Website DeepSeas
Description:
Position Overview
Key Responsibilities
• 2. Communicate and coordinate with internal and external stakeholders.
• 3. Identity, develop, document, and deploy threat detection platforms that meet multiple stakeholder requirements.
• 4. Collaborate with threat intelligence and vulnerability management teams to stay updated on emerging threats and vulnerabilities.
• 5. Tune detection rules to enhance threat detection capabilities according to threat intelligence reports, purple team testing, PEN testing, and IR feedback.
• 6. Knowledge and operational experience using MITRE ATT&CK to map use cases across the initial points of exposure, alert mapping and incident reporting.
• 7. Drive continuous improvement initiatives within the SOC.
• 8. Test and Verify detection pipeline visibility and analytics across multiple threat actor TTP’s
• 9. Security Automation and Orchestration platform and process support for various teams across the Security Operations Function.
• 10. Collaborate with threat intelligence teams to instrument threat intelligence visibility across the enterprise for high-fidelity TTP’s and indicators related to new threat actor TTPs.
Skills Knowledge and Expertise
• Requires both written and verbal communication skills with both technical and non-technical stakeholders.
• Proficiency in SIEM, EDR, xDR, and NDR tools.
• Hands on experience with using ATT&CK framework tools and pen testing tools to simulate adversarial behaviors (e.g., ransomware, trojans, worms) and translating those behavior’s into methodology\technique level detections within detection platforms.
• Experienced with various operating systems
• Knowledge of common enterprise network architectures and cloud architectures.
• Knowledge of interpretive script languages like Python, PowerShell, or Bash to support automation.
• Strong knowledge of multiple analytic techniques on major data analytics platform, (e.g. KQL, SPL, Kibana Query Language, LINQ, etc)
Certifications: GIAC Certified Detection Analyst (GCDA) or equivalent.
Why DeepSeas?
· We stand in solidarity with our teammates.
· We prioritize personal health and well-being.
· We believe in the power of diversity.
· We solve hard problems at the speed of cyber.
This is your chance to join a supportive crew of teammates and an industry-leading organization that values opportunities for growth. If DeepSeas sounds like a good fit for you, send us your resume and let’s talk!
Information security is everyone’s responsibility:
• Understanding and following DeepSeas’s information security policies and procedures.
• Remaining vigilant and reporting any suspicious activity or possible weaknesses in DeepSeas’s information security.
• Actively participating in DeepSeas’s efforts to maintain and improve information
• security.
• DeepSeas considers this position is as Moderate Risk with a potential to
• view/access/download restricted/private client/internal data. This information must be treated with
• sensitivity and in the most secure manner. HR reserves the right to perform random background/drug
• screens to ensure the safety of client/DeepSeas data
About DeepSeas
To apply for this job please visit deepseas.pinpointhq.com.