Knowledge, Skills and Abilities:
- Foundational Cybersecurity Knowledge - Demonstrates working knowledge of cybersecurity fundamentals, including confidentiality, integrity, and availability (CIA); access control concepts; and defense-in-depth strategies. Recognizes common attack types, tactics, and vulnerabilities, and applies this understanding to alert validation and triage.
- Networking and Operating System Fundamentals - Understands how core network protocols (TCP/IP, DNS, HTTP, etc.) and the OSI model relate to system communications. Utilizes this knowledge to identify abnormal network traffic and system behavior. Operates comfortably in multiple OS environments and interprets basic system and event logs.
- Security Tools and Technologies - Proficiently operates standard SOC monitoring tools such as SIEM, IDS/IPS, and EDR platforms. Collects, reviews, and interprets logs for indications of compromise. Uses vulnerability scanners and antivirus platforms to identify and verify potential risks.
- Cyber Defense and Detection Concepts - Applies detection methodologies to identify and validate anomalies and potential intrusions. Understands signature-based and behavioral detection models, and supports tuning or rule enhancement activities by providing relevant observations.
- Incident Response Awareness - Executes standard triage and response actions during security incidents in accordance with defined playbooks. Documents case findings accurately and escalates as appropriate based on impact and scope.
- Risk and Compliance Fundamentals - Recognizes how risk management and compliance frameworks (ISO, HIPAA, PCI DSS) apply to SOC operations. Identifies and reports deviations from policies or standards and participates in routine evidence gathering.
- Cryptography and Data Protection - Understands core encryption and key management principles, including proper handling of sensitive data. Applies privacy standards when managing logs or data that include PII, PHI, or PCI information.
- Analytical and Problem-Solving Skills - Analyzes event data to determine patterns and relationships between security alerts. Applies logical reasoning and investigative methodology to identify root causes and assist with containment or remediation.
- Communication and Documentation Skills - Produces clear, concise, and accurate documentation within ticketing and reporting systems. Communicates technical findings effectively to peers and supervisors, ensuring continuity of investigations across shifts.
- Professional and Ethical Conduct - Adheres to Avertium and client security policies, confidentiality agreements, and data handling standards. Models responsible cyber hygiene and professional integrity in all actions and communications.
- Continuous Learning and Adaptability - Pursues ongoing development through internal training, certifications, and peer mentorship. Actively incorporates feedback from senior analysts to improve analytical efficiency and technical acumen.
Certifications:
- Required (or be able to obtain): Microsoft SC200, Sentinel 1 SIREN
- Desirable: Microsoft AZ500
- Example additional considerations or equivalents such as (not all inclusive): A+/Network+, CCT, DFE, CSA, GISF, ECSS
Skills Required
- Foundational knowledge of cybersecurity fundamentals, including confidentiality, integrity, availability, access control, defense in depth, attacks, tactics, and vulnerabilities
- Understanding of networking protocols including TCP/IP, DNS, HTTP, and the OSI model
- Ability to operate across multiple operating system environments and interpret system and event logs
- Proficiency with SIEM, IDS/IPS, and EDR platforms
- Experience or ability to use vulnerability scanners and antivirus platforms
- Understanding of security detection methodologies, including signature-based and behavioral detection
- Ability to execute incident triage and response actions using established playbooks
- Knowledge of risk and compliance frameworks including ISO, HIPAA, and PCI DSS
- Understanding of encryption and key management principles and privacy requirements for PII, PHI, and PCI data
- Clear technical communication and accurate security documentation skills
- Microsoft SC-200 certification or ability to obtain it
- Sentinel 1 SIREN certification or ability to obtain it
- Microsoft AZ-500 certification
- Additional certifications such as A+, Network+, CCT, DFE, CSA, GISF, or ECSS
What We Do
Avertium is the security partner that companies turn to for end-to-end cybersecurity solutions that attack the chaos of the cybersecurity landscape with context. By fusing together human expertise and a business-first mindset with the right combination of technology and threat intelligence, Avertium delivers a more comprehensive, more programmatic approach to cybersecurity – one that drives action on the ground and influence in the boardroom. That’s why over 1,200 mid-market and enterprise-level organizations across 15 industries turn to Avertium when they want to be more efficient, more effective, and more resilient when waging today’s cyber war. Show No Weakness® Avertium will focus its comprehensive expertise on supporting mid-to-large enterprises, making it one of the largest managed cybersecurity services companies focused on this market. Avertium is led by Jeff Schmidt, a security industry veteran, who has previously held executive leadership roles at a variety of successful technology and security companies, including International Network Services, All Covered, BT Counterpane, SQS, and Authomate. For more information and career opportunities, visit https://www.avertium.com/.








