Analyst, Cybersecurity Operations (Detection & Response) L1
* Full-time
* McDonald's Office Location: International Office
As a L1 Response Analyst within the Security Operations Center (SOC), your role primarily involves using defensive measures and information gathered from various sources to identify, analyse, and report cybersecurity events, protecting McDonald's information assets.
You will support the Incident Response process by assisting in crisis situations and responding to immediate and potential cybersecurity threats. This role focuses on security operations, event monitoring, and incident response, demonstrating your strong security skills. The role works directly within Global Cyber Security (GCS), the organization responsible for our Cybersecurity Operations & Incident Response program and critical services, ensuring our leadership makes informed risk-based decisions.
You will collaborate with the Incident Response and Cyber Operations teams, contributing to long-term projects that enhance security. This position offers the opportunity to engage in essential work that safeguards our organization's cybersecurity.
The ideal candidate for this role should possess a foundational understanding of cybersecurity practices, cloud technologies, detection and response frameworks, and incident handling procedures (containment, eradication, recovery, and lessons learned). They should be familiar with adhering to established incident response playbooks and practices, have an attention to detail, and be willing to work collaboratively across global cross-functional teams.
Experience required:
* Basic knowledge of computer networking concepts, protocols, and network security methodologies.
* Entry-level ability to analyse cyber threats and vulnerabilities.
* Awareness of authentication, authorization, and access control methods.
* Basic skills in utilizing intrusion detection methodologies and techniques for detecting host and network-based intrusions.
* Recognition of common system and application security threats and vulnerabilities.
* Understanding of network attacks and their relationship to threats and vulnerabilities.
* Familiarity with common adversarial tactics, techniques, and procedures.
* Basic knowledge of Windows, MacOS, and/or Linux operating systems.
Responsibilities:
* Continuously monitor and analyse system activity using security operations tools to identify malicious activity.
* Characterize and analyse network traffic and logs to identify potential threats to McDonald’s assets.
* Analyse network alerts from various sources within the enterprise to determine their root cause.
* Provide timely detection, identification, and analysis of possible attacks and intrusions, differentiating them from benign activities.
* Collaborate with the Incident Response (IR) team, market stakeholders, and SOC to validate security events and provide tuning input.
* Perform event correlation to gain situational awareness and assess the effectiveness of observed attacks.
* Monitor external data sources to stay informed about cyber defense threat conditions.
* Offer cybersecurity recommendations to leadership based on significant threats and vulnerabilities.
* Collaborate with stakeholders to resolve computer security incidents and ensure vulnerability compliance.
Preferred Qualifications:
* Professional certification such as GSEC, SSCP, Security+, CEH.
* Experience working from Incident Response Playbooks.
* Experience working with case management tools, SOAR, email security solutions, SIEM, and EDR technologies.
* Experience developing automation through scripting languages such as Python.
At McDonald’s, we are committed to creating an inclusive culture that means people can be their best authentic self in our restaurants and offices, which helps us to better serve our customers. We do not tolerate inequality, injustice, or discrimination of any kind.
#J-18808-Ljbffr