Home
/
Comprehensive
/
Security Analyst, Incident Response
Security Analyst, Incident Response-September 2024
Mexico City
Sep 21, 2024
About Security Analyst, Incident Response

  At Lyft, our mission is to improve people’s lives with the world’s best transportation. To do this, we start with our own community by creating an open, inclusive, and diverse organization.

  Lyft connects people to transportation to change the way we live and get around our communities. Lyft’s engineering team is growing rapidly, and we are looking for Security Engineers to help us scale. Come be part of a new team at Lyft focused on enabling and empowering engineering teams to deliver at scale.

  Our drivers and passengers entrust Lyft with their personal information and travel details to get where they're going and expect us to keep that data safe. Lyft's security team leads efforts across the company to ensure our systems are secure and worthy of our users' trust.

  Lyft Security builds systems to protect and defend infrastructure and services from cyber attacks. We consult with teams as they build and launch new products and features, proactively plans for the unexpected, and responds to incidents that occur. Our work has company wide impact and takes place at all levels of the stack, from infrastructure to web application security, as well as mobile apps, IT, bikes, scooters, etc. We believe in scaling security through engineering fundamentals, automation, and tooling. Check out our blog posts at https://eng.lyft.com/tagged/security to learn more about some of the things we’ve built.

  The Incident Response team owns identification, and response of security indents as well as our proactive hypothesis based Threat Hunting program.

  The Security Analyst is part of the detection and response group obsessed with quality of security alerts, feedback loops to respond quickly to incidents, reducing time to detect and executing proactive actions.

  Responsibilities:

  Swiftly Respond to Security Incidents:

  Respond promptly to security incidents by orchestrating coordinated responses across engineering teams and other relevant disciplines.Analyze and Prioritize High-Quality Security Alerts:

  Assess and prioritize security alerts of high quality with the potential to impact the organization, based on SOCLess approachCollaborate with the Detection Engineering Team:

  Work closely with the Detection Engineering Team to identify and implement new security strategies aimed at detecting threats, reducing the attack surface, and enhancing the organization's overall cybersecurity posture.Conduct Proactive Threat Hunting Operations:

  Define and execute proactive threat hunting operations across the organization's systems and services, aiming to uncover detection gaps, identify weaknesses in security controls, and refine existing processes.Assess the Organization's Threat Landscape:

  Evaluate the threat landscape specific to the organization to prioritize proactive security measures and actions.Develop Automation and Tooling:

  Create and maintain automation tools to enhance the efficiency and impact of the incident response team's activities.Cultivate and Maintain Key Partnerships:

  Establish and nurture relationships with critical partners both within the organization and externally to foster collaboration and information sharing.Experience, Knowledge and Skills:

  Cybersecurity Knowledge:

  A deep understanding of cybersecurity principles, including threat landscape, attack vectors, and security best practices

  knowledge of security frameworks, standards, and compliance requirements relevant to your industry (e.g., NIST, ISO 27001). (Nice to have)

  Technical:

  Proficiency in using security tools and technologies such as SIEM (Security Information and Event Management), EDR (Endpoint Detection and Response), and IDS/IPS (Intrusion Detection System/Intrusion Prevention System)

  Strong understanding of operating systems (Windows, Linux, macOS) and their security features.

  Scripting and automation skills, experience with cloud technologies such as AWS/GCP and their tech stack

  Incident Detection and Analysis:

  Experience in monitoring and analyzing security alerts and events generated by security systems.

  The ability to identify and investigate potential security incidents and determine their severity.

  knowledge of structure analysis techniques and decision making as OODA loop.

  Incident Response Experience:

  Hands-on experience with incident response processes, including identification, containment, eradication, and recovery.

  Experience in handling different types of security incidents, such as malware infections, data breaches, insider threats, zero day vulnerabilities, third-party

  Threat Hunting Experience (Nice to have):

  Proven ability to proactively identify and investigate potential threats and vulnerabilities in the organization's environment.

  Familiarity with threat hunting techniques, including TTPs (Tactiques, technique and procedures) analysis, anomaly detection, and behavior analysis.

  Experience in creating and refining threat hunting camping based on hypothesis or cyber threat intelligence.

  Communication Skills:

  Strong communication skills to collaborate effectively with other team members, stakeholders, and management.

  Ability to document incident response and threat hunting activities clearly and concisely.

  The ability to adapt to evolving cybersecurity threats and technologies and stay current with industry trends

  Ability to manage multiple tasks and priorities, and work independently with minimal supervision

  Certifications: Although we are not requiring security certification, the following could be a plus to be considered:

  Certified Incident Handler (GCIH)

  Certified Threat Intelligence Analyst (CTIA)

  CompTIA Security+ Certified SOC Analyst (CSA+)

  vendor-specific certifications

Comments
Welcome to zdrecruit comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
SIMILAR JOBS
Garage Porter
DetailsLocation: Arena DistrictRate: $15.00-$15.45/hrSchedule: Mon.-Fri. 7a-3p FULL-TIMEThe Garage Porter is responsible for ensuring garages and surface lots are maintained and cleaned on a daily ba
Warehouse Cleaners
Overview Position Summary Details The Cleaner position provides the cleaning and upkeep of an assigned area. Pay: $16.25-$17.25 per hour. The pay listed is the hourly range or the hourly rate for thi
Logistic Manager - Afternoon Shift
Job Seekers can review the Job Applicant Privacy Policy by clicking HERE. Summary The Manager Customer Logistics will oversee the day-to-day operations within an assigned function, and is responsible
USPS Careers
The United States Postal Service is actively recruiting for manypositions that may be perfect for you. Whether you are looking for fulltime, part time or seasonal positions, USPS has options availabl
Leisure Travel Agent - Minnesota
It's a great time to join AAA The Auto Club Group! JOIN THE TEAM COMMITTED TO DRIVING YOUR CAREER FORWARD Job Type: Full time Exempt/Non Exempt: Hourly Job Description: Why Choose a Career with the A
Warehouse Associate - 1st Shift
Job Title:              Warehouse Associate Department:         Shipping FLSA Status:       Hourly -- nonexempt     SUMMARY: LogistiQ, a Division of LEWCO is a fast-growing conveyor equipment supplie
India-Bangalore: Senior Developer
As a Senior Developer, you will be responsible for executing, driving, and owning assignments through all stages of the development lifecycle to completion. You will document and map requirements to
Speech Language Pathologist
Speech Language Pathologist Job Ref: 191855 Location: Houston, TX 77000 Category: Speech Language Pathology Line of Business: PDS_Therapy Pay Rate: Up to $120000.00 per hour ApplyRefer a FriendBack B
Pharmacy Technician
Bring your heart to CVS Health. Every one of us at CVS Health shares a single, clear purpose: Bringing our heart to every moment of your health. This purpose guides our commitment to deliver enhanced
Oracle ERP Manager
Oracle ERP Manager Print (https://www.governmentjobs.com/careers/gwinnett/jobs/newprint/4327862) Apply  Oracle ERP Manager Salary $121,592.00 - $175,919.00 Annually Location Gwinnett County, GA Job
Copyright 2023-2024 - www.zdrecruit.com All Rights Reserved