Enterprise Threat Management and Security Architecture (ETMSA) Engineer
As a key member of the ETMSA team at a fast-growing company, you will play an essential role in safeguarding the organization against cybersecurity threats and incidents. Your responsibilities will revolve around responding to and managing these incidents throughout their lifecycle, from initial identification through to containment, eradication, recovery, and post-incident evaluation. You will collaborate closely with a global team of incident responders to ensure that cybersecurity protocols are effectively implemented.
Your primary focus will be on utilizing your expertise in cyber defense, digital forensics, log analysis, and intrusion analysis to address security incidents across various facets of the organization's infrastructure, including endpoints, networks, and cloud systems. By deploying advanced technologies such as Next-Generation Firewalls (NGFW), Endpoint Detection and Response (EDR), Intrusion Detection/Prevention Systems (IDS/IPS), and Data Loss Prevention (DLP) tools, you will work towards enhancing the overall security posture.
In this role, you will report to the Director and be actively involved in all phases of the incident response lifecycle, including participating in incident prevention projects aimed at bolstering the organization's security defenses. You will collaborate with different stakeholders to ensure regulatory and compliance requirements are met, conduct incident response readiness assessments, and create runbooks and playbooks to streamline incident response processes effectively. Additionally, you will be responsible for detecting, analyzing, containing, eradicating, and recovering from cybersecurity incidents while adhering to local regulatory guidelines.
Post-incident activities will involve leading lessons learned meetings, overseeing follow-up actions, documenting incidents comprehensively, and generating incident reports. The role will require strong technical and analytical skills, hands-on experience in performing incident response activities, and proficiency in using scripting languages such as Bash, PowerShell, Python, etc., to aid incident response across various environments. Familiarity with cybersecurity tools and frameworks like MITRE ATT&CK and Cyber Kill Chain will be essential, along with a passion for exploring new technologies and enhancing team capabilities.
Applicants should possess a minimum of 5 years of experience in the cybersecurity industry, along with security-related certifications as an added advantage. Being a fast learner, a team player, and having a proactive attitude towards learning and problem-solving will be highly valued. Confidence in managing incidents, collaborating with stakeholders, and making critical decisions is crucial, along with a solid understanding of regulatory requirements and compliance standards. Possessing business acumen in addition to technical skills will also be a distinct advantage for this role.
