CSIRT運用支援(セキュリティ運用・インシデント対応) at Nexus Corporation | JP | Rezi

CSIRT運用支援(セキュリティ運用・インシデント対応) at Nexus Corporation

CSIRT運用支援(セキュリティ運用・インシデント対応)

Nexus Corporation · JP

1 weeks ago

CSIRT運用支援(セキュリティ運用・インシデント対応)

Nexus Corporation · JP

9 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this CSIRT運用支援(セキュリティ運用・インシデント対応) role.

Rezi rewrites your resume against Nexus Corporation's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the CSIRT運用支援(セキュリティ運用・インシデント対応) posting at Nexus Corporation — free, in seconds.

About the Role

We are seeking a CSIRT Operations member to join our client's team. This role involves primary alert response, log investigation, and comprehensive incident management.

Responsibilities

  • Primary alert response and log investigation (AV/EDR/Server OS Antivirus/Mail Security/FW/Proxy, etc.)
  • End-to-end incident response including detection analysis, impact assessment, containment, and remediation planning
  • Creation of reports and incident tickets
  • Direct communication with client representatives and user departments, including complaint handling
  • Utilize VDI environment (connection from own PC: CyST)

Requirements

  • Minimum 2 years of practical experience in SOC/CSIRT/Security Operations and Maintenance
  • Experience in primary alert response and log investigation
  • Basic knowledge of Windows clients/servers (processes, services, event logs, permissions, patch application, etc.)
  • Basic network knowledge (TCP/IP, DNS, HTTP(S), Proxy, IP addresses/FQDNs/Ports)
  • Basic knowledge of Azure AD/M365 and fundamental vulnerability concepts (CVE, CVSS, etc.)
  • Experience operating EDR products (alert analysis, isolation/blocking, hunting query execution, etc.)
  • Experience operating mail security products or M365 Defender/EOP (suspicious email analysis, quarantine checks, phishing response)
  • Experience operating Web Proxy/Cloud Proxy (Zscaler, etc.)
  • Experience using ticketing and incident management tools (JIRA, ServiceNow, etc.)
  • Experience reading public vulnerability information (JVN, NVD, vendor advisories, etc.) and organizing response strategies
  • Japanese document creation skills (monthly reports, incident reports, warning emails, etc.)
  • Ability to explain complex technical information clearly to non-technical audiences
  • Ability to share information within the team and handle handovers

Skills

  • SOC/CSIRT/Security Operations and Maintenance
  • Alert response
  • Log investigation
  • Windows client/server
  • TCP/IP
  • DNS
  • HTTP(S)
  • Proxy
  • Azure AD
  • M365
  • Vulnerability concepts (CVE, CVSS)
  • EDR products
  • Mail security products
  • M365 Defender/EOP
  • Web Proxy/Cloud Proxy (Zscaler)
  • Ticketing/Incident management tools (JIRA, ServiceNow)
  • Vulnerability information analysis
  • Japanese technical writing
  • Clear communication
  • Team collaboration
  • Dark web monitoring/account breach detection services (SOCRadar)
  • Microsoft Defender suite
  • Threat hunting
  • Azure/M365 security configuration review
  • Log analysis (Excel/Power BI)
  • Security certifications (Information Security Assurance Specialist, CISSP, GCIH, GCFA)

Location

  • Onsite

Work Type

  • Full-time

Experience Level

  • 2+ years

Education Level

  • Security certifications (Information Security Assurance Specialist, CISSP, GCIH, GCFA)