Incident Response Engineer combating cybersecurity threats for GEICO by handling security events and conducting incident response activities. Engaging in complex investigations including cloud response and malware analysis.
Responsibilities
Identify, detect, respond, and mitigate sophisticated threats to GEICO
Perform incident response functions including: Responding to cloud-based incidents in AWS, Azure, and GCP
Host-based analysis of Windows, Linux and Mac operating systems
Examine data collected from a variety of tools and sources (e.g., IDS alerts, firewall logs, web logs, network traffic logs) to identify IOCs and/or malicious TTPs
Review/Comprehend log data and apply use case scenarios in effort to further develop threat detection and incident response capabilities
Analyze events that occur within their environments for the purposes of mitigating threats
Requirements
4+ years of Incident Response experience
Knowledge of digital forensics and incident response best practices
Experience with responding to cloud-based incidents
Demonstrated experience performing root cause analysis of security events and incidents
Knowledgeable with security frameworks (E.g. – MITRE ATT&CK framework)
Ability to understand security control mechanisms for Windows, Linux, and Mac operating systems
Knowledge of computer networking concepts and protocols, and network security methodologies
Knowledge of common threat actor TTPs
Proficient in scripting languages such as Bash, Python, Perl, and PowerShell.
Ability to apply strong critical thinking, logic, decision making, troubleshooting, and problem-solving skills
Strong written and oral communication skills
Ability to work independently and as a team member
Ability to handle advanced-level triage and troubleshooting
Ability to produce technical documentation, such as Visio flows and processes
Ability to understand complex problems while presenting them simplistically in a formal setting
Ability to learn and apply large amounts of technical and procedural information, and to follow published standards and processes.
Ability to follow complex instructions, resolve conflicts or facilitate conflict resolution, and have strong organization/priority setting skills.
Ability to analyze Windows systems for changes that occur during a specific timeframe.
Ability to analyze network packet captures
Knowledge of cloud computing technologies and concepts (SaaS, PaaS, IaaS, etc.)
Knowledge in cyber defense systems and mechanisms.
Senior Technical Leader for enterprise virtualization platform at ComPsych. Leading virtualization engineers, guiding design decisions, and managing infrastructure initiatives.
Senior Client Engineer enhancing construction projects with data - driven technology from nPlan. Focus on client relationships and maximizing product value in the construction industry.
Cybersecurity Engineer providing application - level administration of forensic tools and systems at GDIT. Focused on maintaining and enhancing cybersecurity operations for federal customers.
Cybersecurity Engineer maintaining and enhancing digital forensic and cybersecurity toolsets for critical systems. Ensuring compliance while supporting the application - level administration for federal agency requirements.
Standards Engineer responsible for designing, updating, and communicating engineering standards at Liberty, impacting energy and water solutions. Collaborate across departments to ensure compliance and provide training.
Mechanical Engineer performing design and analysis for nuclear power plant components at Westinghouse Electric Company. Evaluating equipment with ASME Code and supporting fabrication processes.
Senior Safety Engineer supporting Nuclear safety case development for submarine defueling and dismantling. Requires engineering degree and knowledge in nuclear safety.
Project Development Engineer Intern supporting automation projects with Repair Engineering Groups at Teradyne. Collaborating on ongoing projects and developing engineering tools in Costa Rica.
Manufacturing Engineer I at Crown Equipment Corporation supporting process technology and implementing improvements based on engineering analysis. Collaborating on product introductions and fielding production issues.