The CSOC Security Engineer is a key member of the 24x7 Cyber Security Operations Center; monitoring and responding to real-time alerts and incidents in order to contain and mitigate risk to T-Mobile's systems, services and information assets. This is a high profile, fast-paced role that interfaces across the entire company and at all levels of the organization.
Responsibilities
The role of a CSOC Security Engineer is the detailed and repeatable execution of all operational tasks as documented in processes and subordinate procedures, specifically:
- Monitor incoming event queues for potential security incidents per operational procedures
- Perform triage, analysis, and response of security alerts to determine and initiate appropriate courses of action, with escalation as defined by established procedures
- Collect and organize alert, event and triage data to produce reports to provide feedback to existing content, inform new content, and measure relevant KPIs
- Provide support for and collaboration with higher-tier support teams to investigate escalated incidents
- Assist in the development of new security operations processes as well as the refinement or improvement of existing processes
- Monitor CSOC ticket (or email) queue for potential event reporting from outside entities and individual users
- Maintain CSOC shift logs with relevant activity from current shift.
- Document investigation case notes, ensuring relevant details are passed to CIRT for escalated incident analysis
- Update or reference CSOC knowledge management repository as necessary for changes to CSOC processes and procedures and ingest CSOC daily intelligence reports and previous shift pass downs
- Conduct security research and intelligence gathering on emerging threats and exploits
Qualifications Minimum Required
- US Citizenship required
- 2-4 years of experience working in a large enterprise
- 2-4 years of experience as a SOC or Incident Response investigator or equivalent work experience
- Conversant with cyber security intrusion analysis concepts and techniques
- Understanding of security incident investigation and log analysis
- Experience investigating security incidents, threats and vulnerabilities
- Demonstrable knowledge of networking (TCP/IP, topology, OSI model and network forensics), operating systems (Windows/MacOS/Linux), and web technologies (web applications, database security, web servers)
- Knowledge of federal & compliance regulations e.g. SOX, PCI & CPNI
- Knowledge of Scripting tools (Python/Perl/Shell/HTML/PHP)
- Ability to read and understand system data, including, but not limited to, security event logs, system logs, and firewall logs
- High degree of attention to detail
- Presentation skills to large and small audiences
- Strong verbal and written communication skills
Desired
- Experience supporting Cyber Security Operations in a large enterprise environment
- Experience with SIEM & Log Management solutions
- Experience with cloud security, telecom security, data protection
- Experience with enterprise systems or network administration
- CCNA Security, GCIA, GCIH or other related security certifications
Minimum Required Education
- Degree in Computer Science, Information Technology, or equivalent work experience
- In lieu of a degree, 6+ years of related experience may be considered
- Course work in Cyber Security is strongly preferred
General/Physical Requirements
- Must sit for extended periods of time. Extensive computer and telephone utilization.
- Shift work in a 24x7 Cyber Security Operations Center
- Participation in on-call rotation may be required
"Digital Security"
Company Profile As America's Un-carrier, T-Mobile USA, Inc. (NASDAQ: "TMUS") is redefining the way consumers and businesses buy wireless services through leading product and service innovation. The company's advanced nationwide 4G and 4G LTE network delivers outstanding wireless experiences for customers who are unwilling to compromise on quality and value. Based in Bellevue, Washington, T-Mobile USA. Inc. provides services through its subsidiaries and operates its flagship brands, T-Mobile and Metro by T-Mobile. For more information, please visit
http://www.t-mobile.comEOE Statement We Take Equal Opportunity Seriously - By Choice. T-Mobile USA, Inc. is an Equal Opportunity Employer. All decisions concerning the employment relationship will be made without regard to age, race, ethnicity, color, religion, creed, sex, sexual orientation, gender identity or expression, national origin, marital status, citizenship status, veteran status, the presence of any physical or mental disability, or any other status or characteristic protected by federal, state, or local law. Discrimination or harassment based upon any of these factors is wholly inconsistent with our Company values and will not be tolerated. Furthermore, such discrimination or harassment may violate federal, state, or local law.