Analyst, Cybersecurity Operations
|Published||March 17, 2023|
Why Work for Frontier Airlines?
At Frontier, we believe the skies should be for everyone. We deliver on this promise through our commitment to Low Fares Done Right. This is more than our tagline - it's our driving philosophy. Every member of Team Frontier has an important role to play in bringing this vision to life. Our successful business model allows travelers to take advantage of our fast-growing route network while our bundled and unbundled pricing options allow our customers to personalize their travel experience and only pay for the services they need - saving them money along the way.
What We Stand For
Low Fares Done Right is our mission and we strive to bring it to life every day. Our 'Done Right' promise means delivering not only affordable prices, but making travel friendly and easy for our customers. To do this, we put a great deal of care into every decision and action we take. We must be efficient with the use of our resources and make smart decisions about how we run our business. We must also innovate and be pioneers - we're not afraid to try new things. While our business requires us to fly high in the air, we also consider ourselves down-to-earth in our approach, creating a warm and friendly experience that truly demonstrates Rocky Mountain Hospitality.
At Frontier, we like to think we're creating something very special for our team members. Work is why we're here, but the perks are nice too:
* Flight benefits for you and your family to fly on Frontier Airlines.
* Buddy passes for your friends so they can experience what makes us so great.
* Discounts throughout the travel industry on hotels, car rentals, cruises and vacation packages.
* Discounts on cell phone plans, movie tickets, restaurants, luggage and over 2,000 other vendors.
* Enjoy a 'Dress for your Day' business casual environment.
* Flexible work schedules that support work/life balance.
* Total Rewards program including a competitive base salary, short term incentives, long-term incentives, paid holidays, 401(k) plan, vacation/sick time and medical/dental/vision insurance that begins the 1st of the month following your hire date.
* We play our part to make a difference. The HOPE League, Frontier Airlines' non-profit organization, is dedicated to providing employees financial assistance during catastrophic hardship.
Who We Are
Frontier Airlines is committed to offering 'Low Fares Done Right' to more than 100 destinations and growing in the United States, Canada, Dominican Republic and Mexico on more than 350 daily flights. Headquartered in Denver, Frontier's hard-working aviation professionals pride themselves in delivering the company's signature Low Fares Done Right service to customers. Frontier Airlines is the proud recipient of the Federal Aviation Administration's 2018 Diamond Award for maintenance excellence and was recently named the industry's most fuel-efficient airline by The International Council on Clean Transportation (ICCT) as a result of superior technology and operational efficiencies.
What Will You Be Doing?
The Analyst, Cybersecurity Operations will be part of the Cybersecurity team that analyzes, implements, monitors, troubleshoots, and audits the cybersecurity of the Frontier network infrastructure. The analyst provides timely and comprehensive intelligence on internal/external threats for detection, monitoring, threat hunting, and incident response. The scope of environment includes system-monitoring platforms, anti-virus, DLP, URL filtering, and PCI environments. The analyst will be responsible for performing alert analysis, incident response, digital forensics, and supporting penetration remediation on applications/systems.
* Monitor, investigate, analyze, respond, and report to cyber incidents identified through detection/response platforms.
* Level 1 support in detecting and responding to cybersecurity alerts and incident activity.
* Responsible for engaging and escalating incidents to Level 2 and other Cyber Incident Response Team members.
* Actively drive risk reduction efforts for known cyber security vulnerabilities and known attack traffic patterns/indicators of compromise (IOC).
* Actively monitor security threats and risks, provide in-depth incident analysis, evaluate security incidents, provide proactive threat research, and recommend mitigation strategies.
* Evaluate and determine if/when cybersecurity violations have occurred through examination of network/application logs, open-source research, vulnerability and configuration scan data, and user provided reports.
* Conduct investigations, analysis, and evaluation of projects to determine cybersecurity risk and feasibility as required.
* Administer, maintain, and tune cybersecurity products and services (such as: secure mail gateway, SIEM, IDS/IPS, EDR, vulnerability management, brand monitoring, threat intelligence, security rating, DDoS, web proxy, file integrity monitoring (FIM), data loss prevention (DLP), User Entity & Behavioral Analytics (UEBA)).
* Provide and implement recommendations for new technical controls to help mitigate security vulnerabilities.
* Coordinate and support patch and vulnerability management program functions (report preparation, read-outs, remediation breakouts, ad-hoc requests).
* Provide cybersecurity technical assistance when needed by system/application owners.
* Support multiple day-to-day cybersecurity tasks and projects efforts.
* Provide regular status updates to leadership on projects and remediation efforts.
* Strong understanding of cybersecurity policies and procedures, ability to draft, modify and create standard operating procedures (SOPs) for use of other team members.
* Support organizational Security Awareness Training efforts (suggest training topics, coordinate phishing campaigns, enable awareness to end-users in support of incidents).
* Support vulnerability assessments functions (such as: enterprise pen testing, application pen testing, static/dynamic testing, scorecard assessments).
* Participate and support afterhours/on-call rotation requirements for cybersecurity incidents.
* Develop, monitor, track, and present cyber security metrics.
* Coordinate response and remediation efforts across various departments in a cooperative and beneficial manner.
* Demonstrate ownership and understanding of tasks when engaging with other team members.
* Bachelor's degree in computer science, technology, or equivalent combination of education and relevant experience (required).
* 3+ years of relevant IT/Cybersecurity experience (required).
* 2+ years in security operations with hands-on experience with enterprise cybersecurity products, such as Rapid7, SentinelOne, Proofpoint, Office365, Microsoft Defender for Cloud, Microsoft Defender for Identity (required).
* 2+ years of SIEM (security information and event management) platform experience (required).
* 1+ year supporting adversary tactics and techniques based on MITRE attack framework (required).
* Knowledge of cyber security standards and frameworks such as ISO 27001, NIST CSF, NIST-800-53 (highly desired).
* Hands-on experience with tools like PowerShell, Vulnerability Management, Wireshark, and NMAP (required).
* Industry cybersecurity certification: CompTIA: Security+ or Pentest+, CEH, CISSP, OCSP, SANS: GCIH or GSEC, CISSP, ISACA: CISA or CISM, Security+, SSCP, or CCNA (required, or willing to attain within 3 months of start date).
* Hands-on Cloud infrastructure (Azure/AWS/GCP) cybersecurity remediation experience (desirable).
* Hands-on experience with next-gen endpoint detection/response (EDR), Enterprise Firewall, IPS, Log Management, Cisco, and Checkpoint experience (desirable).
* URL Filtering (web proxy) and troubleshooting experience (desirable).
Knowledge, Skills and Abilities
* Ability to understand and communicate industry trends, maintain awareness of current vulnerabilities and security concerns, and understand their impact on the organization.
* Ability to troubleshoot security/network/system-related issues and manage security components in operating environment.
* Solid understanding of attack vectors, common intrusion techniques, brand intelligence, threat intelligence, application/host/network security hardening, enterprise risk management concepts, and MITRE Attack Framework principles.
* Knowledge of enterprise risk assessment tools, technologies, and methodologies.
* Broad and thorough knowledge of enterprise security systems and devices.
* Knowledgeable in penetration testing, vulnerability assessments, and remediation.
* Designing and implementing cybersecurity controls in an operating environment.
* Able to make accurate work estimates and deliver projects within schedule constraints.
* Proficiency in network traffic analysis and packet analysis.
* Well-organized with the ability to coordinate and prioritize multiple tasks simultaneously with varying deadlines.
* Demonstrate understanding and in-depth knowledge of security threats and applying actionable data to processes and procedures.
* Demonstrate understanding and knowledge correlation analysis, along with an understanding of monitoring programs, such as Splunk and other SIEMs.
* Understanding of the OSI 7-layer model.
* Willing to work more than 40 hours and some weekends as needed.
* Willing to support after-hours and weekend on-call rotation support.
* Strong written and verbal communication skills.
* Ability to remain organized and to elicit cooperation from a wide variety of sources including team members and other internal departments.
* Ability to quickly learn new systems, devices, and methodologies.
* Able to work independently and with a team of peers and other departments.
Laptop endpoint running Windows and a variety of cybersecurity applications and commercial tools.
20% typical office environment, adequately heated and cooled, 80% work from home.
Requires being on-call for after-hours and weekend support.
Light physical effort required by handling objects up to 20 pounds occasionally and/or up to 10 pounds frequently.
General Direction: The incumbent normally receives little instruction on day-to-day work and receives general instructions on new assignments.
$88,000.00 - $110,000.00
At Frontier Airlines, we wholeheartedly support and have a strong commitment to Equal Employment Opportunity (EEO) and Affirmative Action. Frontier is committed to providing equal employment opportunities for all persons regardless of race, color, religion, gender, gender variance, sexual orientation, age, genetic information, martial status, national origin, citizenship status, disability, military, veteran status, and any other basis protected by federal, state, or local laws.
Diversity is an essential part of our success. Our company flourishes because of the unique backgrounds, skills and ideas that our team members contribute every day. We salute and actively recruit veterans. Military experience is valuable and transferable to many of the positions essential to the operations of our airline.
Frontier Airlines is a Zero Tolerance Drug-Free Workplace. All prospective DOT safety-sensitive employees are subject to pre-employment testing for the following drugs and their metabolites: Marijuana, Cocaine, Amphetamines, Opioids and Phencyclidine (PCP). Further, any DOT safety-sensitive job applicant who is found to have tested positive on any required drug or alcohol test at a former employer will be considered ineligible for employment with Frontier.
Disclaimer: The above statements are intended only to describe the general nature and level of work required of the referenced position; they are not intended to be an exhaustive list of all responsibilities, duties, and skills required of individuals in this position. Please be advised that duties and expectations of this position may be subject to change.