You will own the detection engineering and incident response efforts to protect organizational information systems and data.
Responsibilities
Design, build, and fine-tune systems to detect malicious activities, unauthorized behaviors, and suspicious patterns.
Implement automation technologies to streamline vulnerability management, threat detection, and incident response workflows.
Identify, contain, and respond to security incidents while executing corrective action plans to resolve audit findings.
Monitor and audit systems for security violations, vulnerabilities, and abnormalities to maintain control integrity.
Develop and maintain security policies, standards, and alignment with security control frameworks.
Required Skills
10+ years of experience in security operations or related roles.
Working knowledge of security controls including access control, auditing, authentication, encryption, and system integrity.
Proficiency with Linux distributions and Microsoft Windows operating systems.
Hands-on experience with Microsoft Active Directory and TCP/IP networks.
Strong understanding of DNS, network design, and common network protocols.
Experience with network monitoring, next-generation firewalls, and intrusion detection/prevention systems.
Ability to analyze large data sets to identify patterns, anomalies, and malware.
Technical proficiency with Linux, Microsoft Active Directory, TCP/IP Networks, DNS, PowerShell, Python, Bash, ServiceNow, Jira, and Microsoft Defender.
Any Graduate degree.
Preferred Skills
Experience with PCI-DSS, ISO-27001, or SOC II compliance frameworks.
Experience implementing security controls aligned with NIST 800-53 and CIS.
Knowledge of SentinelOne, Tanium, Google Chronicle, Cloudflare, Tenable.io, Recorded Future, or Azure Key Vault.