Analyst, Cybersecurity Operations (Detection & Response) L3
* Full-time
* McDonald's Office Location: International Office
McDonald’s growth strategy, Accelerating the Arches, encompasses all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts we are using our competitive advantages to further strengthen our brand. One of our core growth strategies is to Double Down on the 3Ds (Delivery, Digital and Drive Thru).
As a L3 Response Analyst within the Security Operations Center (SOC), your responsibilities include using defensive measures and information gathered from various sources to identify, analyse, and report cybersecurity events, ensuring the protection of McDonald's information assets. You play a crucial role in supporting the Incident Response process, responding to crisis situations, and mitigating immediate and potential cyber threats.
The ideal candidate for this role should possess a solid understanding of cybersecurity practices, cloud technologies, detection and response frameworks, and incident handling procedures (containment, eradication, recovery, and lessons learned). They should excel in adhering to and enforcing the use of established incident response playbooks and practices, possess an acute attention to detail, and collaborate effectively across global cross-functional teams.
Required experience:
* Experience working in a security operations or incident response role.
* Advanced proficiency in computer networking concepts, protocols, and network security methodologies.
* Strong expertise in analysing and mitigating cyber threats and vulnerabilities.
* Advanced competence in authentication, authorization, and access control methods.
* Proficiency in utilizing and developing intrusion detection methodologies and techniques for detecting host and network-based intrusions.
* In-depth knowledge of system and application security threats and vulnerabilities, with the ability to develop and implement mitigation strategies.
* Advanced understanding of network attacks, their relationship to threats and vulnerabilities, and the ability to develop countermeasures.
* Proficiency in adversarial tactics, techniques, and procedures, with the ability to anticipate and counteract them.
* Expertise in conducting eDiscovery and forensic investigations, including the collection, preservation, analysis, and presentation of digital evidence in support of incident investigations.
* Comprehensive knowledge of the stages of a cyber-attack and the ability to develop and implement defense strategies at each stage.
* Proficiency with Windows, MacOS, and/or Linux operating systems, with the ability to perform advanced security configurations and troubleshooting.
* Experience in leading and mentoring junior analysts, providing guidance and support to enhance their skills and performance.
* Ability to develop and implement advanced threat detection and response strategies.
* Effective communication skills, with the ability to provide detailed reports and recommendations to senior management.
Responsibilities:
* Continuously monitor and analyse system activity using security operations tools to identify malicious activity.
* Characterize and analyse network traffic and logs to identify potential threats to McDonald’s assets.
* Provide timely detection, identification, and analysis of possible attacks and intrusions, differentiating them from benign activities and reviewing tuning recommendations to improve alert efficacy.
* Collaborate with key stakeholders to validate security events and provide security response expertise to remediate cyber security incidents.
* Perform event correlation to gain situational awareness and assess the effectiveness of observed attacks.
* Conduct security operations and incident response trend analysis and reporting.
* Conduct eDiscovery and Forensic investigations in support of incident investigations.
* Mentor analysts to promote their performance and career growth in alignment with department and organizational objectives.
* Plan and execute protective measures, including policy, processes, and cybersecurity awareness.
* Develop and implement remediation plans in conjunction with incident response requirements.
* Support threat hunting efforts across market networks, identifying indicators of compromise (IOCs) and evidence of compromise.
* Lead and mentor junior analysts, providing guidance and support to enhance their skills and performance.
Desired Skills:
* Professional certification such as GIAC, GCIH, GCIA, ITIL.
* Familiarity with NIST Risk Management Framework and NIST Cybersecurity Framework, Cyber Kill Chain.
* Experience working with case management tools, SOAR, email security solutions, SIEM, and EDR technologies.
* Experience working with complex multinational companies and distributed business models.
* Experience developing automation through scripting languages such as Python.
Education:
* Bachelor’s degree or equivalent experience in Computer Science, Cybersecurity, Information Technology, Software Engineering, Information Systems, or Computer Engineering.
McDonald’s is an equal opportunity employer committed to the diversity of our workforce. We promote an inclusive work environment that creates feel-good moments for everyone.
#J-18808-Ljbffr