Job Description
Job Purpose
The ICE Cybersecurity DFIR team is responsible for defending critical financial infrastructure from Global Cyber threats. We leverage an evolving arsenal of controls that require technical proficiency as well as tenacity, professionalism, and strong communication skills.
Responsibilities
- Email Triage - Evaluating staff reported emails for malicious intent
- Data Loss Prevention - Reviewing Daily DLP events for evidence of internal information leaving the network
- Operations - Handling end user support requests. Some examples of end-user requests : unblocking websites, permitting file uploads, modifying anti-virus policies, and testing email attachments.
- Incident Management - Detect, document, investigate, and resolve security incidents in an efficient manner
- Intrusion Detection - Develop and tune anomaly detection capability to produce reliable actionable data
- Behavioral Analysis - Develop and implement criteria to identify anomalous user behavior leading indicating insider threat activity
Desirable Knowledge And Experience
University degree in Engineering, CIS, or related disciplineHands-on experience with Systems AdministrationDeep understanding of networking and its applicationRelevant Information Security experienceCore Competencies
Problem solving : We focus on identifying and solving our customers' needs and make well-informed, quick decisionsCommunication : We communicate clearly, constructively, and frequentlyIntegrity & Professionalism : We hold ourselves and each other to the highest standardsCollaboration : We work as one team focused on a common set of objectives and committed to each other's' successLeadership : We lead by exampleAdvancement Opportunity
Seniority is determined by experience and demonstration of exceptional competencies including :
Automation - Automating simple tasks using python increasing efficiency and continuityCounter Measures - Ability to design and implement preventative and corrective controls to counteract emerging threatsSecurity Analytics - Efficiently distill actionable information from large data sets for reporting, hunting, and anomaly detectionProactive Threat Hunting - Develop and execute focused plans to discover advanced threats that evade traditional security controlsServe as a responsible Subject Matter Expert (SME) on one or more tools or technologies via learning, testing, implementing, enhancing, and educating.Skills Required
intrusion detection, Networking, Data Loss Prevention, Incident Management, Automation, Systems Administration