Enterprise Threat Management and Security Architecture (ETMSA) Engineer
As a vital member of the ETMSA team at a leading organization, you will play a key role in handling cybersecurity threats and incidents from start to finish. This includes activities such as Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned. You will collaborate closely with a global team of incident responders.
Your role will involve utilizing your expertise in cyber defense, digital forensics, log analysis, and intrusion analysis to address security incidents across various areas such as endpoints, network, and cloud infrastructure. Your responsibilities will encompass prevention, detection, response, and remediation activities by leveraging advanced technologies like Next-Generation Firewalls (NGFW), Endpoint Detection and Response (EDR), and Data Loss Prevention (DLP), among others.
Additionally, you will need to demonstrate strong collaboration and communication skills to effectively engage with diverse stakeholders in multicultural and global settings.
Key Responsibilities
- Collaborate with the Director to facilitate the incident response lifecycle
- Participate in incident prevention projects to enhance security posture
Preparation
- Familiarize with regulatory and compliance requirements
- Engage in self-assessment exercises to ensure the efficacy of incident response processes
- Develop incident response runbooks and standard operating procedures in alignment with regulatory mandates
- Assess the readiness of different layers concerning people, processes, and technology
Detection & Analysis
- Respond to escalated cybersecurity incidents from various channels, including the 24/7 SOC team
- Address incidents in compliance with local regulatory requirements
- Assess the risk, impact, and scope of identified security threats
- Conduct in-depth incident analysis by reviewing security-related logs against threats and IOCs
Containment, Eradication, and Recovery
- Communicate with stakeholders to provide guidance on containing and eradicating security incidents
- Engage in root cause analysis using forensic tools to identify sources of compromise
- Document and present investigative findings for notable events and incidents
Post-Incident Activities
- Facilitate lessons learned meetings for stakeholders
- Lead follow-up activities and document incidents in the case management system
- Provide incident reports as needed
Requirements
- Minimum of 5 years' experience in the Cyber Security industry
- Strong technical and analytical skills
- Knowledge of cyber security incident response processes
- Hands-on experience in incident response activities
- Proficiency in scripting languages like Bash, PowerShell, Python, etc.
- Familiarity with cybersecurity tools and software such as NGFW, EDR, IDS/IPS, SIEM, etc.
- Understanding of frameworks like MITRE ATT&CK and Cyber Kill Chain
- Enthusiasm for exploring new technologies and enhancing team capabilities
- Additional certifications in security-related areas are advantageous
- Awareness of regulatory and compliance requirements is a plus
Preferred Qualifications
- Eager to learn and proactive in taking on challenges
- Strong team player with excellent collaboration skills
- Willingness to go the extra mile and dedicated to continuous learning
- Demonstrated accountability, decisiveness, and urgency in incident management
- Ability to handle incidents and engage with senior stakeholders effectively
- Business acumen in addition to technical skills for making critical decisions
