Just curious how realistic it is for someone to cross fields into a role like this?
The reason I ask, I see these positions pop up at my current place of employment but always gun shy to apply. It's either a total hit or a miss in regards to the bullets. Worst case we all get a good laugh!
RESPONSIBILITIES
- Analysis of security logs including data acquisition, data cleaning, and creating security alerts based on data I perform a lot of data cleaning, analysis, aquisition etc.... Nothing in the security space though
- Scripting, customization, and light application development within SIEMs (Splunk, etc.) No Clue
- Behavioral Analytics and search/query design involving very large security datasets Mine large sets of data for finance and supply chain. Nothing really in the behavioral realm
- Organization and manipulation of medium to very large data sets Oh yeah this is in my wheelhouse (Home run)
- Create written reports, dashboards, and visualizations Absolutely, I do this all the time it's 50% of my position.
- Analyze data for trends, statistical patterns, and intelligence See above***
- Develop security use-cases for Insider Threat activity and malware behavior No clue
- Incident and alert response No clue
EXPERIENCE/SKILLS
- Experience interpreting security logs and related datasets No
- Strong analytical skills Yes
- Windows events, endpoint processes, *NIX event logs Not really
- Knowledge of network design, security tools, and TCP/IP protocols Not really
- Excellent oral and written communication skills Yes
- Ability to excel in a team environment; self-starter Yes
- Strong ability to work without direction towards a desired outcome Yes
- Programming/Scripting – Python and XML preferred; R a plus XML and R ~2 years (PS R is pretty easy)
- Experience with APIs and moving data between databases and applications Yes
- SQL and SQL Databases YES
- Advanced Excel; Microsoft Office, Powerpoint, etc. YES
- Experience with Splunk (preferred) or other SIEM-type platform No Clue
- Must work well under pressure, multi-task, be dependable and accountable YES
I'm just curious what it would take for people from different spaces to transition? Thanks for any insights....