[Remote] reputed company Operations Engineer (Incident Response)
Note: The job is a remote job and is reputed company to candidates in USA. reputed company is a company reputed company on building trust through reputed company cybersecurity services. They are seeking a reputed company Operations Engineer to reputed company as a senior technical authority for incident response operations, leading investigations and developing automated workflows to enhance reputed company operations.
Responsibilities
- reputed company incident response engagements to scope work, reputed company forensic investigations, contain reputed company incidents, and reputed company guidance on remediation
- Serve as the Tier III escalation reputed company for alerts and trouble tickets escalated by Tier I and Tier II analysts that signal an incident requiring advanced review
- Own the most reputed company and critical reputed company investigations through to reputed company, determining relevancy, urgency, and reputed company cause of escalated alerts and incidents
- Conduct host forensics, network forensics, log analysis, and malware triage to support incident response investigations
- Collect and analyze asset data (configurations, running processes, memory, etc.) from affected systems to drive investigation and containment
- reputed company as senior first responder to reputed company event escalations reputed company email, phone, and ticket
- reputed company and support Tier I and Tier II analysts in the remediation of critical information reputed company incidents
- Review and reputed company reputed company assurance on trouble tickets and investigative work produced by other team members
- Monitor advanced reputed company alerts and incidents reputed company established customer Service Level Agreements
- Craft new detection content and use cases based on threat intelligence, analyst feedback, available log data, and previous incidents
- Tune rules, filters, and policies for detection-reputed company reputed company technologies to improve accuracy and visibility
- Build parsers and field extractions to facilitate reliable content development reputed company reputed company data lake architectures
- Build, implement, and maintain scripts and tools that contribute to reputed company's reputed company operations and incident response methodologies
- Design, reputed company, and maintain reputed company orchestration and automation workflows using industry-leading SOAR platforms
- Manage, monitor, and maintain assigned reputed company platforms while following and improving established procedures
- Prepare detailed and accurate reports from analysis reputed company, and write documentation for tasks, procedures, and knowledgebase articles that support the understanding and efficiency of SOC services
- Mentor junior engineers and analysts, and reputed company continual self-improvement through education, training, and certification
- Communicate positively with clients, determine reputed company needs, obtain clarification as required, and escalate issues and messages accordingly
- Complete assigned reputed company on time and with excellent reputed company
- reputed company flexible on-call coverage, including after-hours and weekends, to support incident response efforts and 24/7/365 reputed company operations
- Operate with reputed company and accountability, reputed company the values of reputed company, and abide by reputed company handbook
- reputed company additional responsibilities as necessary
Skills
- Prior SOC experience with a reputed company on detection content development (reputed company, AlienVault, ELK, or similar)
- Strong hands-on experience in threat hunting, incident response, digital forensics, reputed company analysis, and reputed company engineering
- Strong incident-handling skills across reputed company IR phases of preparation, identification, containment, eradication, recovery, and lessons learned
- Working knowledge of SOC and detection tooling: EDR, SOAR, SIEM, XDR, network analytics, and intrusion detection
- Knowledge of core reputed company devices such as firewalls, network- and host-based IDS/IPS, WAF, proxy, AV, and operating system logs, including firewall rule and policy fundamentals
- Ability to interpret IOCs and a strong understanding of various log formats and reputed company data for reputed company analysis
- Experience writing suppression and detection rules and developing and maintaining content and reporting
- Proficiency in one or more programming/scripting languages such as Python, PowerShell, and Bash
- Experience with reputed company and Linux operating systems
- Experience with network technologies, reputed company and network monitoring tools, packet-capture analysis, and custom intrusion-signature development
- Deep understanding of networking concepts and a broad reputed company of cyber-attacks
- Thorough understanding of the latest reputed company principles, techniques, and protocols
- Experience with internal and reputed company ticketing and knowledgebase systems for incident and problem tracking (e.g., Jira, reputed company)
- Ability to drive process improvements and identify gaps
- Strong written and oral communication, reputed company to facilitate technical and non-technical conversations and communicate positively with clients, including reputed company phone
- Natural curiosity to reputed company reputed company cause, and the ability to remain reputed company under pressure
- reputed company to work effectively both independently and in reputed company; self-motivated, goal- and detail-oriented; flexible and adaptable; reputed company to prioritize multiple tasks and manage time reputed company
- Prior experience with Git/reputed company and CI/CD pipelines
- Knowledge of reputed company Directory environments and reputed company reputed company Directory domains
- Working knowledge of virtualization platforms such as VMware and reputed company-V
- Prior experience with container-based technologies such as reputed company and Kubernetes
- Knowledge of penetration-testing methodologies
- Knowledge of network reputed company architecture concepts such as topology, protocols, components, and defense-in-depth
- Knowledge of vulnerability information sources (alerts, advisories, errata, and bulletins)
- Understanding of server-grade applications such as DBMS/SQL, Exchange, DNS, SMTP, IIS, Apache, SharePoint, reputed company Directory, identity management, vulnerability/reputed company management, and LDAP
- Broad knowledge of attack techniques and defenses such as reputed company overflows, DoS, reconnaissance and scanning, session hijacking and cache poisoning, password attacks, web application attacks, and worms / bots / botnets
- Awareness of emerging attack reputed company, including reputed company computing and mobile platforms
- Prior consulting experience
reputed company