Job Summary
Must have:
- Experience in a CSOC, Cyber detection, Threat Hunting and/or SOAR development role.
- Experience developing detections within a SIEM environment (such as Splunk ES).
Nice to have:
- Experience working with Splunk or MS Defender Advanced Hunting.
- Experience working with security tools such as endpoint detection and response systems, network anomaly detection etc…
- Experience working with one or more cloud environments (AWS, Azure, GCP, etc) and awareness of threats impacting them.
- Demonstrated willingness to engage in self-learning or cyber security research outside of standard business hours.
- Designing and implementing threat/attack modelling to derive abuse cases, detection logic and automation course of actions.
- Ability to think like an adversary/threat actor.
- Well versed in the development of detection and hunting strategies for a broad range of cyber threats, including malware, DDOS, hacking, phishing, lateral movement and data exfiltration in the Financial Services sector or similar.
- Working in large/complex environments.
- Good consulting and stakeholder management
- Pro-active & energetic work ethic.
- Participation or experience in penetration testing / red teaming exercises, including network, infrastructure and application exploitation would be a plus.
- Knowledge of the following frameworks:
- NIST Cybersecurity framework
- MITRE ATT&CK
- Lockheed Martin Cyber Kill Chain™ or similar methodologies
Key Responsibilities
2. To conduct comprehensive code reviews, establish and oversee quality assurance processes, performance optimization , implementation of best practices and coding standards to ensure successful delivery of complex projects.
3. To ensure process compliance in the assigned module| and participate in technical discussions/review as a technical consultant for feasibility study (technical alternatives, best packages, supporting architecture best practices, technical risks, breakdown into components, estimations).
4. To collaborate with stakeholders to define project scope, objectives, deliverables and accordingly prepare and submit status reports for minimizing exposure & closure of escalations.