Take ownership and oversight of a team who executes all aspects of reactive & proactive defensive security projects, including a DFIR Lab, for one on-site VIP customer
Perform the required duties of the Incident Response and Forensic Team’s Senior Manager (both people management and operational management duties)
Serve as technical lead on active incident response engagements across different sub-entities for this one VIP customer. Lead and execute the coordination, investigation and resolution of large-scale incidents following industry standard processes e.g. 800-61 r2 PICERL in a calm and methodical manner utilizing your strong technical skills
Execute, coordinate and lead threat hunting activities in support of incident response, as well as proactive environment assessments and SOC activities
Provide subject matter expertise in the threat detection and cyber defence domains
Take ownership of the DFIR Lab & service for this VIP on-site customer, contributing significantly in a leadership capacity, to process documentation and continuous service improvement activities
Lead and coordinate host and/or network-based forensics across various platforms
Lead and coordinate digital systems and mobile forensic investigations supporting cyber incident response engagements
Lead and coordinate the drafting of detailed reports and technical briefs, effectively communicating tasks, methodology and guidance to VIP on-site customer
Use your ability to stay calm and grounded in highly challenging situations to instil trust within client stakeholders; explain technical findings in a manner that can be easily understood by technical and non-technical stakeholders
Demonstrate industry thought leadership through internal brown-bag knowledge sharing sessions, coordinate the team’s topics for such sessions
Develop talent within the team by providing constructive and positive direction and support to achieve targets, build capabilities, and take on challenging DFIR & research projects
Lead research activities in search of service improvement tasks and better understanding of threat landscape.
lead and nurture a team culture built on trust, respect, appreciation, flexibility, and unity
Flexible schedule that is open to changing situations and opportunities, as with any position that is related to Incident Response
You must be a team player, with a humble and approachable nature who is willing to go the extra mile.
Ability to make an impact already after the initial couple of weeks of adapting into the new environment. Flexible schedule that is open to work in shifts (as per the team’s schedule) as well as changing situations and opportunities. There will be no working shift for this position, but the team’s shifts shall rotate from 6AM to 2PM and from 2PM to 10PM in a monthly basis, as a requirement to work for this important VIP on-site client, including on-call rotation as well of one week duration once every 2 months.
Technical Skills
Expert understanding of blue team operations and threat hunting
Deep understanding of digital forensics methodologies as well as usage of various tools
Expert understanding of network protocols, TCP/IP etc.
Expert understanding of network forensic principles and applications
Expert understanding of Microsoft Windows
Strong understanding of Linux and OSX
Expert understanding of enterprise IT and IT Security infrastructure. You will use this knowledge to lead strategic recommendations to customers, with the help of the DFIR Team, and ensure the best remediation of the managed incidents
Strong forensic skills across multiple operating systems
Proven experience performing duties utilising PICERL / NIST IR standards