Security Analyst, Incident Response
Mylan Inc.
Viatris is a global healthcare company uniquely positioned to bridge the traditional divide between generics and brands, combining the best of both to more holistically address healthcare needs globally. With a mission to empower people worldwide to live healthier at every stage of life, we provide access at scale, currently supplying high-quality medicines to approximately 1 billion patients around the world annually and touching all of life's moments, from birth to the end of life, acute conditions to chronic diseases.
We have been included on number of award lists that demonstrate the impact we are making.
Every day, we rise to the challenge to make a difference and here’s how the Security Analyst, Incident Response role will make an impact:
Key responsibilities for this role include
•
Perform analysis of log files from a variety of sources (e.g., individual host logs, network traffic logs, security system logs, and intrusion detection system [IDS] logs, Endpoint Detection and Response systems, and SIEM logs) to identify threats to security.
•
Utilize incident handling methodologies and frameworks (e.g. (VERIS, MITRE, NIST, ISF)).
•
Coordinate and provide expert technical support and guidance to enterprise-wide cyber security partners to resolve cyber incidents and implement best practices.
•
Coordinate with enterprise-wide cyber defense staff to review escalated incidents.
•
Assess the effectiveness of security controls for services, applications, and associated processes.
•
Identify, capture, contain, and report on malware.
•
Analyze and review anomalous code as malicious or benign.
•
Isolate, analyze, and remove malware.
•
Design countermeasures for known and intelligence driven identified security risks and threat actors.
•
Collect, process, package, transport, and store electronic evidence to avoid alteration, loss, physical damage, or destruction of data during security incidents.
•
Review logs to identify evidence of past intrusions.
•
Characterize and analyze logs, alerts, analytics, network traffic, reports, events, trends, threat tactics, business and event triggers, to identify anomalous activity and potential threats.
•
Confirm what is known about an intrusion and discover new information, if possible, after identifying intrusion via dynamic analysis.
•
Create a forensically sound duplicate of the evidence (i.e., forensic image) that ensures the original evidence is intentionally modified, to use for data recovery and analysis processes. This includes, but is not limited to, hard drives, floppy diskettes, CDs, PDAs, mobile phones, GPS, and all tape formats.
•
Provide technical and non-technical summary of incident findings in accordance with established incident response plan.
•
Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack.
•
Monitor...