Fortinet→
SOC Analyst at Fortinet in Sunnyvale, CA
Entry LevelOn-siteFull-timeSunnyvale, CA$117k–$143k/yr
Skills
soc operationsincident response life cyclecyber kill chainthreat intelligencelayered securitycybersecurity frameworkssecurity log analysisvisualizationreporting technologiespostgresqlregular expressionsnetwork security technologiesfirewallssiemsandboxlinux system administrationwindows system administrationcybersecurity certificationssolution-focusedself-directeddisciplineconsistencyconflict management
Job Description
Summary: Fortinet is looking for a Security Operations Centre (SOC) Analyst to be part of the FortiCloud SOC-as-a-Service team. The role involves monitoring security events, identifying threats, assessing risks, and working with customers globally to improve their security posture.
Responsibilities:
- Monitor SOC alerts to detect potential threats
- Use threat intelligence feeds, triage alerts and filter out false-positives
- Create custom reports, dashboards, and execute log searches to support investigations and customer’s requirements
- Work with customers and Forensic analysis team to contain and eradicate incidents if need be
- Follow Incident Response playbooks, processes and procedures and help to improve them
- Create/Update use case detections to detect new threats from raw logs
- Create/Update playbooks to automate repetitive triage steps
Required Qualifications:
- Understanding of SOC operations and Incident Response Life cycle
- Understanding of Cyber Kill chain, threat vectors and threat intelligence
- Understanding of layered security at data, OS and network levels
- Understanding Cybersecurity Frameworks
- Hands-on experience with security log analysis such as AV, IPS, Anti-Spam logs
- Hands-on experience with visualization, reporting technologies
- Hands-on experience with PostgreSQL, regular expressions
- Hands-on experience with Network Security technologies such as Firewalls, SIEM, Sandbox
- Hands-on experience with Linux and Windows system administration
- Team player, solution-focused, conflict management skills
- Self-directed, takes initiatives
- Open to new challenges and learning opportunities
- Understands the importance of discipline, consistency and communication
- Good verbal and written communication skills
- Must be authorized to work in the U.S. without sponsorship
Preferred Qualifications:
- Previous working experience with Fortinet products is a bonus
- Cybersecurity certifications such as GCIA, GCIH, GMON, GSOC, CEH, Security+ is a bonus
- Graduates from IT degrees, or mid-career IT professionals with certifications in cybersecurity may apply
Required Skills: SOC operations, Incident Response Life cycle, Cyber Kill chain, Threat intelligence, Layered security, Cybersecurity Frameworks, Security log analysis, Visualization, reporting technologies, PostgreSQL, Regular expressions, Network Security technologies, Firewalls, SIEM, Sandbox, Linux system administration, Windows system administration, Cybersecurity certifications, Solution-focused, Self-directed, Discipline, Consistency, Conflict management
Benefits: Medical, Dental, Vision, Life and disability insurance, 401(k), 11 paid holidays, Vacation time, Sick time, Comprehensive leave program
Benefits
Medical
Dental
Vision
Life and disability insurance
401(k)
11 paid holidays
Vacation time
Sick time
Comprehensive leave program