We’re looking for a candidate to fill this position in an exciting company.
Conducts investigations and forensics on internal and cloud assets for SAP and its line of businesses
Leads incidents of local and regional scale, sets investigations goals and prioritizes tasks
Drives continuous improvement and increases efficiency through standardization and automation
Works independently and with management on highly visible and complex projects
Contributes to major, global scale incidents and crisis situations by conducting analysis and writing summaries or reports
Designs, implements and verifies new detection mechanisms and queries
Mentors analysts and helps develop skills
Is part of a 24/7 follow-the-sun organisation
Degree in Computer Science or equivalent experience
Experience working in a 24/7 operational environment (Cyber Intelligence Fusion Center, SOC, NOC, Operations Center).Has Security certification (e.g. Security+, GCIA, GCIH, CISSP)
Knowledge in the area of creation and maintenance of detection use cases and design of playbooks
Experience managing cases with enterprise SIEM or Incident Management systems (Information Security, Information Systems, Engineering or related work experience)
Technology: Good knowledge of one or more of the following: Windows/AD file system, registry functions and memory artifacts, Unix/Linux file systems and memory artifacts, Mac file systems and memory artifacts, Cybersecurity automation, SIEM tools (Splunk, Loggly, Sumo Logic, LogZilla, jKool, QRadar)
TCP/IP communications & knowledge of how common protocols and applications work at the network level, including DNS, HTTP(S), SSH, RDP and SMB
Experience in network security and network systems including LANs/WANs/VPNs/Firewalls and IDS’s
Experience with one or more scripting languages (PowerShell, Python, Bash, etc.)
Knowledge of APT actors; their tools, techniques, and procedures (TTPs), TTP methods and frameworks
Ability to demonstrate analytical expertise, close attention to detail, excellent critical thinking, logic, and solution orientation and to learn and adapt quickly
Ability to summarize and communicate findings and issues concise and clearly.