Lead Consultant - Incident Response
CPX · Abu Dhabi, Abu Dhabi Emirate, United Arab Emirates
قدّم وتابع مع أبلاي إيدجOverviewAs a Principal Consultant – Incident Response, you live and breathe blue team operations. Your technical expertise in endpoint and network threat detection and defence is complemented by your integrity and passion for cyber security and technology in general. You work well in a team of highly motivated and skilled blue teamers, but you can also achieve your work independently in different engagements and scenarios. You enjoy taking on new challenges in a fast paced and dynamic working environment. You are a team player who is always willing to help out where required, with a humble and positive attitudeResponsibilitiesServe as technical lead on active incident response engagements and across different IR Retainer customersAchieve tasks independently within the team after initial 2-3 monthsExecute threat hunting activities in support of incident response and proactive environment assessmentsCarry out host-based assessments using EDR tools and network assessments utilizing full packet data to determine the extent and scope of possible compromisePerform host and/or network-based forensics across Windows, Mac, and Linux platforms.Execute digital forensic investigations supporting cyber incident response engagementsContribute to process documentation and continuous service improvement activitiesCollaboration with customers to enhance defensive security posture and existing security controlsFlexible schedule that is open to changing situations and opportunitiesProduce detailed reports and technical briefs, effectively communicate tasks, methodology and guidance to customersExplain technical findings in a manner that can be easily understood by technical and non-technical staffDemonstrate industry thought leadership through blog posts, internal brown-bag sessionsYou must be a team player, with a humble and approachable nature who is willing to go the extra mileQualificationsTechnical Skills:Strong understanding of blue team operations and threat huntingSound understanding of network protocols, TCP/IP, etc.Sound understanding of Microsoft WindowsSound understanding of Linux and OSXSound forensic skills across multiple operating systemsStrong understanding of network analysis tools like Bro/Zeek, Rita, or SuricataAbility to perform analysis of system and network devices logsSound understanding of the capabilities of static and dynamic malware analysisSound understanding of enterprise systems, technologies, and infrastructureStrong understanding of targeted attacks and ability to create customized tactical and strategic remediation plans for compromised organizationsStrong understanding of current threats, vulnerabilities, and attack trendsStrong understanding of the ATT&CK frameworkExcellent organizational skills, ability to prioritize, and ability to work independentlyAny other responsibilities as required by the Line ManagerSkills/Certifications (Technical & Non-Technical)Good attention to detail and reporting accuracyEnglish language skills, both spoken and writtenGIAC Certified in a minimum of one discipline: GNFA, GCIH, GCIA, GCFE, GCFA, GDAT, etc. Or equivalent (eLearn Security, etc.)Previous experience working with EDR tools and threat-hunting toolsPrevious experience performing network forensics is desirableKnowledge about cloud security infrastructure (AWS, Azure, Oracle, others) is desirableExcellent organizational skills, ability to prioritize, and ability to work independentlyMinimum Work Experience - 6 yearsEducation - Bachelor's degree in Computer Science or Engineering is desirable but not mandatory