During your tenure as a Senior Consultant/Manager, you will demonstrate and develop your capabilities in the following areas:
• Compile detailed investigation and analysis reports for internal CSOC consumption and delivery to management.
• Analyze network traffic, IDS/IPS/DLP events, packet capture, and FW logs.
• Analyze malicious campaigns and evaluate effectiveness of security technologies.
• Develop advanced queries and alerts to detect adversary actions.
• Lead response and investigation efforts into advanced/targeted attacks
• Identify gaps in IT infrastructure by mimicking an attacker’s behaviours and responses.
• Provide expert analytic investigative support of large scale and complex security incidents.
• Perform Root Cause Analysis of security incidents for further enhancement of alert catalogue.
• Continuously improve processes for use across multiple detection sets for more efficient Security Operations
• Review alerts generated by detection infrastructure for false positive alerts and modify alerts as needed.
Leadership Capabilities:
- Builds own understanding of our purpose and values; explores opportunities for impact.
- Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.
- Understands expectations and demonstrates personal accountability for keeping performance on track.
- Actively focuses on developing effective communication and relationship-building skills.
- Understands how their daily work contributes to the priorities of the team and the business.
Qualifications:
• Incident response and resolution, SIEM platform (SPLUNK), Threat detection and analysis, Scripting (Python, PowerShell)
• Bachelor’s degree in Computer Science, Cybersecurity, or related field
• Total 5-8 years of experience with 3-5 years in a similar role
• Required certifications such as GCIH, CySA+, SANS SEC503, CISSP
• Fluent in English.