Information Security Lead/Senior Analyst (SOC)
About Liferay
Liferay is a uniquely profitable open source software company with 850+ fiery-eyed employees scattered across the known world. Our flagship product is Liferay Digital Experience Platform (DXP) which companies like HP, Barclays, and Coach use to build great web experiences for their customers and employees. Along with making cool software, we have a greater-than-profit vision that fuels us. We are also self-funded which gives us the freedom to work on whatever we think brings the most value to customers and communities in the long run. Liferay also includes Liferay DXP Cloud, Analytics Cloud, and Commerce products.
About You and this Role
You’re excited about the chance to help build out the Information Security team. You’ve got 3+ years of experience working in security monitoring and incident response operations. You understand the tactics, techniques, and strategies of attackers. You love to detect, monitor, and alert all those around when you find attackers, deploy tools to fight back, play with red teams and improve response times to react in real time.
In this role you are going to lead and operate your own Security Operations Center, help other departments understand the nature of security and improve the security posture, be the cyber security shield of the company.
Key Responsibilities:
- Act as a lead in the incident response team, leading the effort to document and report the results based on the investigation of security incidents
- Identify, categorize, and prioritize detected incidents
- Support the resolution of incident(s) to reduce security risks
- Establish and enforce defined Incident Response procedures and security standards
- Maintain and create procedures for Security Operations Center duties
- Perform analysis of security exploits, threats, and vulnerabilities providing remediation activities
- Prepare and run accurate reports from operational data
- Assist in the coordination, documentation, and management of information security activities
- Support the resolution of information security issues outside of incidents, actively cooperating with other company departments.
- Mentor and encourage the growth of other team members
- Evaluate new security technology and trends, and then makes recommendations to strengthen our information security environment
- Research current industry practices and standards to improve information security
- Periodically review incident responses and suggest changes to procedures and processes
Required Qualifications:
- Bachelor’s Degree or equivalent from four year college or university in a STEM focused area or equivalent in a related field, or commensurate experience
- Beginner knowledge of software development and information technology operations (DevOps)
- Expert knowledge of Incident Response procedures and implementations
- Exceptional attention to detail and organization
- Ability to comprehend, analyze and interpret complex documents
- Possesses strong communication and problem solving skills
- Able to work independently and effectively as part of a team, while handling multiple tasks and responsibilities
- Ability to work in a global environment, fluent English level.
Optional BUT highly desired Certifications and field knowledge:
- Relevant experience with information security, control standards, and frameworks such as ISO27001, SOC 2, GDPR