Enterprise Threat Management and Security Architecture (ETMSA) Engineer
As a valuable team member of the ETMSA department at a leading crypto company, you will play a crucial role in responding to and managing cybersecurity threats and incidents from start to finish. This includes Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned, collaborating with incident responders globally. Your expertise in cyber defense, digital forensics, log analysis, and intrusion analysis will be key in addressing security incidents across various platforms such as endpoints, network, and cloud infrastructure. Your responsibilities will encompass prevention, detection, response, and remediation efforts, ensuring the protection of information assets by utilizing technologies like NGFW, EDR, IDS/IPS, DLP, among others.
Furthermore, you will utilize your strong communication and collaboration skills to effectively engage with diverse stakeholders in multicultural and global settings.
Responsibilities
- Report to the Director to facilitate all stages of the incident response lifecycle.
- Engage in different incident prevention projects for enhancing security measures.
- Prepare by understanding regulatory and compliance requirements and conducting self-assessment exercises.
- Develop incident response runbooks, playbooks, and SOPs aligned with regulatory standards.
- Evaluate the readiness of different layers in incident response - people, process, and technology.
- Detect and analyze cybersecurity incidents escalated from various sources, complying with regulatory guidelines.
- Assess risks, impacts, and scopes of identified security threats.
- Conduct detailed incident analysis to investigate security-related logs against emerging threats and IOCs.
- Contain, eradicate, and recover by providing guidance, recommendations, and participating in root cause analysis.
- Document investigative findings and share reports for significant events and incidents of interest.
- Conduct post-incident activities including lessons learned sessions, follow-up actions, and incident documentation.
Always remain prepared to assist during security incidents.
Requirements
- Minimum of 5 years of experience in the Cyber Security field.
- Strong technical and analytical abilities.
- Knowledge of cyber security incident response processes and familiarity with AI tools for automating security tasks.
- Hands-on experience in performing incident response activities.
- Proficiency in scripting languages like Bash, PowerShell, Python, Go for responding to incidents in diverse environments.
- Familiarity with cybersecurity tools such as NGFW, EDR, IDS/IPS, etc.
- Understanding of frameworks like MITRE ATT&CK or Cyber Kill Chain.
- Enthusiasm for exploring new technologies and enhancing team capabilities.
- Preferably possess security-related certifications.
- Familiarity with regulatory and compliance requirements is advantageous.
Preferably
- Quick learner with a can-do attitude.
- Strong team player with collaboration skills.
- Eagerness to learn and go the extra mile.
- Demonstrated sense of ownership, accountability, urgency, and prioritization.
- Confidence in managing incidents and engaging with senior stakeholders.
- Ability to consider business aspects in critical decision-making.
