Job description
- The Carbon Black SME will be responsible for the design, deployment and management of globally deployed EDR systems
- This role will work closely with the HO Cyber security team, Threat Intelligence team, Incident Response, and monitoring analysts to define and tune rules and device security policies to meet the project requirements
Qualifications :
Bachelors or Masters Degree in Computer Engineering, Information Technology or information systemsFamiliar with basic understanding of Malware, TCP / UDP packets, security tools such IDS / IPS, web proxies, SIEM, DNS security, DDoS protection, firewalls3+years of experience in deployment, management configuration for Carbon Black EDR, preferably in multi geography environment.5+ years total experience in cyber security engineering role with respect to design, implement and operation for End point security solutions.Relevant cyber security experience in IT Security, Incident Response or network security with strong knowledge working in a Security Operations Center.Experience with : SIEM (QRadar, Splunk, Nitro, etc), SOAR (Resilient, Demisto, ServiceNOW, etc), Ticketing (JIRA, ServiceNow, Remedy, etc)Knowledge of generic information security standards / programs. Understanding of basic network concepts, familiarity with TCP / IP and VLAN functionalityExperience with risk management, vulnerability management, threat analysis, security auditing, security monitoring, incident response and other information security practices preferredAt least one technical certification (CCNA / MCSE / RHCE / Etc)At Least one cyber security certification (CISSP / CISM / CEH / COBIT / CompTia / etc). Security+,Linux+, GREM, GCFA, GNFA, OSCP, or similar certification preferredSkills Required
Demonstrated experience scripting environments like bash and / or PowershellProficiency in server network administration skills - Windows and LinuxKnowledge of on-prem and cloud infrastructure technologiesCapability to develop professional documents in the form of reports, analysis, documentations (in English)Strong attention to detail, analytical mind, and outstanding problem-solving skillsExperience in working under pressure in a fast-paced environment.Strong collaboration and communications skills required to address and resolve issues in a matrixed environment.Full professional proficiency in EnglishGood experience and exposure for advanced incident analysisExperience with the common tools associated with penetration testing (Metasploit, Burp Suite, Kali etc)Ability to effectively code in a scripting language (Python, Perl, etc)Team management and upskillingPersonal skills :
Good Team playerPossess Positive and learning attitudeGood Verbal and Written communication skillsSense of Ownership, Priorities and AutonomousAbility to travel up to 50% of the timeWhat we offer :
Working on international projectsWide range of possibilities to gain both technical and soft skills as well as professional certificationsRoles Responsibilities
Configuring modifying Policies in carbon black EDR cloud consoleConfigure Threat Intelligence Feeds for Carbon BlackConfigure the EPP Scan exclusion list in CB EDRVerify UAT Server / endpoints etc on status in EDR ConsoleTroubleshooting EDR UAT issuesCreating and submitting UAT reportTroubleshooting EDR client deployment issuesCapable to fine tune incidents to avoid false-positive alertsIdentify, develop and propose enhancements to existing processes and operationsAbility to read and understand system data including security event logs, system logs, application logs, and device logsAbility to analyse incidents, independently form conclusions, and present findings and recommendations to other analystsExposure to SOPs creation related to different process and incident investigation analysisAbility to investigate malicious activity to understand nature of threatAbility to Collaborate / Interact with different teams in SOCExposure to Threat hunting activityExposure in email analysis to categorize it as a Spam / Scam, Malicious, LegitimateAbility to analyze different IOCs and take actions accordinglyAdministration and maintenance of the endpoint protection infrastructureSkills Required
Network Administration, Linux, Perl, Information Security, Dns