Hybrid CSIRT Engineer

Posted last month

Apply now

About the role

  • Incident Response Engineer combating cybersecurity threats for GEICO by handling security events and conducting incident response activities. Engaging in complex investigations including cloud response and malware analysis.

Responsibilities

  • Identify, detect, respond, and mitigate sophisticated threats to GEICO
  • Perform incident response functions including: Responding to cloud-based incidents in AWS, Azure, and GCP
  • Host-based analysis of Windows, Linux and Mac operating systems
  • Examine data collected from a variety of tools and sources (e.g., IDS alerts, firewall logs, web logs, network traffic logs) to identify IOCs and/or malicious TTPs
  • Review/Comprehend log data and apply use case scenarios in effort to further develop threat detection and incident response capabilities
  • Analyze events that occur within their environments for the purposes of mitigating threats

Requirements

  • 4+ years of Incident Response experience
  • Knowledge of digital forensics and incident response best practices
  • Experience with responding to cloud-based incidents
  • Demonstrated experience performing root cause analysis of security events and incidents
  • Knowledgeable with security frameworks (E.g. – MITRE ATT&CK framework)
  • Ability to understand security control mechanisms for Windows, Linux, and Mac operating systems
  • Knowledge of computer networking concepts and protocols, and network security methodologies
  • Knowledge of common threat actor TTPs
  • Proficient in scripting languages such as Bash, Python, Perl, and PowerShell.
  • Ability to apply strong critical thinking, logic, decision making, troubleshooting, and problem-solving skills
  • Strong written and oral communication skills
  • Ability to work independently and as a team member
  • Ability to handle advanced-level triage and troubleshooting
  • Ability to produce technical documentation, such as Visio flows and processes
  • Ability to understand complex problems while presenting them simplistically in a formal setting
  • Ability to learn and apply large amounts of technical and procedural information, and to follow published standards and processes.
  • Ability to follow complex instructions, resolve conflicts or facilitate conflict resolution, and have strong organization/priority setting skills.
  • Ability to analyze Windows systems for changes that occur during a specific timeframe.
  • Ability to analyze network packet captures
  • Knowledge of cloud computing technologies and concepts (SaaS, PaaS, IaaS, etc.)
  • Knowledge in cyber defense systems and mechanisms.

Benefits

  • 401K savings plan with 6% match
  • Performance and recognition-based incentives
  • Tuition assistance
  • Mental healthcare assistance
  • Fertility and adoption assistance
  • Flexible work arrangements (GEICO Flex program)
  • Employee engagement and recognition programs

Job title

CSIRT Engineer

Job type

Experience level

Mid levelSenior

Salary

$75,000 - $150,000 per year

Degree requirement

Bachelor's Degree

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job