Position Summary
At JetBlue, cyber security operates across a complex IT environment, encompassing traditional data centers, Software as a Service (SaaS) services, multiple cloud providers, and a diverse end-user environment. We are committed to providing robust security for our extensive corporate network and our e-commerce platforms.
We are seeking an entry-level Incident Responder to support our Incident Response (IR) team in managing and investigating alerts escalated from our Tier 1 Security Monitoring team. The ideal candidate will possess a good working understanding of both traditional network and e-commerce-oriented security threats, and be comfortable conducting Response activities in a hybrid environment with an extensive set of log sources and tools.
Essential Responsibilities
- Monitor and analyze network traffic, system logs, and escalated alerts from security tools including firewalls, endpoints and IDS/IPS to detect signs of suspicious or malicious activity.
- Analyze telemetry from various sources, including network devices, user endpoints, Content Delivery Networks (CDNs), mail security tools, and traditional and Web Application Firewalls (WAFs) to identify malicious activity.
- Assist in the investigation and resolution of security incidents, including malware infections, phishing attacks, and unauthorized access.
- Participate in coordinated daily operations via constant interactions with Threat Intelligence, Detection Engineering and Security Monitoring teams.
- Author custom dashboards and content across various security tools, e.g. SIEM.
- Ensure playbooks, case management and process documentation stay current.
- Maintain detailed documentation of security incidents including timelines, findings, and remediation steps; track post-incident action items and keep metrics on completion.
- Work with other crewmembers and automation tools to improve timely and efficient handling of security Incidents and investigations.
- Other duties as assigned.