|
About the Job: As a DFIR Engineer II on the Threat Detection & Response team, your role will include responding to, investigating and containing anomalous or malicious activity that could indicate a security threat. You'll be responsible for staying up to date on the latest cybersecurity threats and assisting in the continual development and refinement related to monitoring, detecting and responding to abnormal network and host activity. What You'll Do:
Triage, pivot and correlate across multiple network and host-based log sources. Analyze system artifacts and memory for evidence of compromise. Proactively hunt for and identify malicious activity in various log sources using threat intelligence and other indicators of compromise. Document detailed findings including timelines of events or incidents Continually improve incident response procedures and documentation. Engage with Detection Engineering and Red Team to identify opportunities to better monitor/detect suspicious behavior and automate response capabilities. Keep up to date on evolving cyber threats and identify methods to detect them. Participate in an on-call rotation with other Incident ResponseEngineers
What You'll Bring to the Role:
Bachelor's Degree in Information Security, Computer Science, or equivalent combination of education, training, and experience. Two or more years in an Incident Response or Security Operations Center (SOC) role. Background in information technology with an emphasis on network or systems administration. Hold or willingness to obtain certifications such as GCIH, GCFE, GCFA, GDAT, CISSP or other relevant security certifications. Foundational understanding of networking, Windows, Mac & Linux operating systems, and cybersecurity principles. Experience with security tools including SIEM, EDR, AV, CASB, Next-gen Firewalls, and VPN. Experience with system and network artifacts. Working knowledge of the MITRE ATT&CK framework. Familiarity with various cloud environments and containerization technologies (AWS, Azure, O365, Docker, Kubernetes). Functional and practical experience with at least one development or scripting language/framework (e.g. PowerShell, Python, .Net) and regular expressions. Strong analytical, problem-solving, and communication skills. Demonstrated curiosity and passion for cybersecurity.
What Set you apart:
Incident Response-Responds to crises or urgent situations within the pertinent domain to mitigate immediate and potential threats. Uses mitigation, preparedness, response, and recovery approaches as needed to maximize the preservation of property and information security. Digital Forensics-Collects, processes, preserves, analyzes, and presents computer-related evidence in support of network vulnerability mitigation and criminal, fraud, counterintelligence, or law-enforcement investigations. Triage-Investigates technical problems through a systematic and hypothesis-driven approach to understand the context of what is causing the issue and identify a solution. Threat Awareness-Uses knowledge of threats to support the tracking of common and emerging security threats, increasing awareness of potential risks and the protections available against them. Threat Research-Identifies and assesses the capabilities and activities of cybercriminals or foreign intelligence entities. Produces findings that help initiate or support law-enforcement and counterintelligence investigations or activities. Cloud & IT Infrastructure-Applies DevOps principles and a cybersecurity mindset to services and capabilities. Uses an understanding of enterprise IT environments, including operating systems, networks, and domain services, and orchestrates applications and infrastructure through a pipeline approach. Scripting & Integration-Applies scripting knowledge to automate tasks and integrate transactional systems. Uses systems that facilitate or automate business application solutions, including records maintenance, inventory management, process analytics, and general administration.
#LI- Hybrid Compensation Range: Pay Range - Start: $89,360.00
Pay Range - End: $134,040.00
Geographic Specific Pay Structure: Structure 110: Structure 115: We believe in fairness and transparency. It's why we share the salary range for most of our roles. However, final salaries are based on a number of factors, including the skills and experience of the candidate; the current market; location of the candidate; and other factors uncovered in the hiring process. The standard pay structure is listed but if you're living in California, New York City or other eligible location, geographic specific pay structures, compensation and benefits could be applicable, click here to learn more. Grow your career with a best-in-class company that puts our clients' interests at the center of all we do. Get started now! Northwestern Mutual is an equal opportunity employer that welcomes talented individuals of all backgrounds. We are committed to creating and maintaining an environment in which each employee can contribute creative ideas, seek challenges, assume leadership and continue to focus on meeting and exceeding business and personal objectives.
Skills
Cyber Threat Hunting, Digital Forensics, Endpoint Detection and Response, MITRE ATT&CK Framework, Log Analysis, Python Automation, SIEM Tools, Incident Response
FIND YOUR FUTURE
We're excited about the potential people bring to Northwestern Mutual. You can grow your career here while enjoying first-class perks, benefits, and our commitment to a culture of belonging.
- Flexible work schedules
- Concierge service
- Comprehensive benefits
- Employee resource groups
|