Senior Cyber Event Analyst

  • Full-time
  • Business Segment: Operations & Technology
  • Compensation: USD 95000 - USD 120000 - yearly

Company Description

NBCUniversal is one of the world's leading media and entertainment companies. We create world-class content, which we distribute across our portfolio of film, television, and streaming, and bring to life through our theme parks and consumer experiences. We own and operate leading entertainment and news brands, including NBC, NBC News, MSNBC, CNBC, NBC Sports, Telemundo, NBC Local Stations, Bravo, USA Network, and Peacock, our premium ad-supported streaming service. We produce and distribute premier filmed entertainment and programming through Universal Filmed Entertainment Group and Universal Studio Group, and have world-renowned theme parks and attractions through Universal Destinations & Experiences. NBCUniversal is a subsidiary of Comcast Corporation.

Our impact is rooted in improving the communities where our employees, customers, and audiences live and work. We have a rich tradition of giving back and ensuring our employees have the opportunity to serve their communities. We champion an inclusive culture and strive to attract and develop a talented workforce to create and deliver a wide range of content reflecting our world.

Comcast NBCUniversal has announced its intent to create a new publicly traded company ('Versant') comprised of most of NBCUniversal's cable television networks, including USA Network, CNBC, MSNBC, Oxygen, E!, SYFY and Golf Channel along with complementary digital assets Fandango, Rotten Tomatoes, GolfNow, GolfPass, and SportsEngine. The well-capitalized company will have significant scale as a pure-play set of assets anchored by leading news, sports and entertainment content. The spin-off is expected to be completed during 2025.

Job Description

NBCUniversal’s Cyber Defense Operations team is responsible for providing cyber threat intelligence, event analysis, incident response and threat hunting for all areas of NBCUniversal in a highly collaborative, fast paced, and agile fashion.  As a member of the Cyber Response team, a candidate can expect to utilize their technical expertise to assess, contain, and remediate cyber threats.  The Senior Cyber Event Analyst is responsible for analysis, escalation and initial response actions of security events and alerts to incidents.

The ideal candidate would have a working knowledge of current and relevant security technologies and how to apply them to cyber event analysis and response actions.  A clear investigative methodology with a focus on preserving evidence and analyzing data to form conclusions that will steer response directions.  Experience analyzing and responding to security events and incidents with practical and working knowledge of response analysis methodologies and enhancing security response processes. In addition, the candidate must be willing and available to work any shift including overnight shifts, weekends, and holidays to meet the needs of a 24x7/365 operation, with possibility of schedule changes based on business needs and priorities.

The role involves regular interaction with various groups and leadership within the organization in order to accomplish job responsibilities. Working under the direction of the Manager, Cyber Response, the successful candidate will be responsible for participating in the following activities:

  • Triage, scope, and disposition all security alerts or operational requests across multiple technology platforms (Cloud, Hosts, Networks, Applications, Email) to identify threats needing to be escalated to Incident Response and the Business
  • Day-to-day operational tasks related to the ongoing support of Cyber Operations.
  • Responsible for documenting evidence throughout the incident life cycle, conducting shift handovers, escalating security events to incident response, and providing support during cyber security incidents.
  • Responsible for the ticket queue triage: prioritization, assignment and disposition of security incident tickets/events.
  • Responsible for analyzing threat data from multiple sources and building evidence backed dispositions. 
  • Responsible for front line triage and response including some containment and remediation actions such as network isolation of hosts and blocking indicators of compromise within security perimeter tools.
  • Analyst must keep detailed reports on all analysis activity, documented in the case management tool to validate process adherence.
  • Responsible for contributing to the creation and updating of new and existing SOAR playbooks and runbooks and general response documentation.
  • Identify operational gaps in security processes, provide ideas for solutions and take ownership for implementation.
  • Peer review of tickets for fellow Cyber Event Analysts that request one.
  • Managing the Cyber hotline during their shift.
  • Act as a mentor to any Cyber Event Analysts and Intern’s that may be part of our team.
  • Act as a SME for our team for our documented policies, processes and procedures.
  • Identifying areas of educational/knowledge improvements including taking ownership of appropriate documentation and communication to the team.

Qualifications

  • Bachelor’s Degree or above in an IT related field, Cyber Security relevant active certifications, and/or equivalent work experience
  • Minimum 4 years working in Cyber Defense field with experience in Incident Response, Security Analysis or Security Operations Center (SOC)
  • Hands-on experiences
    • supporting SOC/incident response functions,
    • in analyzing cybersecurity events, and incidents (malware, public cloud services, network/host intrusion, phishing, etc.),
    • utilizing centralized logging platforms to perform log investigations,
    • utilizing industry security tools/technologies to support cyber event analysis (EDR, public cloud services, WAF, e-mail security gateway, firewalls, etc.),
    • host-based/network-based forensic tools and analysis,
    • utilizing OSINT to support analysis,
    • pulling artifacts from an endpoint (where applicable) to support a cyber investigation,
    • with Cloud infrastructures as it relates to Cyber Security events/alerts (AWS, GCP, and/or Azure),
  • Strong knowledge within the following areas
    • documenting and correlation of events associated the logs, OSINT sources, and/or artifacts reviewed to support the story telling for the cybersecurity event,
    • cyber threat landscape to include different types of adversaries, campaigns, and the motivations that drive them,
    • industry recognized security and analysis frameworks (Mitre ATT&CK, Kill Chain, Diamond Model, NIST Incident Response, etc.),
    • understanding of when and how to escalate to direct management and/or on-call team member,
    • scoping above and beyond what is presented to them within a cyber alerts/event or user reported item
  • Working knowledge of core Enterprise IT concepts (web application architectures, networking, operating systems, etc.)
  • Strong communication (both verbal and written)
  • Must be self-motivated and able to work both independently and as part of a team
  • Ability to be on call and provide support during nontraditional working hours
  • Well organized and ability to prioritize workload with minimal oversight
  • Detail oriented
  • Acting as a mentor to non-senior level Cyber Event Analysts and Interns

Desired Characteristics: 

  • Scripting experience (i.e., Python)
  • Previous experience providing incident response/SOC support for Fortune 1000 companies or the Media and Entertainment industry
  • Demonstrated experience working with network tools and technologies such as firewall, proxies, IPS/IDS devices, full packet capture (FPC), and email platforms
  • Relevant certifications (GCIA, GCIH, GCFA, GNFA, etc.)

Additional Requirements:

  • Fully Remote: This position has been designated as fully remote, meaning that the position is expected to contribute from a non-NBCUniversal worksite, most commonly an employee’s residence.
  • Must be willing and available to work any shift including overnight shifts, weekends, and holidays to meet the needs of a 24x7/365 operation, with possibility of schedule changes based on business needs and priorities.

This position is eligible for company sponsored benefits, including medical, dental and vision insurance, 401(k), paid leave, tuition reimbursement, and a variety of other discounts and perks. Learn more about the benefits offered by NBCUniversal by visiting the Benefits page of the Careers website. Salary range: $95,000 - $120,000

 

Additional Information

As part of our selection process, external candidates may be required to attend an in-person interview with an NBCUniversal employee at one of our locations prior to a hiring decision. NBCUniversal's policy is to provide equal employment opportunities to all applicants and employees without regard to race, color, religion, creed, gender, gender identity or expression, age, national origin or ancestry, citizenship, disability, sexual orientation, marital status, pregnancy, veteran status, membership in the uniformed services, genetic information, or any other basis protected by applicable law. 

If you are a qualified individual with a disability or a disabled veteran, you have the right to request a reasonable accommodation if you are unable or limited in your ability to use or access nbcunicareers.com as a result of your disability. You can request reasonable accommodations by emailing [email protected].

For LA County and City Residents Only:  NBCUniversal will consider for employment  qualified applicants with criminal histories, or arrest or conviction records, in a manner  consistent with relevant legal requirements, including the City of Los Angeles' Fair Chance Initiative For Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, where applicable.

Privacy Policy