
Security monitoring technologies, such as SIEM, IPS/IDS, UEBA, DLP, among others.
Scripting and automation
Demonstrates behavioral skills, such as:
Ability to work in a team environment, able to train and coach other team members
Excellent verbal and written communications skills and ability to produce clear and thorough security incident reports and briefings.
Strong logical thinking abilities, especially analyzing security events.
Excellent analytical and problem-solving abilities
Excellent organizational and attention to details in tracking activities within various Security Operation workflows.
Well established client-focused communication skills that requires to read, review, investigate, and summarize reports on complex issues, in a manner that can be understood by non-technical readers.
Ability to lead incident investigation efforts and effectively coordinate communications.
Bachelor’s degree preferred, but not required. Relevant technical and industry certifications are a plus, e.g. Comptia, GIAC certifications, CISSP, SIEM vendor-specific certifications.
All your information will be kept confidential according to EEO guidelines.
Experian Careers - Creating a better tomorrow together
Find out what its like to work for Experian by clicking here