- 2 - 5 years of experience in security incident response and technical forensics investigation
- 2 - 5 years of experience in a Senior Defender administrator role, including policy design and optimization, and ensuring agent version currency
- 2 - 5 years of experience in IT Network or Cyber Operations
- Incident handling and forensics skills including knowledge of common probing and attack methods, network/service discovery, system assessment, viruses and other forms of malware.
- Ability to monitor and analyze SIEM, endpoint, network (Firewall,IPS), and application logs
- Extensive documentation skills with Excel, PowerPoint and ticketing systems
- Ability to prepare reports of analysis and results to provide briefings to management
- Skills in performing and optimizing operational processes
- Technical expertise in supporting up-to-date and cutting-edge security technologies
Preferred
Bachelor s degree in information security, Computer Science or equivalent
Information Security Certifications such as CISSP, CRISC, and/or CISM
Experience interfacing with other internal or external organizations regarding failure and incident response situations
Knowledgeable and experienced in:
- SIEM (Exabeam) or other UEBA platform
- IDS/IPS (Cisco/Sourcefire/Palo)
- EDR (CrowdStrike)
- CyberArk
- IRT Coordination
- SOC/MSS
- Daily Threat Dashboard Reporting
- MITRE Framework implementation and auditing
- Scripting and automation experience