Trellix

Associate Solution Consultant - Security Incident Handler

Trellix$80K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-4 years' experience in Information Security, focusing on operational security monitoring or incident response.
  • Bachelor's Degree in computer science, information technology, or a related cyber field is preferred.
  • In-depth understanding of cyber threats, attack vectors, and incident management processes.
  • Familiarity with Trellix products and various security technologies.
  • Strong scripting skills in Linux and Python; experience with other languages is a plus.

Responsibilities

  • Manage client engagements related to security monitoring and incident response.
  • Act as a key member of the 24x7 Security Operations Task Force and CSIRT team.
  • Respond to security incidents, including malware investigations and phishing mitigations.
  • Conduct host and network forensics during security incidents to analyze for indicators of compromise.
  • Identify and mitigate vulnerabilities, employing compensating controls as required.
  • Document and report on incidents, providing technical and executive summaries.
  • Collaborate with client and company managers for project cost and schedule oversight.

Benefits

  • Retirement Plans
  • Medical, Dental and Vision Coverage
  • Paid Time Off
  • Paid Parental Leave
  • Support for Community Involvement
Full Job Description
(opens in new tab)

Job Title:

Associate Solution Consultant - Security Incident Handler

Role Overview:

Develops and delivers detailed IT and cybersecurity solutions through consulting project activities. Responsibilities include client identification through final invoicing for engagements requiring varied interpersonal and technical skills. Technical responsibilities include problem identification, security monitoring, rapid incident response, threat detection, system architecture definition, software specification/design, implementation, testing, client training, and solution deployment. Performance is typically evaluated based on utilization (i.e., billable hours). Project management activities include interaction with company and client managers and cost/schedule monitoring. May have financial responsibilities including project cost estimating, proposal generation, and invoicing. May participate in sales and proposal presentations in addition to completing ongoing team account activities. Identifies additional product/services opportunities within customer organizations. Performance is typically measured by the capture of the consulting engagement and/or delivery of agreed solutions within budgeted hours.

Job Description:

Trellix Professional Services is seeking a Security Incident Handler with a passion for Cyber Security Defense and a strong understanding of security monitoring and incident response.

We have an onsite Elite team-one of the best Cyber Security consulting teams-working directly with our strategic customer as a joint Security Operations Task Force, and growing this piece of the business is a top priority!

This is a full-time hybrid role (3 days onsite, 2 days remote) with Public Sector Professional Services. You will work hand in hand with the customer's Cyber Security, IT, and business teams to ensure the highest security around all Trellix Solutions and broader Cyber Security ecosystems. The Computer Security Incident Response Team (CSIRT) is responsible for 24x7x365 security monitoring and rapid incident response across the customer's environments. As the 'tip of the spear' and the last line of defense protecting customer data and assets from adversaries, you will exercise judgment within broadly defined practices and policies in selecting methods, techniques, and evaluation criteria for obtaining results.

Note: This position may require occasional after-business-hour and weekend on-call shifts.

About the Role:
  • Manage and perform client work related to our product service offerings, security monitoring, and incident response.
  • Act as an integral member of the joint Security Operation Task Force and CSIRT team in a 24x7x365 operations environment.
  • Respond to security incidents in a production environment, including investigating/remediating endpoint malware infections and mitigating email-borne threats (phishing/spam).
  • Conduct host and network forensics during security incidents, analyzing system artifacts (file system, memory, running processes, network connections) for indicators of compromise (IOCs).
  • Identify and mitigate vulnerabilities using alternate or compensating controls where necessary.
  • Recognize potential security violations, report incidents as required by regulations, and mitigate adverse impacts.
  • Create end-of-engagement reports, technical DFIR (Digital Forensics & Incident Response) reports, and executive summaries describing findings and analysis.
  • Author formal reports, architecture designs, optimization guides, and best-practice white papers covering a variety of security topics.
  • Interact with company and client managers on cost/schedule monitoring, estimating, proposal generation, and invoicing.
  • Help identify and develop new client opportunities, expert services engagements, and potential consulting sales leads.
  • Maintain technical proficiency through self-training or formal training while sharing knowledge and mentoring consultant peers.

About You:
  • Experience: 3 to 4 years' experience in Information Security, including operational security monitoring or incident response.
  • Education: Bachelor's Degree; technical degree or diploma preferred in computer science, information technology, or a related cyber field.
  • Core Technical Expertise:
    • Understanding of cyber threats, attack vectors, detection capabilities, incident management processes, and compensating security controls.
    • Experience monitoring and leveraging Trellix products: Trellix ePO, Endpoint Security (ENS), Trellix Detection & Response / Active Response (EDR), Advanced Threat Defense (ATD Sandbox), Threat Intelligence Exchange (TIE), Data Exchange Layer (DXL), Data Loss Prevention (DLP), SIEM, XDR, and Email Gateway ATP.
    • Monitoring and log analysis across Network/Host IDSs, UEBA, WAFs, Database Security, Firewalls/Routers/Switches/VPNs, File Integrity Monitoring (FIM), Active Directory, and OS logs.
  • Forensics & Threat Knowledge:
    • Host and network forensics capabilities, system artifact analysis, and threat hunting methodologies.
    • Basic technical understanding of the MITRE ATT&CK™ framework and MITRE's Ten Strategies of a World-Class Cybersecurity Operations Center .
    • Knowledge of TCP/IP protocol suites (packet/traffic dissection) and OS logging configuration (Syslog, flat-files).
    • Familiarity with Windows, Mac, and Linux OS administration, application hardening, and security controls.
  • Scripting & OS Skills:
    • Strong Linux and Python skills are preferred. Experience with PowerShell, Perl, Go, C#, or general shell scripting is a significant plus.
    • Understanding of relevant infrastructure technologies: Virtualization (VMware, Nutanix) and Cloud Services (AWS, Azure).
  • Soft Skills & Professionalism:
    • Excellent client-facing presentation, verbal, and written communication skills (ability to communicate with technical staff and executive leadership).
    • Advanced proficiency in Microsoft Office Suite (Word, Excel, PowerPoint).
    • Ability to prioritize and manage multiple tasks independently in a high-tempo environment.


Company Benefits and Perks:

We believe that the best solutions are developed by teams who embrace each other's unique experiences, skills, and abilities. We work hard to create a dynamic workforce where we encourage everyone to bring their authentic selves to work every day. We offer a variety of social programs, flexible work hours and family-friendly benefits to all of our employees.
  • Retirement Plans
  • Medical, Dental and Vision Coverage
  • Paid Time Off
  • Paid Parental Leave
  • Support for Community Involvement

About Trellix

Trellix was a software company that provided web publishing tools for small businesses and individuals. The company was founded in 1999 and was headquartered in Cambridge, Massachusetts. Trellix was acquired by HP in 2003 and its technology was integrated into HP's Small Business Center.
Learn more about Trellix
Size
3,400 employees
Market Cap
$4.1 billion
Industry
Net Income
-$207.3 million
Founded
2004
5 Year Trend
+8.6%
Revenue
$940.5 million
NASDAQ

Similar Jobs

More Jobs at Trellix

More Information Technology Jobs

Find similar Associate Solution Consultant - Security Incident Handler jobs: