It All Starts with Our People
As the leader in automotive preventive maintenance, Valvoline has a proven track record of growth. We continue to invest in our people, processes, and technology to strengthen our ability to efficiently deliver Quick, Easy, Trusted service across all our stores – every day. We're not just in the car business; we're in the people business. And we're looking for humble, hungry, and smart people to help us shape the future of mobility. If you're hungry to drive change and seek a dynamic, collaborative environment that fuels both personal and professional growth, you've found your place with us.
Our highest priority is creating a welcoming workplace with team members from a wide variety of diverse backgrounds and experiences.
The Opportunity
Valvoline has a rewarding opportunity as a Sr. Incident Response Analyst. In this role, you will work closely with the other members of the Computer Security Incident Response Team (CSIRT) to develop and implement a comprehensive information security program. This role is responsible for a broad range of tasks, including the day-to-day administration of information security tools and devices, as well as first-level and second-level support for security information and event management (SIEM) and may include significant responsibilities for the security administration of a wide variety of IT systems across the enterprise.
How You'll Make a Difference
- Perform third-tier alert queue monitoring. Record and capture alert timelines for accurate reporting.
- Parse event logs generated by endpoint detection and response tools and technologies (anti-virus, data loss prevention, client-based web proxy, firewall, IDS) to detect anomalies and/or abnormalities.
- Proactively seek out new or enhanced data enrichment sources for SOAR to ensure the accurate disposition of alerts.
- Generate new SOAR use case scenarios in response to changing business requirements and evolving threat landscape.
- Maintain familiarity with all Valvoline security policies, procedures, and standards. Investigate and resolve security violations by providing postmortem analysis to illuminate the issues and possible solutions.
- Implement or coordinate remediation required by audits and reviews, and document exceptions as necessary.
- Participate in security investigations and compliance reviews, as requested by internal or external auditors.
- Lead projects that have a CSIRT touchpoint, ensuring project tasks are completed on time and Incident response capabilities are maintained or enhanced.
- Analyze network and firewall logs to identify patterns, anomalies, and security threats.
- Deploy, configure, and maintain IDS/IPS platforms such as Rapid7 or similar tools.
- Review security baselines of all CSIRT tools to ensure critical configuration settings are maintained and operational.
- Write, tune, and maintain custom IDS (and other rules) to enhance detection capabilities in our SIEM platform.
- Lead or support technical response and root cause analysis to security-related events.
- Represent Cyber Security and support IT in Disaster Recovery planning and implementation including tabletops.
- Other duties and responsibilities as determined by Valvoline from time to time in its sole discretion.
What You'll Need to Succeed
- Bachelor's degree in IT, engineering, business, management, or a related field, or equivalent work experience
- Minimum of six years of technology experience, including troubleshooting and performing root cause analysis of complex IT solutions
- Minimum of six years of experience in security incident management processes and tools preferred
- Any of CISSP, CISM, CEH, Security+, Network+, CCNA, CCNP, CCNE, SANS preferred
- Advanced experience with SOAR
- Advanced experience with SEIM (Splunk, Elastic Stack)
- Advanced experience with Endpoint Detection and Response (Forensics, Tools, and Technologies, etc.), Intrusion Detection and Prevention, and Packet Capture and Analysis
- Advanced experience with Email Technologies (Spam Filters, Headers, Phishing, etc.) and Network Technologies (TCIP/IP, Basic Routing, DNS, etc.)
- Advanced experience with Scripting (Python, PowerShell, HTML)
- Advanced experience with Network Sensor administration
- Advanced experience with Identity and Access Management Concepts (SSO, MFA, etc.)
- Advanced experience with Operating Systems (Microsoft Windows and Linux)
- Advanced analytical and problem-solving skills to enable effective security incident and problem resolution
- Advanced team-oriented interpersonal skills, with the ability to interface effectively with a broad range of people and roles, including vendors and IT business personnel
- Experience with NIST preferred
- Experience with Vulnerability Management a plus
- Advanced verbal and written communication skills; ability to work with integrity and maturity on confidential information
- Must be authorized to work in the U.S.
We Take Care of the WHOLE You
- Health insurance plans (medical, dental, vision)
- HSA and flexible spending accounts
- 401(k)
- Incentive opportunity*
- Life insurance
- Short and long-term disability insurance
- Paid vacation and holidays*
- Employee Assistance Program
- Valvoline Instant Oil Change discounts
- Tuition reimbursement*
- Adoption assistance*
*Terms and conditions apply, and benefits may differ depending on position.
Your Path to Valvoline
Valvoline provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
Join us in revolutionizing the automotive aftermarket industry while enjoying competitive benefits, a supportive work culture, and opportunities for advancement. Apply now and become an integral part of our journey at Valvoline.
The Company endeavors to make its recruitment process accessible to any and all users. Reasonable accommodations will be provided upon request to applicants with disabilities to facilitate equal opportunity throughout the recruitment and selection process. Please contact Human Resources at 1.833.VVV.Report or email ECC@valvoline.com to make a request for reasonable accommodation during any aspect of the recruitment and selection process. The contact information is for accommodation requests only; do not use this contact information to inquire about the status of applications.