At SAP, we enable you to bring out your best. Our company culture is focused on collaboration and a shared passion to help the world run better. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and future-focused work. We offer a highly collaborative, caring team environment with a strong focus on learning and development, recognition for your individual contributions, and a variety of benefit options for you to choose from.
Incident Response Analyst – Cyber Fusion Center – Newtown Square, PA An SAP Incident Response Analyst is a crucial front-line defender, leader of SAP's digital enterprise. Our Incident Handlers are responsible for triaging critical security events detected by security monitoring operations, analyzing all available data to determine if a cyber-attack is occurring, scoping the extent of a suspected attack, coordinating efforts to contain attacks, and conducting forensic investigation to determine the details around the attack.
The Role Our incident handlers are responsible for triaging security alerts detected by Enterprise Detection and SIEM, analyzing all available data to determine if a cyber-attack is occurring, scoping the extent of a suspected attack, coordinating efforts to contain attacks, performing forensic investigations to determine the details around an attack, and providing guidance on remediation actions.
In this role, respond to alerts, perform root cause analysis, develop attack remediation strategies, and ensure the communication and handle escalations of security activities. You will also assist in the development of incident handling processes, standard operating procedures, playbooks and runbooks. Through developing workflow automation, you will lower response times.
You will work with Security Engineering teams to make improvements to detection and alerting mechanisms and conduct forensic investigations to determine incident details and provide supporting evidence.
Role Requirements You should have extensive demonstrated experience in cyber-attack investigations and of working in a similar 24/7 environments managing cases with enterprise SIEM or Incident Management systems.
We are looking for analytical, critical thinkers, who have an eye for detail and are solution orientated. You should be quick to learn and adapt and operate in a dynamic environment.
You will also need to have the following technical skills and experience:
Ability to possess and maintain a U.S. Government/DoD Clearance.Security certification (e.g. Security+, GCIA, GCIH, CISSP)Knowledge of APT actors; their tools, techniques, and procedures (TTPs)Knowledge of TTP methods and frameworksKnowledge of TCP/IP communications & knowledge of how common protocols and applications work at the network level, including DNS, HTTP, and SMBKnowledge of one or moreWindows/AD file system, registry functions and memory artifactsUnix/Linux file systems and memory artifactsMac file systems and memory artifactsDatabase, web application, cloud, or mobile device cyber incident response principals and techniquesCybersecurity automationWeb servers and web applications.SIEM (Splunk)Security tools: IPS, Web proxy, Email proxy, pDNS, Deception, EDR etc....Experience with one or more scripting languages (Powershell, Python, Bash, etc.)Experience with integration of threat hunting and cyber threat intelligence into the incident response processExperience with information security compliance audit frameworks and requirements e.g. PCI, FISMA, FedRAMP, SOC, SOX, PCI, GDPR and Data PrivacyBring out your best SAP innovations help more than four hundred thousand customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ERP) software, SAP has evolved to become a market leader in end-to-end business application software and related services for database, analytics, intelligent technologies, and experience management.
We win with inclusion SAP's culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone – regardless of background – feels included and can run at their best. SAP is proud to be an equal opportunity workplace and is an affirmative action employer.
EOE AA M/F/Vet/Disability Qualified applicants will receive consideration for employment without regard to their age, race, religion, national origin, ethnicity, age, gender (including pregnancy, childbirth, et al), sexual orientation, gender identity or expression, protected veteran status, or disability.
Compensation Range Transparency: SAP believes the value of pay transparency contributes towards an honest and supportive culture and is a significant step toward demonstrating SAP's commitment to pay equity. The targeted combined range for this position is ******** (USD) USD.
Requisition ID: 410188 | Work Area: Information Technology | Expected Travel: 0 - 10% | Career Status: Professional | Employment Type: Regular Full Time | Additional Locations: #LI-Hybrid
#J-18808-Ljbffr