Incident Response Engineer responsible for incident detection and recovery at Kong. Collaborating with teams to enhance security processes and systems.
Responsibilities
Execute, develop and document incident handling guides and processes for Kong
Prioritizes events using existing tools to correlate data to reduce false positives and detect threats
Analyze and tune security alerts and interpret events, as well as create new signals based on signatures and behavioral activities
Respond to security incidents and perform forensics on IT systems as necessary.
Guide/lead mitigation strategies for identified vulnerabilities and threats
Design, automate and maintain a portfolio of security alerts, automated actions, and escalation workflows supporting a high-performing 24/7 incident response capability.
Conduct threat hunting activities, anticipate future threats, and maintain forward-thinking strategies for tools/technology/processes that combat sophisticated threat actors.
Assist with implementation of counter-measures or mitigating controls
Develop and maintain Incident Response capabilities in public cloud environments
Prepare incident reports of analysis methodology and results.
Recognize potential, successful, and unsuccessful intrusion attempts and compromises thorough reviews and analyses of relevant event detail and summary information
Partner with key stakeholders and communicate effectively to improve preparation, identification, analysis, containment, and post-mortem activities feedback loop.
Develop monthly reporting dashboards and metrics on incidents and response capabilities
Prepare executive summaries and conduct briefings on significant investigations.
Requirements
Experience in crisis management, namely in preventing incidents from becoming a crisis
Insight of using incidents as opportunities by leveraging Incidents to drive innovation, situation awareness, and fixes
Passion for automation, delegation, and scalability via playbooks and highly effective processes
Drive for automating processes and workflows to detect, contain and eliminate active malicious agents
Expertise in building and operating security information/event management systems (SIEM), centralized logging, and enrichment solutions (Endpoint protection/detection, Panther, Crowdstrike, AWS Security Hub, codebase infrastructure, build infrastructure)
Practical experience working with cloud technologies; ability to build and deploy a solution using Terraform.
Experience with building and deploying solutions (Ansible, Terraform)
Competency in Linux, windows;
Ability to automate workflows via Python or javascript scripting languages.
Commercial Security Service Sales Executive promoting and selling security services at Johnson Controls. Building relationships and delivering solutions to protect people and property within assigned territories.
Security Incident Responder in a leading IT service company in Germany, responsible for analyzing and responding to IT security incidents while developing technological solutions.
Deputy ISSO leading compliance and security activities for NOAA systems at RCG. Requires active Secret clearance and CISSP certification with 8+ years of experience.
Technical Recruiter hiring for Snap Inc.'s security and machine learning teams. Full life cycle recruiting support for technical talent across Snap's innovations.
Cloud Security Architect integrating cyber defense strategies across cloud platforms for Elevance Health. Lead collaboration with infrastructure and engineering teams to enhance security in cloud environments.
Senior Security Advisor designing advanced security solutions for Optiv’s clients. Driving sales and building relationships in a competitive cyber security landscape.
Personnel Security Specialist leading intake operations at PSI. Focused on case coordination, quality assurance, and team training for security suitability tasks.
Security Coordinator overseeing supervision and training of security personnel for BronxWorks' homeless services programs. Ensuring compliance, safety, and coordination with social services directors in Bronx area.
Part - Time Security Officer safeguarding personnel and property at Kaman Air Vehicles. Providing access control, monitoring systems, and responding to incidents in Bloomfield, CT.