Enterprise Threat Management and Security Architecture (ETMSA) Engineer
As a team member of the ETMSA team at Crypto.com, you will play a crucial role in responding to and managing cybersecurity threats and incidents across their entire lifecycle, from Preparation to Identification, Containment, Eradication, Recovery, and Lessons Learned. This will involve collaborating with a global team of incident responders.
During your tenure, you will utilize your expertise in cyber defense, digital forensics, log analysis, and intrusion analysis to tackle security incidents across various environments, including endpoints, network, and cloud infrastructure. Your responsibilities will encompass prevention, detection, response, and remediation tasks, with a focus on ensuring the protection of information assets and technologies by leveraging technologies such as Next-Generation Firewalls (NGFW), Endpoint Detection and Response (EDR), and more.
Your role will require effective communication and collaboration skills to work successfully with stakeholders in diverse global settings.
Your Key Responsibilities:
- Reporting directly to the Director to oversee all phases of the incident response lifecycle.
- Participating in various incident prevention projects aimed at enhancing security posture.
Preparation:
- Understanding different regulatory and compliance requirements and participating in self-assessment exercises.
- Developing incident response runbooks, playbooks, and SOPs compliant with regulatory standards.
Detection & Analysis:
- Responding to cybersecurity incidents escalated from various sources.
- Assessing the risk, impact, and scope of identified security threats.
- Conducting in-depth incident analysis from various data sources.
Containment, Eradication and Recovery:
- Communicating with stakeholders, providing guidance for containment and eradication, and participating in root cause analysis.
- Documenting investigative findings and presenting them for critical events.
Post-Incident Activities:
- Leading lessons learned meetings with stakeholders, tracking follow-up activities, and documenting incidents in the case management system.
Requirements:
- Minimum of 5 years of experience in the Cyber Security industry.
- Strong technical and analytical skills with hands-on incident response experience.
- Proficiency in scripting languages like Bash, PowerShell, Python, etc.
- Familiarity with cybersecurity tools and frameworks like NGFW, EDR, IDS/IPS, SIEM, etc.
Preferably:
- A quick learner with a proactive approach and a strong team player.
- Passionate about learning new technologies and enhancing team capabilities.
- Understand the concepts of ownership and accountability, with a mindset for urgency and prioritization.
- Proficient in managing incidents and engaging with stakeholders effectively, along with a business-oriented decision-making approach.
Overall, you should exhibit a keen enthusiasm for cybersecurity, with the ability to adapt and enhance incident response processes effectively.
