Interview Type: Skype * Very long term project; initial PO for 1 year, expect to go for 4+ years Hybrid; ;Background check required before you start the project. ***
Job Description:
Under general direction, evaluates the adequacy and effectiveness of internal data controls, business and technical processes, and the performance of the organization's technology platforms to ensure the integrity of the organizations systems and data. Performs security and integrity reviews of the organization's data or IT systems.
Must Have
Minimum 2 years hands on experience in at least one (1) of the following areas:
SOC Analyst
Threat hunting
Detection engineering
Network Security engineering
Experience in client facing environments including active correspondence via email, instant message, voice/video calls with screen sharing
Minimum 2 years experience in active troubleshooting of technical systems including creation of documentation
Strong desire to learn, grow, and stay connected to the changing threat landscape
Ability to discuss the fundamentals of information security in at least THREE (3) of the following areas:
Governance, Risk, and Compliance (GRC)
Cloud and hosted applications
Containerization
Application security
Network security and Zero Trust Architecture (ZTNA/NetSec)
Endpoint security and OS hardening
Security tooling and reporting automation (leveraging PowerShell/Python/Bash etc. to drive data into reports and dashboards)
Malware analysis/forensic system analysis
Incident response and remediation
Penetration testing of Apps, endpoints, or devices
Cyber Threat Intelligence (CTI) including automation of feeds and processing of incoming alerts/vulnerabilities
Vulnerability Management
Data Protection
Nice to Have
ISACA CRISC cert
ISC2 SSCP cert
Hands-on experience with SOAR and other automations
Hands-on experience using common AI models for automation, reporting, or research
Familiar with various NIST frameworks such as CSF 2.0, 800-207, and 800-53
Familiar with MITRE ATT&CK framework
Familiar with OWASP and web application penetration testing
Connections to the larger infosec community